Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! Unable to send Slack block messages

I've been trying to send a block message from the SlackBlockBuilder automation. However, when I try to test it out via the debugger panel, it would result in an error.

 
Spoiler
Command: 
!SlackBlockBuilder list_name="SLACKV3_BLOCK_ASK_URLAL
...

IDarma by L0 Member
  • 1810 Views
  • 3 replies
  • 0 Likes

Delete File from War Room

Hi everyone,

 

I would like to ask is it possible to permanently delete the downloaded file in War Room? My team wants to make use of the Jobs function in XSOAR to handle files, and the file should be deleted in XSOAR after handling it.


Thanks,

Eliza

ElizaWan by L0 Member
  • 2995 Views
  • 3 replies
  • 0 Likes

Access to XSOAR Community edition

Hello everybody,

 

after reading through some of the threads here, most people run into a similar issue as I did. 

Not receiving the URL to download - has anyone found a suitable solution? 

 

I used a company email, I waited a week for it to come aft

...

JanGrob by L1 Bithead
  • 1268 Views
  • 2 replies
  • 0 Likes

Using Microsoft Authenticator MFA

Hello LiveComm,

I am working on using MFA for authentication to xsoar on a server that has Active Directory (On-Prem) SAML authentication already in use. The use case is to require the user to authenticate using the Microsoft Authenticator app. I hav

...

Community Edition

Hello, I have signed up for the community edition, however I have never received the download URL. Also, I signed up for the DFIR, but cannot access the slack, as the link is expired when sent.

loyglenn by L0 Member
  • 1546 Views
  • 2 replies
  • 0 Likes

how can I get cortex Community Edition

Hi,

I filled out the form for the community edition at https://start.paloaltonetworks.com/sign-up-for-community-edition.html. I have received a confirmation email and an email for more information I have replied.

 

unfortunately I get no response to use

...

ten4you by L0 Member
  • 4607 Views
  • 4 replies
  • 0 Likes

Creating a Queue on Slack Integration

Hello all, 

I am working with Slack from the playbook level where a message summarizing an incident is sent followed by Slackask automation to ask users on a channel to confirm the information with two interactive buttons. Take note that the flow has

...

XSOAR Incident Re Run

soemtimes for testing purpose we need to create similar incident again but I am stuck at this phase. I have exisiting incident and i want to re run it(either manually create, duplicate and re run it or just simply re run exisitng incident, or importi

...

Syedhkt by L2 Linker
  • 1225 Views
  • 2 replies
  • 0 Likes

XSOAR Upgradtion Issue

Cortex XSOAR 8 will have a new FQDN and IP Address in the new platform. May I know is there any existing playbook have pulled the XSOAR data, and export to third-party platform automatically? If yes, it may require to re-configure the IP Address.

 

C

...

Syedhkt by L2 Linker
  • 857 Views
  • 2 replies
  • 0 Likes
  • 1110 Posts
  • 34 Subscriptions