Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

How to Automatically Send an Email When an Incident is Created in XSOAR?

Hello, I want to automatically send an email whenever an incident is created in XSOAR. I’ve created a playbook and written a simple script that sends an email for a specific incident when executed within the playbook. However, I’d like to automate this process so that an email is sent automatically for every incident without manually triggering ...

O.Isik by L0 Member
  • 1471 Views
  • 1 replies
  • 0 Likes

Remove apps with Playbook XSOAR XDR

I would like to know about your experience. How do you handle uninstalling software on specific devices that are not allowed and need to be removed via Cortex XDR with Cortex XSOAR Playbooks without the user see the uninstall.

tlmarques by L4 Transporter
  • 886 Views
  • 1 replies
  • 0 Likes

Web File Repository Integration error "Failed to execute wfr-status command"

Hi, Anyone encountered the following error when executing "wfr-status"? Command: !wfr-status(Web File Repository) Reason Failed to execute wfr-status command. Error: Verify that the server URL parameter is correct and that you have access to the server from your host. Error Type: <requests.exceptions.ConnectionError> HTTPCo...

SerKuan by L0 Member
  • 1194 Views
  • 2 replies
  • 0 Likes

Resolved! About XSOAR Free Edition Licenses

Dear All, I installed the free version of XSOAR.However, when I installed XSOAR after the 30-day free license period, the license was not applied properly when I applied the license file. Can I get the free license again by applying again from the following site? https://start.paloaltonetworks.com/sign-up-for-community-edition.html?hsCtaTrac...

Resolved! Field Change Script To System Fields

Hey CommunityDid anyone ever attach a field change trigger script to a system field? I guess it can't be done directly but is there a work around? Also, is there a way to run a script as soon as incident is created Cortex XSOAR

Resolved! Can XSOAR disk space vary automatically?

Hi everyone! I hope you're doing well. I wanted to ask something: Is it possible for the disk usage on my XSOAR to sometimes be at 60% and other times drop below that number? I mean, without me taking any action, can the disk space percentage decrease on its own? Thanks in advance!

CSOAR Pre processing rule with scheduled jobs

How can we set the preprocess rule to drop any incidents created by schedule jobs? For example: any incident category=job and some incident field like description contains "False". The playbook in schedule Job, will run some tasks and condition and will mark the incident description with "False" if that incident is False and need to be dropped...

Securonix

Can someone help me? I have created an instance in the Securonix integration but I want to fetch incidents but I do not get the alerts from my SIEM SECURONIX. It should be noted that the user and everything is correct. But I would like to know if anyone in the community has had the same problem and how they solved it.

mgamarra by L0 Member
  • 767 Views
  • 0 replies
  • 0 Likes

Query on Filtering Closed Incidents by Time Frame in XSOAR dashboard

I'm in the process of creating a widget and need help retrieving details of incidents that were closed within a specific week or time frame, irrespective of their creation date. Additionally, I would like to know if there's a method to achieve this without using scripting. Could you please provide guidance on how to implement this functionality?...

ansusabu by L1 Bithead
  • 2651 Views
  • 5 replies
  • 0 Likes

Resolved! MS Defender XSOAR Integration daily re-auth.

Hello, used this integration guide (https://xsoar.pan.dev/docs/reference/integrations/microsoft-365-defender) and the integration pulls incidents just fine. Currently using a self-deployed application and device code flow. Problem I am running into is a daily re-auth for a user account using the device code flow. I suspect it might have to do wi...

Set Incident values from Integration

Hello all, I have customized a ticketing integration to our image. The last part I'm struggling with is returning values from the integration to incident fields.My usecase is that, SOC analyst will create a ticket inside our ServiceDesk application via button in Incident Layout. When this button is pressed, the command from the SD integration ...

XSOAR keeps firing the same incident

Hi All, My XSOAR instance is a cloud hosted environment running on the latest version 8 build. I have a playbook that sends a notification email to a user in response to a change in their account settings to confirm if recognized. The user is requested to respond via the webform link that the data collection task generates in the email that ...

PWJ2020 by L0 Member
  • 1327 Views
  • 2 replies
  • 0 Likes
  • 1298 Posts
  • 45 Subscriptions