Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! About XSOAR Free Edition Licenses

Dear All, I installed the free version of XSOAR.However, when I installed XSOAR after the 30-day free license period, the license was not applied properly when I applied the license file. Can I get the free license again by applying again from the following site? https://start.paloaltonetworks.com/sign-up-for-community-edition.html?hsCtaTrac...

Resolved! Field Change Script To System Fields

Hey CommunityDid anyone ever attach a field change trigger script to a system field? I guess it can't be done directly but is there a work around? Also, is there a way to run a script as soon as incident is created Cortex XSOAR

Resolved! Can XSOAR disk space vary automatically?

Hi everyone! I hope you're doing well. I wanted to ask something: Is it possible for the disk usage on my XSOAR to sometimes be at 60% and other times drop below that number? I mean, without me taking any action, can the disk space percentage decrease on its own? Thanks in advance!

CSOAR Pre processing rule with scheduled jobs

How can we set the preprocess rule to drop any incidents created by schedule jobs? For example: any incident category=job and some incident field like description contains "False". The playbook in schedule Job, will run some tasks and condition and will mark the incident description with "False" if that incident is False and need to be dropped...

Securonix

Can someone help me? I have created an instance in the Securonix integration but I want to fetch incidents but I do not get the alerts from my SIEM SECURONIX. It should be noted that the user and everything is correct. But I would like to know if anyone in the community has had the same problem and how they solved it.

mgamarra by • L0 Member
  • 917 Views
  • 0 replies
  • 0 Likes

Query on Filtering Closed Incidents by Time Frame in XSOAR dashboard

I'm in the process of creating a widget and need help retrieving details of incidents that were closed within a specific week or time frame, irrespective of their creation date. Additionally, I would like to know if there's a method to achieve this without using scripting. Could you please provide guidance on how to implement this functionality?...

ansusabu by • L1 Bithead
  • 3127 Views
  • 5 replies
  • 0 Likes

Resolved! MS Defender XSOAR Integration daily re-auth.

Hello, used this integration guide (https://xsoar.pan.dev/docs/reference/integrations/microsoft-365-defender) and the integration pulls incidents just fine. Currently using a self-deployed application and device code flow. Problem I am running into is a daily re-auth for a user account using the device code flow. I suspect it might have to do wi...

Set Incident values from Integration

Hello all, I have customized a ticketing integration to our image. The last part I'm struggling with is returning values from the integration to incident fields.My usecase is that, SOC analyst will create a ticket inside our ServiceDesk application via button in Incident Layout. When this button is pressed, the command from the SD integration ...

XSOAR keeps firing the same incident

Hi All, My XSOAR instance is a cloud hosted environment running on the latest version 8 build. I have a playbook that sends a notification email to a user in response to a change in their account settings to confirm if recognized. The user is requested to respond via the webform link that the data collection task generates in the email that ...

PWJ2020 by • L0 Member
  • 1607 Views
  • 2 replies
  • 0 Likes

Resolved! Stopping unnecessary "Message from Cortex XSOAR Security Operations Server" emails from DBOT

Hi Guys, After assigning an analyst to an incident we receive one email per task change from DBOT, that is very noisy and I don't see any reference on the documentation to customize the same. Highly appreciate if anyone can tell me how to get around this. The email is as below DBot has updated an incident 400681 Use-case Name .View it on https:/...

Issue with timestamp_range_start and timestamp_range_end Dates in XSOAR Elasticsearch Integration Command

Problem Description:The date filtering functionality for start and end dates in the Elasticsearch search command on XSOAR does not seem to be working correctly. The command used is as follows:!es-search index="index-runtime-evts" query="queryTest" timestamp_range_start="-2y" timestamp_range_end="now"I also tried entering a specific timestamp, su...

MF762 by • L1 Bithead
  • 1095 Views
  • 1 replies
  • 0 Likes

Dashboard Graph Display Incident Count Per Month

Hello Live, I have a simple yet trivial question regarding displaying a graph showing each month's incident count consecutively. I can see it groups the count in a non-specified month order. Please see the graph below and take note of the seemingly random order of dates. Is there a way to display this correctly? I'm looking for September, Octob...

image.jpg
  • 1310 Posts
  • 46 Subscriptions
Top Solution Authors