<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Demisto-Qradar Integration in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/demisto-qradar-integration/m-p/336556#M7</link>
    <description>&lt;P&gt;Hi, How to filter out the incidents ingestion in to demisto from Qradar based on time.&lt;/P&gt;&lt;P&gt;Eg:&lt;/P&gt;&lt;P&gt;I have been integrated Demisto with Qradar on today and i want to start recieveing offences only generated from today.&lt;/P&gt;&lt;P&gt;We have done some filtering to recieve only active offeneces on integration tab (status="OPEN") but we need to recieve offences which are generated from today. Can i get the filter same as like mentioned above.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 03 Jul 2020 04:27:19 GMT</pubDate>
    <dc:creator>YeswanthKumar</dc:creator>
    <dc:date>2020-07-03T04:27:19Z</dc:date>
    <item>
      <title>Demisto-Qradar Integration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/demisto-qradar-integration/m-p/336556#M7</link>
      <description>&lt;P&gt;Hi, How to filter out the incidents ingestion in to demisto from Qradar based on time.&lt;/P&gt;&lt;P&gt;Eg:&lt;/P&gt;&lt;P&gt;I have been integrated Demisto with Qradar on today and i want to start recieveing offences only generated from today.&lt;/P&gt;&lt;P&gt;We have done some filtering to recieve only active offeneces on integration tab (status="OPEN") but we need to recieve offences which are generated from today. Can i get the filter same as like mentioned above.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2020 04:27:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/demisto-qradar-integration/m-p/336556#M7</guid>
      <dc:creator>YeswanthKumar</dc:creator>
      <dc:date>2020-07-03T04:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: Demisto-Qradar Integration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/demisto-qradar-integration/m-p/336582#M8</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is how all integrations implement the ingestion mechanism. When you set up a new integration instance that "fetch" incidents - it will mostly look for last 10 minutes, and fetch only "alerts" from that timeframe. Then, once an incident is "fetched", the system will maintain that id, and in the next cycle it will start searching from that point onward.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Specifically for QRadar - it will start ingesting incidents from the moment you configured the instance, so you will only get QRadar Offenses that are created &lt;U&gt;&lt;STRONG&gt;after&lt;/STRONG&gt;&lt;/U&gt; the integration is activated. The query parameter that you can set up in the integration configuration will be applied &lt;U&gt;&lt;STRONG&gt;on top&lt;/STRONG&gt;&lt;/U&gt; of this time frame consideration (and not as a substitute)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gilad&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2020 20:21:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/demisto-qradar-integration/m-p/336582#M8</guid>
      <dc:creator>GShriki</dc:creator>
      <dc:date>2020-07-03T20:21:01Z</dc:date>
    </item>
  </channel>
</rss>

