Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Chronicle Errors for a while now -

!gcb-list-detections alert_state="ALERTING" page_size="100" detection_for_all_versions="False" list_basis="CREATED_TIME" start_time="2023-07-17T14:52:46.000Z" end_time="2023-07-17T14:57:46.894Z" retry-count="2" retry-interval="30" is returning "Faile

...

NickyR by L1 Bithead
  • 643 Views
  • 1 replies
  • 0 Likes

Resolved! SearchIncidentsV2 not returning results

Hi, I am using SearchIncidentsV2 automation to loop through 2 IP addresses previously saved to IP incident key, to see if these IPs are showing in FireEye NX alerts. When I try to loop I receive empty foundIncidents key:  

 

 

 

When I hardcode the

...

MMagdic_0-1689670794647.png
MMagdic by L2 Linker
  • 1308 Views
  • 8 replies
  • 0 Likes

Issues after upgrading XSOAR

Hello wonderful people,

 

I just upgraded XSOAR from version 6.9 to version 6.11 in a live environment.

 

The upgrade was successful but "I got failed to migrate podman containers" after the upgrade.

 

Also after all, whenever I try to pull data from

...

Resolved! Delete Indicators Command

1) Is there a way to delete a batch of indicators with a single command, let's say all IP addresses imported with Feed XXX?

2) When I change Domain indicator expire time (Indicator Type) from 14 days to 1 hour, after expiration time indicators are st

...

MMagdic by L2 Linker
  • 2004 Views
  • 7 replies
  • 0 Likes

Resolved! Generate Investigation Summary Report

Hi

I have used the automation Generate Investigation Summary Report to generate a report of particular incident. But I am not getting full content in the report that is being generated. In war room I can see details but in the generated report inform

...

Himangi by L2 Linker
  • 776 Views
  • 1 replies
  • 0 Likes

Creating an XSOAR Incident from Splunk

Hey team,

 

We tried to push splunk alerts to XSOAR and we used the Splunk create XSOAR incident.

 

Splunk logs show that it was successful, but we do not see any incidents in XSOAR.

 

apparently 06-19-2023 16:33:01.558 +0000 INFO sendmodalert [37342

...

  • 940 Posts
  • 30 Subscriptions