Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

XSOAR SLA Script

Hi everyone,

 

I have a question regarding SLA tagged scripts on XSOAR. 

I have a field-change-triggerred script that starts an SLA timer within automation if the field is changed to certain values. This part is okay and we observe that the sla timer

...

SplunkPy Integration

Hi everyone,
I get data from splunk with the "search index=notable" query using Splunkpy. I assign the incoming data to the type named Splunk Generic Notable by default. Here, when an incident occurs, there are fields such as event_code, process_name

...

Ability to paste images in Incident Tasks

As in War Room, it would be very useful to be able to paste an image from the clipboard using Ctrl+V for Add-on type tasks. For example, this could be provided through the add-on pop-up (Screenshot 2) in the Incident Tasks section (Screenshot 1).

Cor

...

Splunk Search Result Issue

Dear All,

I have query that return 11587 records, i checked on splunk. I run this query on xsoar but it showed me total record is 11587 but the actual data is 4900 i trying to figure out, i checked event limit size, query setting all fine but still i

...

XSOAR Mark war room entries as note

Hi everyone,

 

I have button in the incident layout and the script it triggers creates a new incident and posts all of the war room entries to the new incident. In the incident, we have some notes that should also be seen as notes in the new incident

...

Retrieve screenshots from Notes section

Hi!

 

We are trying to give more importance to XSOAR within our SOC processes. As part of the changes we are introducing, we want all alert documentation to be done from now on in the 'Notes' section of each XSOAR incident.

 

The issue we are facing

...

adocasar by L1 Bithead
  • 581 Views
  • 2 replies
  • 0 Likes

WHOIS Integration - Connection Refused Errors

Hi All,

I am using hois integration to use "domain" command. I sometimes have array of strings for domains and sometimes single string and in most of cases whois return results to me but i got sometimes "Connection Refused" Issue. I already adjusted

...

Syedhkt by L2 Linker
  • 719 Views
  • 1 replies
  • 0 Likes
  • 1272 Posts
  • 43 Subscriptions
Top Liked Authors