Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Sum number field

Can someone explain why this isn’t working? I created a number field called “niv”, added it to a dashboard with a SUM aggregation, but it shows 0 instead of the expected total (55).

NivNet by L1 Bithead
  • 594 Views
  • 0 replies
  • 0 Likes

Playbook stuck after upgrade

Hi! I have a playbook that gets stuck in a very weird way. I seek for community help as after my last session with product support, i do not seem to go anywhere as there were no obvious platform errors, they blame the playbook. 😞 Since the upgrade to the latest 6.14 build, one popular custom playbook is stuck on specific conditional task. It ...

support.png
Antanas by L2 Linker
  • 492 Views
  • 0 replies
  • 0 Likes

While True Condigtional

Hello Everyone,I want to ask about the while loop condition in XSOAR, is it possible to do that? for example i want to check condition the agent status to see whether it is connected or not, if it is not connected set 10minutes delay and then check the condition again Thank you!

G.Anshar by L1 Bithead
  • 4052 Views
  • 3 replies
  • 0 Likes

all incidents are missing

Hi everyone All incidents from our cortex xsoar instance are missing or are not shown, but we don't have any filter. The info is still on the server because we can see all the .db files, we tried to re-index the database but this didn't solve the issue. any ideas what might be happening? thanks

Playbook Task - Filters and Transformers help needed

Hi All, i have a playbook task that runs a XQL query against a dataset to take info from the alert context data, do a search against a specific dataset, then take the output of the '_broker_device_name' field and then this is written to my parentincidentcontext data.. this works. however, i am struggling with a simple task, and this is for a ...

PA_nts by L4 Transporter
  • 3627 Views
  • 1 replies
  • 0 Likes

Defining a Known User Object List for Automated Playbook Logic in XSOAR

I need to define a known user list as an Object List so that the playbook can automatically check it. If the username involved in the incident is found in this known list, the condition should pass and the incident should move forward toward automatic resolution. How do we properly define a list inside the playbook and configure the logic so t...

Chamindu by L1 Bithead
  • 3875 Views
  • 1 replies
  • 0 Likes

Enriching context data with info from datasets

Hi, Is anyone able to guide me on how to achieve this perhaps? I want to ran a task in a playbook that will do a custom query in a dataset and pull information and add it to the alert context data.. is this possible and if so guidelines would be appreciated. thanks in adv

PA_nts by L4 Transporter
  • 2021 Views
  • 0 replies
  • 0 Likes

XSOAR IP Forwarding requirement

For Cortex XSOAR 6.X On-premises deployment, in server deployment / system requirements describes that IPv4 IP forwarding is required (System Requirements • Cortex XSOAR Administrator Guide • Palo Alto Networks documentation portal ). Security team is questioning if there is other possibility to deploy XSOAR by not enabling IPv4 IP Forwarding or...

M.Sylos by L0 Member
  • 1158 Views
  • 0 replies
  • 1 Likes
  • 1302 Posts
  • 45 Subscriptions