Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.
About Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.

Discussions

Welcome to the Cortex XSIAM Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 847 Views
  • 0 replies
  • 0 Likes

IP Enrichment from Internal IP Address Range

Is it possible to build API request to enrich details about the local IP and in which Internal IP CIDR range it is exists? We have this data in XSIAM configuration. 

For big enterprise with many networks its useful enrichment to know the network locat

...

MDovirak by L1 Bithead
  • 303 Views
  • 0 replies
  • 0 Likes

XSIAM Pending Playbooks

In XSIAM, how can I determine (query ?) the current total number of playbooks with a playbook run status of "Pending" via an XSIAM command or XSIAM API, as opposed to filtering in UI ?  The use case is to be "proactively" notified (via workflow or jo

...

DBruce by L0 Member
  • 440 Views
  • 0 replies
  • 0 Likes

XSIAM XQL Query help needed

Hi All,

So i need some xql query help please..

Example : I have 2 datasets in xsiam, one called 'xdr_data', and another called 'ioc',
In my 'ioc' dataset I have a field called 'indicator' with different values ie 4.4.4.4; 1.2.3.4 for example.. these

...

PA_nts by L4 Transporter
  • 585 Views
  • 1 replies
  • 0 Likes

Marketplace Content pack update - best practices

Hi All,

How do you manage content updates in the market place currently?

Any best practices to follow as it seems this is a manual process to review the release notes and plan updates accordingly.

Is there a way to notify via email if new content pac

...

PA_nts by L4 Transporter
  • 294 Views
  • 0 replies
  • 0 Likes

Collecting IIS Log

Hi,

I have configured the filebeat to collect the IIS log,

but I don't see any dataset related to the IIS log in the dataset table and also don't know how and in which dataset to get those logs.

this the filebeat configuration

---
filebeat.modules:
- m

...

API to get data from lookup dataset

Hi All,

in XQL - i can run a query and dump the data into a lookup dataset, this works, then i can run a local query against this lookup dataset and i see all the data as expected.

however, when i run an API request against (https://api-yourfqdn/publ

...

PA_nts by L4 Transporter
  • 304 Views
  • 0 replies
  • 0 Likes
  • 115 Posts
  • 37 Subscriptions
Top Solution Authors
Top Liked Posts
Top Liked Authors
Labels