XSOAR muti-site (DC,DR) design best practice
Dears All,
Kindly we need your support to provide us with best practices for muti-site high availability architecture (DC, DR)
Dears All,
Kindly we need your support to provide us with best practices for muti-site high availability architecture (DC, DR)
I am not seeing the AWS command describe-vpc-endpoints in any of the integrations...I just want to confirm I'm not missing it somewhere before I submit a feature request. Thanks.
Hello!
I would like to ask you how to implement a way to define the input values on the Incident Layout.
For example, I would need it in a case where I have a sub playbook and I want to give a value to one of its mandatory arguments without having to
...
Hi everyone,
I'm currently working on how to make some EQL queries to my Elastic Instance from Cortex XSOAR. I'm using ElasticSearch integration, specifically the command "es-eql-search" which purposoe, I guess, is to make a EQL query to ElasticSea
...
From the Welcome mail I receive Palo Alto network Support expected is Hub right?
Hi all,
I'm trying out SlackAskV2 and my message is being sent to the channel successfully. I used 'Yes' and 'No' as options.
When I click the 'Yes' or 'No' buttons from the slack channel, nothing is returned to the War Room.
Now, where do I find the
...
I'd appreicate guidance on how to update IOC fields with information extracted from an excuted playbook task.
My use case centers around updating File Hash IOCs to include file signature metadata information to enable easier cleaning up of IOCs as
...
Hi Guys,
After assigning an analyst to an incident we receive one email per task change from DBOT, that is very noisy and I don't see any reference on the documentation to customize the same. Highly appreciate if anyone can tell me how to get around
...
Hi Everyone
I have multiple simple playbooks tasks taking over a mins to complete, such as closing ticket, condition select etc,
We checked the CPU and Memory usage it seems normal,
Any suggestion where I can change why ti taking so long?
Ch
...
in a multi tenant environment, should I forward all the system configurations to tenants or are some of them meant only for hosts?
CSP cases in particular, can be pretty confusing. CSP tells me to put a sys config on the main account and in another c
Hello!
I have a question. How can I make it so that I would like to rasterize email/url. The image that appears in the war room (which is the result of running the command) i would like to display on one layout field.
I guess I should use dynamic secti
I want to achieve below steps. is there any exiting playbook or have to customized playbook?
In this first step, we will fetch the list of existing IOCs from Microsoft APT and compare them with the IOCs
...
Hello!
During incident investigations, it would be useful if certain Context Data fields (if they have a value) are written to the incident layout and you don't have to search for the value in the Context.
My question would be, how can I make it so t
...
I need to create some report and I am using pandas module for that but unable to read the file from my local rdp desktop. Note: I am using xsoar from web Interface. I try to use with "\\" to avoid escape sequence mistake. It is unable to read the fil
...
Hi,
First of all, we are using a lot of automations searching for incidents using queries often with more than 100 results.
The scripts line looks like this:
res = demisto.executeCommand('SearchIncidentsV2', {'query': query, 'limit': 5000})[0].get(
...Subject | Likes |
---|---|
1 Like | |
1 Like | |
1 Like | |
1 Like | |
1 Like |