Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

XSOAR Prod Is Not Installing Updates From Dev

I have two xsoar tenant one is dev and other is prod. on prod i have main tenant and tms tenant. i pushed content from dev to repo and from main on prod side get the content from git. i saw push is fine and commit is succesful when push from dev side

...

Syedhkt by L2 Linker
  • 538 Views
  • 1 replies
  • 0 Likes

Rasterize URL returns an empty png

Hi guys,

 

Currently working on a Brand Abuse response playbook and when trying to take a screenshot for retrieving evidences it returns an empty, white png.

My config of the instance is as follows:

I tried, both Rasterize modes, Headless CLI and Web

...

FOtero_0-1741085590994.png
FOtero_3-1741085774251.png
F.Otero by L1 Bithead
  • 467 Views
  • 1 replies
  • 0 Likes

Playbook Showing Keep Running & Running

Dear All,

I am facing really annoying issue. I have setup integration(mapper,type) and playbook hit very well on incident but the problem is the playbook showing running and running for all incidents and not run. I try to pause and resume but it also

...

Syedhkt by L2 Linker
  • 725 Views
  • 1 replies
  • 0 Likes

CSV Feed Same Indicators

Hi,


I am using CSV Feed integration and a delta triggered Job, that is triggering whenever there is a new item (IP indicator) in CSV feed. The playbook under job is adding only new and modified indicators which have "tag":"pending_ip".


Now, I underst

...

MMagdic by L2 Linker
  • 432 Views
  • 0 replies
  • 0 Likes

Engine in cloud - design concept

I have a cloud instance of XSOAR, with set of technologies in cloud and on prem as well, my initial thought is to have an engine for each group, that means two engines, and separate the technologies accordingly, any thought on that and what is challe

...

ahmad by L0 Member
  • 523 Views
  • 1 replies
  • 0 Likes

ElasticSearch integration es-eql

Can someone, anyone, post a properly formatted (working) !es-eql-query command run in XSOAR.  I am apparently too dumb to get it working.  For context, here's the ES|QL query I'm trying to make work.

FROM logs-* | WHERE winlog.event_data.LogonProcessN

...

Increasing docker image pull timeout

Hey everyone,

I am looking for a way to increase the docker image pull timeout from its 5 minutes default.

The error occurs due to a combination of very slow network connection (a traffic shaping option which I cannot change) and big images (e.g. dem

...

JanDrees by L0 Member
  • 1309 Views
  • 1 replies
  • 0 Likes
  • 1282 Posts
  • 43 Subscriptions
Top Liked Posts
Top Liked Authors