Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Create a PDF File

Hi everyone What is the best way to create a PDF within a Playboook? What are you all using? Data format doesn't matter but some customisation about the pdf format would be nice. BR Michael

micomi by L3 Networker
  • 2081 Views
  • 4 replies
  • 1 Likes

Recurring automation on active tickets

I'm trying to run an automation every hour which checks for Warroom entries and executes certain code in the automation. This automation should only run and check on the active tickets. The automation itself works, but I still need to execute it with a command in the Warroom at the moment. I've created a job that runs every hour, but I can't see...

G.Buis by L1 Bithead
  • 1797 Views
  • 4 replies
  • 0 Likes

Cortex XSOAR and Cortex XDR Integration - Fetch Incident

Hello, I want to automatically import incidents that occur in XDR as incidents into XSOAR. The integration is successful, but I cannot view the occurring incidents in xsoar and I get the following error. Error: Script failed to run:Error: [Traceback (most recent call last): File "<string>", line 6067, in <module>File "<string&...

Resolved! Close an incident when all the linked incidents are closed

Hi, I want to be able to close an incident when all the linked incidents (child incidents) are closed. Is there a way to achieve this without having to run a post processing script for each linked incident? Post processing scripts introduce a race condition when two automations check each other out for status at the same time.

Global Protect VPN logs from Panorama to Cortex XSOAR

Hello, was reviewing Globalprotect VPN Logs in Panorama and am currently stumped on how to even create an alert or find the logs in which to send to XSOAR. I reviewed the PAN-OS integration, and I can link it to Panorama, but it will collect logs based on specific queries into the logs. None of which go directly to Global protect. Anyone out the...

Where to Download XSOAR Single Server Installer Setup File

Hello Team, Kindly help where to download the xsoar server installer setup file (single server installer file i.e standalone server mode) planning to deploy xsoar test setup environment. I followed the guide single server installation steps and error occurs see the attached screen shorts.

cV V by L2 Linker
  • 4957 Views
  • 6 replies
  • 0 Likes

Resolved! Creating Docker images

I would like to create a Docker image to make a Python Library, which is not pre-installed, available on XSOAR. Therefore, I executed the following command: /docker_image_create name=jpholiday base="demisto/python3-deb:3.8.2.6981" dependencies=jpholiday,datetime However, I encountered an error and was not successful. error creating the docker ...

MEiunyo1 by L1 Bithead
  • 2157 Views
  • 2 replies
  • 0 Likes

Resolved! Web Scrapping

Hi All, I have some website for news and i want to get content of that webiste and send email using xsoar. Any useful integrations? Cortex XSOAR

Syedhkt by L2 Linker
  • 3263 Views
  • 6 replies
  • 0 Likes

6.12 on RH 7.9 - Web server won't start

Hello. We tried in many ways but web server wont start. I see the server working and doing outbound connection, but it's not listening on 443. There is nothing strange in the log as I can see. I don't know what I can look at to fix that. Thanks

SPisani by L0 Member
  • 1167 Views
  • 2 replies
  • 0 Likes

Resolved! How XDR Sync command working in XSOAR

Hello, how the !xdr-iocs-sync firstTime="True" command working in XSOAR, It will deleted IOC list in XDR IOC rules. If i need to run the sync command any proper format to run before those. I want to upload or sync 100 no's of IP's or Domain names with XDR. whether can able upload via sync command. Guide for the above queries. Regards, ...

cV V by L2 Linker
  • 1760 Views
  • 2 replies
  • 0 Likes

Resolved! Integration/Content Packs Update Issue

Hi All, I have some integrations/Content Packs and they need to be updated but when ever I tried to update from update button on market place, it gives me error "Unavailable docker image...." how to tackle this issue and what are possible best ways to fix this Cortex XSOAR

Syedhkt by L2 Linker
  • 1511 Views
  • 1 replies
  • 0 Likes

Non Enterprise Security Splunk users

Hi Please share some info on how you are running your setup. We are currently using the TA-Demisto splunk app to push the alerts to the XSOAR but having issues with excessive incidents in XSOAR being created when we use the |table in our searches and havent been able to figure this out. Thanks in advance for tips and tricks on this subject.

Extracting Incident Files from the Server Side or Through API

I have a functionality question regarding Incident Files, for example, images. I have uploaded images as both "Files" and "Media" on the XSOAR incident through the war room. Can these files be accessed from the DB or Linux side? Take note that this is not for a specific incident but rather a functionality access question. If not possible does th...

  • 1298 Posts
  • 45 Subscriptions