Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

DR to DC failover completed; DR acts as back up server as expected but in DR "Make this the production server option is not grey out"

Hi Team, The customer has did the DR to DC failover but DR backup server has " Make this the production server" tab enabled blue. The client pointing that the option show be disabled. If it is enabled, any person can make backup server as production if the link is active, without making any changes at DC XSOAR GUI. This is critical. Any suggesti...

Configure notification email on new incident

Hello, I would like to enable email notifications for every new incident. I've configured an O365 EWS instance successfully, and set server.notification.using.send-mail to use its instance name. For now, I just want all notifications to be sent to a single email address. I noticed there's an option to configure preferences in the user prof...

M.Nayet by L0 Member
  • 574 Views
  • 0 replies
  • 0 Likes

How do I send an alert to XSOAR?

I see the classify, map and playbook logic in XSOAR and I see that a playbook can ask/pull/poll for info *from* and external tool, which might be done through an integration. But is there a way for an external tool to aynchronously *send/push* an *alert* (not incident) to XSOAR and have XSOAR receive the alert in real time? I can send new *inc...

Obtaining Whois Information for a List of IPs

I'm trying to perform whois queries on an array that contains the list of IPs. My understanding is that I can pass the array to the Inputs of the "ip (whois)" script. However, since there are over 1000 IPs, submitting them all at once results in an error. Is there a way to split the array into chunks of 50? I was considering using Transformers...

R.Henmi by L0 Member
  • 963 Views
  • 1 replies
  • 0 Likes

Automating SLA in XSOAR with Reminders and Reset on Updates

Hi team! First of all, thank you very much in advance for your help. I want to add an SLA to an incident in XSOAR so that if the SLA is breached, the incident is automatically closed. In theory, this is straightforward to implement by setting a timer, a task with a tag, and an automation to close the incident, as specified in the videos and ...

F.Otero by L1 Bithead
  • 4033 Views
  • 2 replies
  • 1 Likes

Resolved! XSOAR 8 + Export Data to On-premise for Retention Compliance

Hello all, I have an XSOAR 8.+ tenant and need to store my incidents from up to two years ago. I understand that by default XSOAR retention policy retains incidents based on license etc. Is there a way to export the data that is half a year old to a cold storage on-premise archive and what are the expected egress costs of such an action? Many ...

Customize System Emails

I see there is documentation on customizing system emails: https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Administrator-Guide/Customize-System-Emails I'm seeing placeholders such as {{ .username}} and {{ .invName}}. Where is the documentation on available placeholders that can be used?

Automating the regression testing of the Playbook

Hi. I am considering automating the regression testing of the Playbook. For instance, it would be ideal if we could confirm whether the existing paths can still transition smoothly when a user adds one more branch to the ConditionalTask in the Playbook. If anyone has a good idea, I would appreciate it if you could share it. Also, I would like...

MEiunyo1 by L1 Bithead
  • 1126 Views
  • 1 replies
  • 0 Likes

Query on the usage of 2 XSOAR's integrations

Hi Team, The customer wants to implement 2 integrations, so they are requesting the TAC support on the usage of 2 integrations. Note: No CS team available. Below are those 2 integrations.1. NCIIPC Threat Intel Feeds via normal API key.2. HPSM (Micro Focus) ticketing tools, while entering the prerequisites information it server URL part it ...

Pre Processing script for dropping multiple similar incidents

Hi Team, I need to find a way to drop similar events (by eventnames field) from QRadar when they are mirrored in in XSOAR by using a pre process rule I have checked for a native approach in Cortex Xsoar to do it but it seems that Pre-processing rules in XSOAR cannot natively count similar incidents based on a dynamic field like "eventname...

Automated Daily Report for XDR and XSOAR?

Hi all and happy Taco Tuesday!I'm part of a very small team of 3 that supports a retail company's domestic and international security & compliance operations, and I'm looking to automate some daily reporting that would ultimately be viewed in Confluence/Jira. Every morning our analyst goes over cyber security news feeds, XDR, and XSOAR to cr...

Propagation Label

Hi all,I imported a custom pack to XSOAR main account, but I don't want some tenants to use it so I want to use XSOAR propagation labels, but even if I set propagation labels, when I sync it distributes to tenants.Do you have any suggestion?

  • 1310 Posts
  • 46 Subscriptions
Top Solution Authors