Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

CSOAR Pre processing rule with scheduled jobs

How can we set the preprocess rule to drop any incidents created by schedule jobs? For example: any incident category=job and some incident field like description contains "False". The playbook in schedule Job, will run some tasks and condition and will mark the incident description with "False" if that incident is False and need to be dropped...

Securonix

Can someone help me? I have created an instance in the Securonix integration but I want to fetch incidents but I do not get the alerts from my SIEM SECURONIX. It should be noted that the user and everything is correct. But I would like to know if anyone in the community has had the same problem and how they solved it.

mgamarra by L0 Member
  • 848 Views
  • 0 replies
  • 0 Likes

Query on Filtering Closed Incidents by Time Frame in XSOAR dashboard

I'm in the process of creating a widget and need help retrieving details of incidents that were closed within a specific week or time frame, irrespective of their creation date. Additionally, I would like to know if there's a method to achieve this without using scripting. Could you please provide guidance on how to implement this functionality?...

ansusabu by L1 Bithead
  • 2975 Views
  • 5 replies
  • 0 Likes

Resolved! MS Defender XSOAR Integration daily re-auth.

Hello, used this integration guide (https://xsoar.pan.dev/docs/reference/integrations/microsoft-365-defender) and the integration pulls incidents just fine. Currently using a self-deployed application and device code flow. Problem I am running into is a daily re-auth for a user account using the device code flow. I suspect it might have to do wi...

Set Incident values from Integration

Hello all, I have customized a ticketing integration to our image. The last part I'm struggling with is returning values from the integration to incident fields.My usecase is that, SOC analyst will create a ticket inside our ServiceDesk application via button in Incident Layout. When this button is pressed, the command from the SD integration ...

XSOAR keeps firing the same incident

Hi All, My XSOAR instance is a cloud hosted environment running on the latest version 8 build. I have a playbook that sends a notification email to a user in response to a change in their account settings to confirm if recognized. The user is requested to respond via the webform link that the data collection task generates in the email that ...

PWJ2020 by L0 Member
  • 1484 Views
  • 2 replies
  • 0 Likes

Resolved! Stopping unnecessary "Message from Cortex XSOAR Security Operations Server" emails from DBOT

Hi Guys, After assigning an analyst to an incident we receive one email per task change from DBOT, that is very noisy and I don't see any reference on the documentation to customize the same. Highly appreciate if anyone can tell me how to get around this. The email is as below DBot has updated an incident 400681 Use-case Name .View it on https:/...

Issue with timestamp_range_start and timestamp_range_end Dates in XSOAR Elasticsearch Integration Command

Problem Description:The date filtering functionality for start and end dates in the Elasticsearch search command on XSOAR does not seem to be working correctly. The command used is as follows:!es-search index="index-runtime-evts" query="queryTest" timestamp_range_start="-2y" timestamp_range_end="now"I also tried entering a specific timestamp, su...

MF762 by L1 Bithead
  • 1044 Views
  • 1 replies
  • 0 Likes

Dashboard Graph Display Incident Count Per Month

Hello Live, I have a simple yet trivial question regarding displaying a graph showing each month's incident count consecutively. I can see it groups the count in a non-specified month order. Please see the graph below and take note of the seemingly random order of dates. Is there a way to display this correctly? I'm looking for September, Octob...

image.jpg

Resolved! unable to push the content from dev to prod

Hi All,I am attempting to push content from dev XSOAR to prod XSOAR, but I’m encountering a strange and frustrating error that lacks detailed information. I got following error when pushing content on dev "Failed committing changes. Error: Unexpected non-whitespace character after JSON at position 183 (line 2 column 1)"

Resolved! JSON Sample Incident Generator

I am trying to create "sample" alert/incidents in our XSIAM TEST environment for playbook testing based old previously worked alerts. Using the !ExportAlertContextToJSONFile command within an alert successfully creates a JSON file. After copying the "raw" JSON results the export command into the JSON Sample Incident Generator integration insta...

DBruce by L0 Member
  • 2159 Views
  • 1 replies
  • 0 Likes
  • 1307 Posts
  • 46 Subscriptions