Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! Use DT format inside an automation.

Hello,

We are working on an automation which calls many different lists of nested dicts. Example:

upField:

0:

field1:value1

field2: value2

1:

field1:value3

field2: value4

 

In a playbook it will be easy to call only field1 using this expression: ${up

...

Josep by L4 Transporter
  • 1562 Views
  • 2 replies
  • 0 Likes

Shorten returned values in query

I'm creating a widget so I can have a report run returning certain Managment Audit log information.  One of the fields, "Management_Auditing_type" has values that are quite long that I would like to truncate.  For example, have "MANAGEMENT_AUDIT_ACTI

...

Onboarding Playbook Questions

Hi, I am needing to build a playbook for onboarding new accounts into Active Directory. I do know they have some Premium Playbooks but I don't have that budget so building our own. 

 

How do I take in to account the aspect if the username is already

...

War Room showing limited outputs

Hello,

We are executing a long playbook. This playbook started to work incorrectly. To check what was happening, we looked inside the War Room, but it only showed a limited number of outputs. In order to check more outputs, we had to scroll up inside

...

Josep by L4 Transporter
  • 1226 Views
  • 3 replies
  • 0 Likes

Delete List using automation/command?

Hi All,

 

I wanted to delete a list using a playbook tasks, but I dont find any automation that can achieve it. It only have createList, and remove data from List

 

May I know any workaround for it?

 

Regards,

Jia Kai

JOng39 by L1 Bithead
  • 2821 Views
  • 3 replies
  • 0 Likes

Resolved! ParseExcel automation issue

hello,
using XSOAR I wanted to parse an excel from an e-mail and insert the information into a table. I created a Grid field by inserting it inside the incident, used ParseExcel inside a playbook setting as "Mapping" inside the automation to identify

...

FrancescoBarducci_0-1695725938445.png

Resolved! Create clean Notes in the layout

Hello,

We'd like to create Notes in the layout. We can use the option "Mark results as note", but it shows the command executed. We'd like to show a clean note, nothing else.

Josep by L4 Transporter
  • 1483 Views
  • 3 replies
  • 1 Likes

"taskComplete isAutoRun=True" not working

Hello,

We are using a playbook to run again tasks which are already running. Just to reset the task. However, when the command "taskComplete isAutoRun=True" is used, it doesn't run again. How can we avoid this? Is there another option?

Josep by L4 Transporter
  • 982 Views
  • 2 replies
  • 0 Likes

Resolved! Splunk Integration

Hi, I have been trying to integrate Splunk Enterprise with xsoar and I keep getting this error message 

 

 

with url: /services/auth/login (Caused by SSLError(SSLError(1, '[SSL: WRONG_VERSION_NUMBER] wrong version number (_ssl.c:1007)'))) ] (2604) (2...

Fetching fields in issuejson

I have added a custom field in Jira. I am trying to print the information in jira by fetching through XSOAR. I am using this command {"fields":{"customfield_11503":{"value":"${incident.techniqueid}"}}} 

where technique id is getting fetched in XSOAR,

...

Himangi by L2 Linker
  • 1161 Views
  • 3 replies
  • 0 Likes
  • 1122 Posts
  • 35 Subscriptions
Top Solution Authors
Top Liked Authors