Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! Stopping unnecessary "Message from Cortex XSOAR Security Operations Server" emails from DBOT

Hi Guys, After assigning an analyst to an incident we receive one email per task change from DBOT, that is very noisy and I don't see any reference on the documentation to customize the same. Highly appreciate if anyone can tell me how to get around this. The email is as below DBot has updated an incident 400681 Use-case Name .View it on https:/...

Issue with timestamp_range_start and timestamp_range_end Dates in XSOAR Elasticsearch Integration Command

Problem Description:The date filtering functionality for start and end dates in the Elasticsearch search command on XSOAR does not seem to be working correctly. The command used is as follows:!es-search index="index-runtime-evts" query="queryTest" timestamp_range_start="-2y" timestamp_range_end="now"I also tried entering a specific timestamp, su...

MF762 by L1 Bithead
  • 929 Views
  • 1 replies
  • 0 Likes

Dashboard Graph Display Incident Count Per Month

Hello Live, I have a simple yet trivial question regarding displaying a graph showing each month's incident count consecutively. I can see it groups the count in a non-specified month order. Please see the graph below and take note of the seemingly random order of dates. Is there a way to display this correctly? I'm looking for September, Octob...

image.jpg

Resolved! unable to push the content from dev to prod

Hi All,I am attempting to push content from dev XSOAR to prod XSOAR, but I’m encountering a strange and frustrating error that lacks detailed information. I got following error when pushing content on dev "Failed committing changes. Error: Unexpected non-whitespace character after JSON at position 183 (line 2 column 1)"

Resolved! JSON Sample Incident Generator

I am trying to create "sample" alert/incidents in our XSIAM TEST environment for playbook testing based old previously worked alerts. Using the !ExportAlertContextToJSONFile command within an alert successfully creates a JSON file. After copying the "raw" JSON results the export command into the JSON Sample Incident Generator integration insta...

DBruce by L0 Member
  • 2005 Views
  • 1 replies
  • 0 Likes

Incident Parent-Child Relationship

I'm looking to establish a hierarchical relationship for linking incidents in XSOAR, specifically a parent-child structure. Currently, the platform allows for linking incidents without hierarchy and creating child incidents under a parent ticket. However, it does not permit linking existing incidents as children. Is there a way to add existing...

XSOAR Reports and Count Problems

Hi, We create two different queries by changing the date range in the reports. These two queries show a different number of incidents for the same day (Jun 24). We tried various queries in the query field. The result did not change both with and without the query. Is there anyone experiencing this issue and finding a solution?

Widget error when Report is scheduled

Hello, I created a simple widget using Python. The code fetches a list from XSOAR, extracts a number, and the widget displays that number. Nothing more. The widget works perfectly when viewed in the report interface or when executed in the playground. However, when the report is scheduled, it shows a "JavaScript" error. Could you help me unders...

SanDev_0-1724574278104.png
SanDev by L2 Linker
  • 906 Views
  • 1 replies
  • 0 Likes

Install Docker Images In XSOAR

Hi Everyone, I need to run phishing model and for that I need demisto/ml docker image. I intsalled machine learning content pack but still not get or see this docker image thats why I'm unable to run that model. I also ready info from here but still confused https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.11/Cortex-XSOAR-Administrator-...

XSOAR hosting docker container problem (exit status 125)

Hey, I have a xsoar instance hosted by PA (saas access) and today none of my containers seems to work. Any script run gives the following message Error from Scripts is : Script failed to run: "docker images demisto/python3:3.10.13.86272" with error "exit status 125" and output "Error: cannot re-exec process to join the existing user namespace H...

Missing context in indicator preview. I executed an NVD reputation command on CVE via a custom script.

Hi Team, The standard customer, where there is missing context in indicator preview. I executed an NVD reputation command on CVE via a custom script (CV Reputation).The results are in the attached playground data, but they're not reflected in the indicator sample. Please refer the screenshot. What has been done: Non- working:Integration: Nis...

Creating usecase with addEntitlement

Hello everyone, I'm try to make a usecase where it will be possible to send email to the XSOAR and instead of creating new incident the email content will be delivered to already open incident based on Incident id or UID with addEntitlement.after creating an entitlement I send email to the XSOAR (I got ews V2 setup and working) with the entitle...

A.Levy by L0 Member
  • 1121 Views
  • 2 replies
  • 0 Likes

Creation of flows and pause by weekday schedules

I would like your kind support in telling me if there is a procedure to pause task flows by schedules. For example, I want a playbooks to have 2 flows: The first flow I want to be activated from Monday to Friday and the second flow I want to be activated only on Saturdays and Sundays.

mgamarra by L0 Member
  • 1299 Views
  • 1 replies
  • 0 Likes
  • 1298 Posts
  • 45 Subscriptions