Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

ZIP a file XSOAR

Hi Team, I'm trying to zip a file using ZipFile Automation as a task in the playbook and after it has been zipped use the ZIP file EntryID to be sent attached in an email, I'm getting this error: 'Unable to read file with id b4841215-d627-4c36-9cb6-243199452aaf', ValueError('failed to get artifact file path, invalid file (52)\n' ZipFile Ta...

Resolved! Crowdstrike API upgradation

I recently got news that crowdstrike is going to upgrade api version so what needs to do at xsoar side in terms of integration. According to my info we just need to update the pack or what else Cortex XSOAR

Syedhkt by L2 Linker
  • 1744 Views
  • 1 replies
  • 0 Likes

Migrating instances to a new server - Accessing API Keys

Hello Live Comm, I have created a new XSOAR Server with a different OS and have begun migrating the data. I need to migrate the instances and we don't have records of the original API keys. Is there a way to access and view the API keys configured on the platform? I need to migrate all of them is there a way to do this? Many thanks, M Sysec Co...

Polling XDR Integration for Alerts that are not Incident Based

Hello all, I am running a Use-Case that requires me to poll the XDR Tenant for all alerts. These include Alerts that are found in an XDR Incident and Independent Alerts that are not found in an incident. For example a Low Severity alert from a BIOC Analytics Source that has not opened or should I say referenced in an incident. These Independent ...

Create a PDF File

Hi everyone What is the best way to create a PDF within a Playboook? What are you all using? Data format doesn't matter but some customisation about the pdf format would be nice. BR Michael

micomi by L3 Networker
  • 2179 Views
  • 4 replies
  • 1 Likes

Recurring automation on active tickets

I'm trying to run an automation every hour which checks for Warroom entries and executes certain code in the automation. This automation should only run and check on the active tickets. The automation itself works, but I still need to execute it with a command in the Warroom at the moment. I've created a job that runs every hour, but I can't see...

G.Buis by L1 Bithead
  • 1893 Views
  • 4 replies
  • 0 Likes

Cortex XSOAR and Cortex XDR Integration - Fetch Incident

Hello, I want to automatically import incidents that occur in XDR as incidents into XSOAR. The integration is successful, but I cannot view the occurring incidents in xsoar and I get the following error. Error: Script failed to run:Error: [Traceback (most recent call last): File "<string>", line 6067, in <module>File "<string&...

Resolved! Close an incident when all the linked incidents are closed

Hi, I want to be able to close an incident when all the linked incidents (child incidents) are closed. Is there a way to achieve this without having to run a post processing script for each linked incident? Post processing scripts introduce a race condition when two automations check each other out for status at the same time.

Global Protect VPN logs from Panorama to Cortex XSOAR

Hello, was reviewing Globalprotect VPN Logs in Panorama and am currently stumped on how to even create an alert or find the logs in which to send to XSOAR. I reviewed the PAN-OS integration, and I can link it to Panorama, but it will collect logs based on specific queries into the logs. None of which go directly to Global protect. Anyone out the...

Where to Download XSOAR Single Server Installer Setup File

Hello Team, Kindly help where to download the xsoar server installer setup file (single server installer file i.e standalone server mode) planning to deploy xsoar test setup environment. I followed the guide single server installation steps and error occurs see the attached screen shorts.

cV V by L2 Linker
  • 5368 Views
  • 6 replies
  • 0 Likes

Resolved! Creating Docker images

I would like to create a Docker image to make a Python Library, which is not pre-installed, available on XSOAR. Therefore, I executed the following command: /docker_image_create name=jpholiday base="demisto/python3-deb:3.8.2.6981" dependencies=jpholiday,datetime However, I encountered an error and was not successful. error creating the docker ...

MEiunyo1 by L1 Bithead
  • 2404 Views
  • 2 replies
  • 0 Likes

Resolved! Web Scrapping

Hi All, I have some website for news and i want to get content of that webiste and send email using xsoar. Any useful integrations? Cortex XSOAR

Syedhkt by L2 Linker
  • 3428 Views
  • 6 replies
  • 0 Likes

6.12 on RH 7.9 - Web server won't start

Hello. We tried in many ways but web server wont start. I see the server working and doing outbound connection, but it's not listening on 443. There is nothing strange in the log as I can see. I don't know what I can look at to fix that. Thanks

SPisani by L0 Member
  • 1232 Views
  • 2 replies
  • 0 Likes
  • 1302 Posts
  • 45 Subscriptions