Feature Request: Ability to add a 'Comment' when Bulk Uploading IOC Rules in XDR

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Feature Request: Ability to add a 'Comment' when Bulk Uploading IOC Rules in XDR

L0 Member

When adding IOC's to XDR, adding a comment is a useful way to keep track of where the IOC originated from. When an alert is triggered from that IOC, the analyst can review the IOC rule and read the comment for context. 

 

When 'bulk' uploading, using a file for example, there is no comment field. Is it possible to add the ability to make a comment for all entries made during a bulk upload?

 

Thanks. 

1 accepted solution

Accepted Solutions

L4 Transporter

Hi @AlCurran

That is a great suggestion, indeed.

 

For an immediate solution, you can add a comment after performing the bulk upload by selecting the checkbox next to the target IOCs, right-clicking, and then selecting "edit selected." The comment field will be editable from there.

 

Mass_Comment_TakeI.gif

To make the selection easier, you can filter by modification date to find the IOCs created only when uploaded.

 

Modificationtion_Date_TakeII.gif

As for submitting a feature request to submit a comment at upload, I recommend submitting that to your Account team directly as I do not believe that they monitor this discussion board.

Visit our Cortex XDR Customer Corner on Live Community to access resources for your product journey, engage in discussions with community members and subject matter experts, and register for upcoming events!

*Cortex XDR Customer Corner: https://live.paloaltonetworks.com/t5/cortex-xdr-customer-corner/ct-p/Cortex_XDR_Customer_Corner

Join our Cortex XDR Office Hours to receive live guidance and training from our Customer Success Architects.

*Cortex XDR Office Hours [NAM]: https://paloaltonetworks.zoom.us/webinar/register/3316669859020/WN_yMpAB-aBTt6xk2h-gsra4w
*Cortex XDR Office Hours [EMEA/APAC]: https://paloaltonetworks.zoom.us/webinar/register/4116709604301/WN_CZuFE5CHQbG9LUEqugsIOw

View solution in original post

2 REPLIES 2

L4 Transporter

Hi @AlCurran

That is a great suggestion, indeed.

 

For an immediate solution, you can add a comment after performing the bulk upload by selecting the checkbox next to the target IOCs, right-clicking, and then selecting "edit selected." The comment field will be editable from there.

 

Mass_Comment_TakeI.gif

To make the selection easier, you can filter by modification date to find the IOCs created only when uploaded.

 

Modificationtion_Date_TakeII.gif

As for submitting a feature request to submit a comment at upload, I recommend submitting that to your Account team directly as I do not believe that they monitor this discussion board.

Visit our Cortex XDR Customer Corner on Live Community to access resources for your product journey, engage in discussions with community members and subject matter experts, and register for upcoming events!

*Cortex XDR Customer Corner: https://live.paloaltonetworks.com/t5/cortex-xdr-customer-corner/ct-p/Cortex_XDR_Customer_Corner

Join our Cortex XDR Office Hours to receive live guidance and training from our Customer Success Architects.

*Cortex XDR Office Hours [NAM]: https://paloaltonetworks.zoom.us/webinar/register/3316669859020/WN_yMpAB-aBTt6xk2h-gsra4w
*Cortex XDR Office Hours [EMEA/APAC]: https://paloaltonetworks.zoom.us/webinar/register/4116709604301/WN_CZuFE5CHQbG9LUEqugsIOw

Great work around, thanks! 

Yeah I’ve suggested it via our account team but haven’t heard back. Just wanted to know if this was something others would be interested in. It’s a small addition but would really help our manual IOC process.

Thanks for your reply! 

  • 1 accepted solution
  • 3736 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!