Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Query on creating custom docker images

Hi, I have some questions regarding creating the custom docker images.

1. Is it possible to create the custom docker images not using the war room? In the docs, the docker images can be created via war room command, but I want to create docker image i

...

Securonix

Can someone help me? I have created an instance in the Securonix integration but I want to fetch incidents but I do not get the alerts from my SIEM SECURONIX. It should be noted that the user and everything is correct. But I would like to know if any

...

mgamarra by L0 Member
  • 214 Views
  • 0 replies
  • 0 Likes

SQL results into layout

Hi ,

 

I’m running a playbook that generates multiple SQL results. What are the best practices for displaying these effectively in the incident layout? Should I use Markdown, custom sections, or widgets? Any tips for handling this?

 

Thanks!

Resolved! MS Defender XSOAR Integration daily re-auth.

Hello, used this integration guide (https://xsoar.pan.dev/docs/reference/integrations/microsoft-365-defender) and the integration pulls incidents just fine. Currently using a self-deployed application and device code flow. Problem I am running into i

...

Set Incident values from Integration

Hello all,

 

I have customized a ticketing integration to our image. The last part I'm struggling with is returning values from the integration to incident fields.

My usecase is that, SOC analyst will create a ticket inside our ServiceDesk application

...

XSOAR keeps firing the same incident

Hi All,

 

My XSOAR instance is a cloud hosted environment running on the latest version 8 build.

 

I have a playbook that sends a notification email to a user in response to a change in their account settings to confirm if recognized. The user is req

...

PWJ2020 by L0 Member
  • 446 Views
  • 2 replies
  • 0 Likes
  • 1122 Posts
  • 35 Subscriptions
Top Solution Authors
Top Liked Authors