Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! Add additional fields in Jira edit issue task

Hi All, 

 

"Jira-edit-Issue" task has some default Arguments as Inputs (eg: IssueID, priority,status, summary, description etc.,). Now I need to add new field as Inputs to Jira edit issue from XSOAR, fields like resolution, etc.

I tried editing the s

...

Himangi by L2 Linker
  • 899 Views
  • 2 replies
  • 0 Likes

SlackAskV2 Invalid Block Format

Hi folks, 

i am new with XSOAR and i try to create an approval workflow with SlackAskV2. 

Of course i prefer the default resonse type with buttons. And here's my problem. It does not work in the playbook editor.
I always get the following error, when

...

NDNico by L0 Member
  • 742 Views
  • 2 replies
  • 0 Likes

Resolved! Grid Field Setup In XSOAR

Dear All

 

I am trying to setup a new Grid Field in XSOAR.

I have added few column header with the field names that I require however, in the layout, not all columns are shown.

There are certain fields which are missing in the display.

 

Uploading report via demisto api post request

Hello everyone,

 

I am trying to upload json file to create report. Despite I tried tons of way I couldn't send the body properly. demisto-api-post request need multipart/form-data content type. Is there any way to send raw json properly?

 

Here is m

...

Paint markdown table cells or rows

Hello,

We use markdown tables to show the analysts' incident data. We use them for manual tasks in details as in layouts. We'd like to paint those cells where the data shown is critical. For example, on a markdown table where some hashes are detonate

...

Josep by L4 Transporter
  • 2390 Views
  • 3 replies
  • 0 Likes

XSOAR Threat intel IOC Ingestion to Splunk

Hi,

 

We have created EDL query to ingest IOC to the SPLUNK from XSOAR Threat intel management Platform.

 

We have to know that Refresh List will work  and how to get all IOC via EDL query from XSAOR

 

Kindly share any best practice any one implement

...

Resolved! Create widget for bioc and ioc rule numbers

Hello everyone,

 

I am trying to get numbers of bioc and ioc rules from our xdr integration. I want to create a widget to see that how many ioc and bioc rules added week by week. Do anyone have idea for this?

 

Thanks in advance.

 

Cortex XDR Cortex

...

query(group) indicators by domain name

If I have a tenant/account that has incidents.

some of those incidents have indicators / entities tied to abc.com or xyz.com

Is there a way to query for, show me all the incidents that have hostnames or account names that end in abc.com?

Wasn't having l

...

JoshBoyd by L2 Linker
  • 690 Views
  • 1 replies
  • 0 Likes

Resolved! Generating reports through automation

Hi everyone,

 

In our environment, we are supposed to generate reports through playbooks since we want to be able to customize the template according to the incident type. Executing the report is simple but downloading is not that simple.

 

I am foll

...

  • 940 Posts
  • 30 Subscriptions