Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! Playbook waiting for a manual Set task

Hello community,

 

I have some playbooks that are responsible for closing incidents in the various sources (XDR, QRadar, XSOAR, JIRA, ...) once I enter a reason or reason for them to be closed.

 

 

I have done this using a "Set" automation that wa

...

rafaelusano_0-1703592508555.png
rafaelusano_1-1703592616387.png

Per Month Query using Beve Query Syntax

Hi,

 

I am trying to take a sum of incidents over a given time, and divide this sum per month, using Beve Syntax.

I there any syntax that would give me a per-month break down?  So I can take incidents per month, and display them in a widget using a b

...

incidents pulling time

Hi , 
in my Qradar integration I don't have this parameter , 

I have enabled the "Long Running Instance" and still it takes too long for the incidents to be fetched.

Is there a way to manually configure the Incident Fetch Interval. 
I'm using IBM QRad

...

Bar_Magnezi_0-1702974903501.png

Resolved! Custom Widget Xsoar

Hi, I am trying to create a custom widget that calculate follwing (Total Incident+ Total Command Execution) with date paramters adjusted by widget. I tried to implement this with JSON method and Automation Script but unable to get the solution. Can y

...

Syedhkt by L2 Linker
  • 1226 Views
  • 1 replies
  • 0 Likes

Create Slack Channel from XSOAR

I am attempting to create a Slack channel from XSOAR using the slack-create-channel command.  After a few minutes, I get the following error:
"Reason

Error from SlackV3 is : Script failed to run: Timeout Error: Docker code script failed due to timeo
...

Bug in native playbook 'QRadarFullSearch'

Hello,

XSOAR's native playbook named 'QRadarFullSearch' has a task called 'Get QRadar search results'. Everytime we run this task, it fails with the following error log:

Failed to execute qradar-get-search-results command.
Error:
Traceback (most recent c

...

adocasar by L1 Bithead
  • 1127 Views
  • 1 replies
  • 1 Likes

Drop and Update but NOT Create (Pre-Processing)

Hi,

 

I am trying to write some preprocessing rules to report on and update BitSight incidents. I only want to create incidents that have a grade of 'BAD' or 'WARN'. I do want to capture, however, when a given incident's grade is updated within BitSi

...

AFamera by L0 Member
  • 1003 Views
  • 1 replies
  • 0 Likes

bitsight-company-findings-get automation

Hello,

 

I am attempting to use the 'bitsight-company-findings-get' command within my automation script, but I am getting an error after I run my script in the playground war room saying I'm using the invalid character '{' even though I copied the co

...

AFamera_0-1698881718740.png
AFamera_1-1698881866094.png
AFamera by L0 Member
  • 761 Views
  • 1 replies
  • 0 Likes

Resolved! Storing Incident Notes in Context Data

Hello all,

I am working on a use-case in which I need to store text based comments (Including MD) to context data for report generation. I have tried to create a script for this yet I have not succeeded. Is there a way to access the comment section i

...

  • 1125 Posts
  • 36 Subscriptions
Top Solution Authors
Top Liked Authors