Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

False Positives Microsoft Teams Large Upload

Hey,


I need your help.

We are receiving alerts "XDR Incident 945 - 'Large upload (generic)' generated by #XDR Analytics detected...

 

Basically, this appears when the user makes a call, shares documents, or shares their screen (using Microsoft Teams)

...

Resolved! Playbook waiting for a manual Set task

Hello community,

 

I have some playbooks that are responsible for closing incidents in the various sources (XDR, QRadar, XSOAR, JIRA, ...) once I enter a reason or reason for them to be closed.

 

 

I have done this using a "Set" automation that wa

...

rafaelusano_0-1703592508555.png
rafaelusano_1-1703592616387.png

Per Month Query using Beve Query Syntax

Hi,

 

I am trying to take a sum of incidents over a given time, and divide this sum per month, using Beve Syntax.

I there any syntax that would give me a per-month break down?  So I can take incidents per month, and display them in a widget using a b

...

Resolved! About XSOAR Free Edition Licenses

Dear All,

 

I installed the free version of XSOAR.
However, when I installed XSOAR after the 30-day free license period, the license was not applied properly when I applied the license file.

 

Can I get the free license again by applying again from th

...

MS Graph Teams (Community Edition)

Has anybody used the O365 Teams (Using Graph API) (Community Contribution) integration to send chat messages and was able to successful @ a user?

I'm looking at the https://learn.microsoft.com/en-us/graph/api/chatmessage-post?view=graph-rest-1.0&tabs=

...

incidents pulling time

Hi , 
in my Qradar integration I don't have this parameter , 

I have enabled the "Long Running Instance" and still it takes too long for the incidents to be fetched.

Is there a way to manually configure the Incident Fetch Interval. 
I'm using IBM QRad

...

Bar_Magnezi_0-1702974903501.png

Resolved! Custom Widget Xsoar

Hi, I am trying to create a custom widget that calculate follwing (Total Incident+ Total Command Execution) with date paramters adjusted by widget. I tried to implement this with JSON method and Automation Script but unable to get the solution. Can y

...

Syedhkt by L1 Bithead
  • 803 Views
  • 1 replies
  • 0 Likes
  • 976 Posts
  • 31 Subscriptions
This widget could not be displayed.
Top Liked Authors