Cortex XSIAM Discussions

Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.
About Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.

Discussions

Welcome to the Cortex XSIAM Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 314 Views
  • 0 replies
  • 0 Likes

XQL Query for a Correlation Rules

I am trying to write a xql query for a correlation rule in which alert or incident will trigger for below condition.
Condition:

Threshold: Only once on match 2

Detect on unique values of: hostname

So, my question is. how to write "Detect on unique valu

...

XSIAM and ITSM Integration question

Hi All,

anyone successfully done this to date?

my integration works in that I can communicate with ITSM ok.

however, I have the following issue.. our ITSM Dev team have provided some fields that is required from XSIAM playbook to ingest the tickets s

...

PA_nts by L3 Networker
  • 469 Views
  • 0 replies
  • 0 Likes

OT Security | XQL

Hello community,

Can someone please help me with build some XQL queries to monitor some OT environment, or give me some tips and idea for this topic.

thnx 

Y.Zalsov by L1 Bithead
  • 439 Views
  • 0 replies
  • 0 Likes

Lookups to compare the difference

I am trying to find clients missing software, I found all the clients WITH the software, dumped them into a a lookup and now trying to find the difference, basically return the ones NOT in the lookup,
So something like this: 

dataset = host_inventory
|

...

XSOAR engine upgrade

For engine upgrade , do we have to manually run the upgrade installer file in engines or just clicking on the “ upgrade engine” button in the UI of XSiam would be enough?

Resolved! Using XQL queries in XSIAM playbooks

Hi Team,

 

I'd like to enquire whether Cortex XSIAM can search the logs of a dataset using XQL Query in a Playbook.
Cortex XSOAR can do that for Cortex XDR using the integration of "Cortex XDR - Search and Compare Process Executions - XQL Engine" .

  • 67 Posts
  • 35 Subscriptions
Top Liked Posts
Top Liked Authors
Labels