Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.
About Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.

Discussions

Welcome to the Cortex XSIAM Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 2440 Views
  • 0 replies
  • 0 Likes

AI Prompt Feature | XSIAM Version 3.4

Hi All,

Does anyone tested the AI prompt feature in XSIAM version 3.4?

From our experience, only generic prompts seem to be working. When we try to use specific real-time case or issue data, it doesn't respond as expected.

We haven't been able to tes

...

Fetched Integrations Objects in XSIAM 3.4

Good morning Live Community,

 

Recently upgraded from XDR to XSIAM.  Have never had XSOAR in the past, but worked through POCs at two different orgs, so somewhat familiar, nowhere near proficient.  Built some simple automations largely dependent on M

...

Resolved! XSIAM API pagination

Hello,

 

I'm trying to use the API to pull a lookup dataset that is larger than 10,000 rows. I don't see any options for pagination and the filters listed in the documentation seem too rigid to easily pull the data. 

 

https://docs-cortex.paloaltonet

...

Fortigate Correlation rules thread

Hi All,

With Fortigate FW logs ingesting into XSIAM, even with the forti content pack installed, there is no real method for detection apart from the analytics engine that will use the '3rd party firewalls' analytic rules to natively detect issues/al

...

PA_nts by L4 Transporter
  • 389 Views
  • 2 replies
  • 0 Likes

Resolved! ServiceNow CMDB data to XSIAM

Hi,

We have integrated XSIAM with ServiceNow CMDB. We want to pull critical assets from the CMDB into XSIAM using an API and we have to do feature field configuration for these critical assets. Currently, I only see an option to upload a static file

...

How do you handle Low Severity alerts/issues?

want to know how you guys deal with low severity alerts.. 

do you monitor/analyze them or only focus on incidents  with medium/high/critical severity?

do you run any playbook automation against these low sev alerts?

are there any best practices from

...

PA_nts by L4 Transporter
  • 1318 Views
  • 3 replies
  • 0 Likes

XSIAM Email Communication

In XSIAM, we need a way for analysts to send email updates at different stages of an incident — like when it is received, contained, and recovered.

Each case should have its own email chain that includes all previous emails for that case.

To support

...

Cortex XDR Host Firewall Rule evaluation

Hi Team,

I have a doubt about Host Firewall rule evaluation. Let say i have a rule created to allow all internal application inbound traffic on specific port / Remote IP. In the same rule group if i create another outbound rule and action type : allo

...

Monitoring Bluetooth

Hi,

 

We are using Cortex XSIAM. Now we want to perform monitoring of Bluetooth in Microsoft Windows 10 and 11 computers. The reason we want to check whether our users are connecting their mobile phones, like iPhone and Androids, through their office

...

O.Faheem by L1 Bithead
  • 533 Views
  • 1 replies
  • 0 Likes

Resolved! Do you backup your custom content?

Hi,

I’m looking for a way to back up my custom content - such as playbooks, lists, scripts, correlation rules, and more, to an external repository (GitHub, GitLab, Azure DevOps, etc.).

So far, I’ve had partial success with playbooks using Python scri

...

  • 145 Posts
  • 41 Subscriptions
Top Liked Authors
Labels