Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! Slack Bot keeps sending messages to users

Occasionally, the bot sends the message in the screenshot below to our users in no particular order. We don't know why that is happening. One time a certain user reported that every time he gets a message from a coworker the bot sends this message to

...

EnesOzdemir_0-1683792595677.png

Cortex XDR Crowdstrike Layouts

Hello, I have just onboarded the crowdstrike integration into Cortex XDR. I am looking to modify the incident layout of the incidents themselves and the option is not available. Instead, inside a Crowdstrike Incident I have to usually go to Crowdstri

...

Resolved! Can run playbook in incident but not job

Currently creating a job to fetch and create an incident through an integration. The job works fine on the test server but doesn't work on production. Forcing the job to run doesn't output an error or even a record of the job attempting to run. But w

...

Bucket not found

Our deploymentt is multi-tenant deployment. When i run "!Github-get-file-content" command, i get an error some tenants (Bucket not found) but other tenants it work.

What is cause of this error?

 

 

 

Cortex XSOAR 

YilmazDincer_0-1683537421281.png

Resolved! Microsoft 365 defender advance hunting query

Hi,

 

I'm trying to build an advance hunting query in Microsoft 365 defender integration, but still giving me error.

 

!microsoft-365-defender-advanced-hunting limit=10 query="""AlertInfo | where alertId = fa85caf1c0-b9b9-bc29-f600-08db44a419b9"""

 

...

Error creating or updating RTIR ticket

I've been trying the #RTIR integration, to create a new ticket indicating a text content, and the execution seems to work but no ticket is created (without indicating text, it works perfectly

Also try to create an empty ticket, and next update with t

...

Pascual by L0 Member
  • 1195 Views
  • 3 replies
  • 0 Likes

Resolved! Problem with Slack Notifications

Email notifications are working fine and I want to see the same notification on Slack too. On mentions in the war room, slack should send a notification to users dm. Even though I have notifications enabled for SlackV3 I am not receiving anything on

...

EnesOzdemir_1-1683280310326.png
EnesOzdemir_0-1683280130237.png

Resolved! indicator extract data

im working on a project with xsoar indicators, we want to add a extra field to the layout that describes what the analist have to look for when certain indicators are present, now that problem that im running into is im trying to make a dynamic secti

...

rune.man by L0 Member
  • 1319 Views
  • 2 replies
  • 0 Likes
  • 1025 Posts
  • 33 Subscriptions
Top Solution Authors
Top Liked Authors