Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.
About Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.

Discussions

Welcome to the Cortex XSIAM Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 951 Views
  • 0 replies
  • 0 Likes

Resolved! Use case BIOC Creation

Hi Live Community, Please I want to create BIOC with GUI for this use case Process name = svchost.exe and (Path not   C:\Windows\WinSxS\* OR C:\windows\system32\* )

 

 

 

BR.

Bouzeghoub_0-1767003982011.png

Do you backup your custom content?

Hi,

I’m looking for a way to back up my custom content - such as playbooks, lists, scripts, correlation rules, and more, to an external repository (GitHub, GitLab, Azure DevOps, etc.).

So far, I’ve had partial success with playbooks using Python scri

...

CPU and Memory Usage

Hello everyone,

I’m looking for an XQL query that shows CPU and memory usage.
For example, I want to visualize something like: the XDR service consumes an average of X% memory and Y% CPU per hour, preferably as a graph.

Could you please help with this

...

Broker Helath Checking

Hello everyone!

 

I working in a environment that have some broker clusters and local brokers as well, I would like know how I can implement some way to have a daily health checking for these brokers, like if the broker is need a reboot to update, if

...

Vulnerability Assessment in XSIAM 3.3

Does anyone know what happened to the Vulnerability Assessment in XSIAM after upgrading to 3.3?

 

I used to be able to do Inventory → Endpoints+Host Inventory → Vulnerability Assessment, select Endpoints on the upper-right bar and then search by Endp

...

How do you handle Low Severity alerts/issues?

want to know how you guys deal with low severity alerts.. 

do you monitor/analyze them or only focus on incidents  with medium/high/critical severity?

do you run any playbook automation against these low sev alerts?

are there any best practices from

...

PA_nts by L4 Transporter
  • 204 Views
  • 0 replies
  • 0 Likes

XSIAM - Vulnerability field (Issues)

Hi All.

 

Please, using "JSON Sample Incident Generator (Community Contribution)" app, is there any way to set "CATEGORY" field a value on Issues?.

 

Using "Classification & Mapping" and setting "Category" field to a specific value did not work.

 

Th

...

XSIAM V3.3 upgrade - anyone having issues?

Hi All, 

We have a XSIAM tenant running v3.2 and PAN upgraded to V3.3 yesterday (Nov 16th 2025) and since then we have a number of issues ie

- content pack updates (base/scripts etc) updates failing

- transformers missing as such custom playbook runs

...

PA_nts by L4 Transporter
  • 393 Views
  • 1 replies
  • 0 Likes

Timeout issue - Health Issue/Alerts in XSIAM

Hello,

 

We are seeing multiple health issues under collection type.

 

For example: 

Issue name: Collection error in the instance AWS_***  collector

Description: timeout while waiting for server to answer: request ********-****-****-****-**********.

...

Vinay_AS by L0 Member
  • 222 Views
  • 0 replies
  • 0 Likes
  • 126 Posts
  • 37 Subscriptions
Top Solution Authors
Top Liked Authors
Labels