Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Need to Know when the incident was modified first time

I created "firstmodificationdate" field in short text type to apply all the incidents. the purpose of that, I want to store the when the incident was modified at first time. first medication of each incident date will be stored in the "firstmodificationdate" field for all type of incidents. Is there any possible to do that in xsoar?

Can we migration xsoar from standalone to multi tenant

Is it possible to migration xsoar from standalone to multi tenant ? I have try to migration from xsoar standalone to multi tenant used method "Migrate Data to Another Server for Multi-Tenant" ref. https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.8/Cortex-XSOAR-Administrator-Guide/Migrate-Data-to-Another-Server-for-Multi-TenantBut found ...

Siwawut by L0 Member
  • 1089 Views
  • 1 replies
  • 0 Likes

Resolved! Query on deleting incidents

Hi Team, The standard customer has a query regarding deleting an incident on XSOAR. 1. In terms of performance usage when delete an incident or multiple selected incidents on the XSOAR console (Incidents page) and when delete an incident or multiple selected incidents through API call on endpoint POST /incident/batchDelete. The question is, wh...

Resolved! Rename table headers

Hi all 😀 I have a table of data in Cortex XSOAR (e.g., a list of dictionaries with results from a query), and I need to rename one of the column headers before processing it further in my playbook. For example, I want to rename the column oldName to newName. How can I achieve this either within a script, automation, or as part of a playbook...

Extract data in value

To extract the specified highlighted dictionary value from the context data mentioned below, which script command and transformer should be utilized....? [{'type': 'events_fetched', 'value': '1'}, {'type': 'rules', 'value': '[{"id":112363,"name":112363,"type":"CRE_RULE"}]'}, {'type': 'event_count', 'value': '1'}, {'type': 'magnitude', 'value': ...

Unable to Control Column Width in Markdown Tables in XSOAR

I am trying to create a table using Markdown in Cortex XSOAR, but I can't control the width of the columns. I need to make one column wider than the others. However, Markdown in XSOAR seems to automatically adjust the width based on the content, and I can't find a way to set fixed column widths. What I've Tried: Standard Markdown table formatti...

SanDev by L2 Linker
  • 2118 Views
  • 3 replies
  • 1 Likes

Cisco ESA (Cisco IronPort) and XSOAR Integration

Hi all, I'm facing an issue with my integration between Cisco ESA and XSOAR. When I search for specific emails that contain attachments or subjects in Arabic, the SOAR can fetch and display them without any problem. However, when I try to search specifically using an Arabic subject line, the SOAR fails to perform the search. Has anyone encou...

Resolved! XSOAR 8 Engine Upgrade Failure

Did anyone recently observed that the engines are failing to connect with a reason saying "update required"? It should be get updated automatically since those are shell based. Cortex XSOAR

SlackASKV2 Response Stuck

Hi All, Yesterday I dont know why slackaskv2 suddenly gave me error because of block key format. I fixed it but slack send message to channel using button and when user click on button no response come back. Idk whats wrong with this annoying stuff. Any useful suggestion pls Cortex XSOAR

TSOARSupport_0-1724385873638.png

Cortex XSOAR Fetch Incident In Exabeam Advanced Analytics

Hi Everyone, I'd like to fetch incidents on Exabeam Advanced Analystics, however, when trying to create an instance I get the following error each time I specify the value Exabeam incident in the Fetch type: Error in API call [400] - Bad Request {"message": "attempt to access uninitialized field", "stackTrace": [], "apiErrorCode": "INTERNAL_...

MS Graph Teams (Community Edition)

Has anybody used the O365 Teams (Using Graph API) (Community Contribution) integration to send chat messages and was able to successful @ a user?I'm looking at the https://learn.microsoft.com/en-us/graph/api/chatmessage-post?view=graph-rest-1.0&tabs=http docs for sending messages but I am not sure if the body arg in !msgraph-teams-send-messa...

Failed to add entries

Team, While pushing the ioc to arcsight active list using arcsight resource id is not found with status code 404.. And also as I checked the resourceID is similar with xsoar and arcsight...but still issue persits. #arcsight #xsoar #as-qdd-entries

To add the Description while push IOCs to XDR

Hello Team, We need to add the description comment to IOC's while pushing to XDR. Already description was added to Indicators it was visible in Indicators Page. while pushing the IOC's to XDR the description was not adding to it when seeing in XDR console the comment column was empty. (Find the attached screenshot for reference) Regards...

cV V by L2 Linker
  • 2011 Views
  • 5 replies
  • 0 Likes
  • 1298 Posts
  • 45 Subscriptions