Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.
About Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.

Discussions

XSIAM and ITSM Integration question

Hi All,

anyone successfully done this to date?

my integration works in that I can communicate with ITSM ok.

however, I have the following issue.. our ITSM Dev team have provided some fields that is required from XSIAM playbook to ingest the tickets s

...

PA_nts by L3 Networker
  • 77 Views
  • 0 replies
  • 0 Likes

OT Security | XQL

Hello community,

Can someone please help me with build some XQL queries to monitor some OT environment, or give me some tips and idea for this topic.

thnx 

Y.Zalsov by L1 Bithead
  • 121 Views
  • 0 replies
  • 0 Likes

Lookups to compare the difference

I am trying to find clients missing software, I found all the clients WITH the software, dumped them into a a lookup and now trying to find the difference, basically return the ones NOT in the lookup,
So something like this: 

dataset = host_inventory
|

...

XSOAR engine upgrade

For engine upgrade , do we have to manually run the upgrade installer file in engines or just clicking on the “ upgrade engine” button in the UI of XSiam would be enough?

Resolved! Using XQL queries in XSIAM playbooks

Hi Team,

 

I'd like to enquire whether Cortex XSIAM can search the logs of a dataset using XQL Query in a Playbook.
Cortex XSOAR can do that for Cortex XDR using the integration of "Cortex XDR - Search and Compare Process Executions - XQL Engine" .

Integrating Proofpoint TAP into XSIAM

Hi,

 

I would like some guidance on which data source I should use when integrating Proofpoint TAP into XSIAM.

 

In the content pack "Proofpoint TAP" on the marketplace,

 

There is a data source named "Proofpoint TAP".  This data source has the abili

...

Rule list

would like to see a list of rules regarding the types of incidents I receive in XSIAM.

I am not talking about IOC/BIOC 

 

Can anyone help with the path ?

Resolved! Coalescing of events in XSIAM?

Looking to migrate from QRadar/QRoC to XSIAM


In QRadar/QRoC, coalescing works in the following manner:

https://www.ibm.com/support/pages/qradar-how-does-coalescing-work-qradar

 

The goal of coalescing is to reduce the need for storage of events for c

...

Widget Library XQL Query

Hi All,

So in the xsiam portal under 'Dashboard and reports' there is a pre-defined list of Widgets in the library..

Within the 'system monitoring' library there is a widget called 'daily consumption' which is great to identify data sources ingestion

...

PA_nts by L3 Networker
  • 539 Views
  • 1 replies
  • 0 Likes

XSIAM Multi-Tenancy

How does multi-tenancy work for MSSPs in XSIAM? 
We are looking to use XSIAM as the core SecOps tooling to replace our current SIEM and we were wondering how does the multi-tenancy function work?  

Simple QXL Query help needed

Hi All,

withing query builder i have a very basic query as per below..

 

dataset = metrics_source
| fields _vendor , _product , total_size_bytes

 

which shows me the data sources and the amount of ingested data per source which is fine over a period

...

PA_nts by L3 Networker
  • 621 Views
  • 1 replies
  • 0 Likes

Resolved! High Memory usage of Cortex Agent

Hi Team,

 

Currently we are currently using XSIAM Agent v8.4, and it is consuming 300+mb of memory. How can we minimize its memory usage?

 

Please see attached photo as reference.

 

Thank you!

  • 32 Posts
  • 29 Subscriptions
Labels