Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! Unblock IP

Hi, I have been using Panorama integration to block the IP. Is there any way where I can unblock the IP or remove the IP from address group of Panorama.

Himangi by L2 Linker
  • 2721 Views
  • 3 replies
  • 0 Likes

False Positives Microsoft Teams Large Upload

Hey, I need your help. We are receiving alerts "XDR Incident 945 - 'Large upload (generic)' generated by #XDR Analytics detected... Basically, this appears when the user makes a call, shares documents, or shares their screen (using Microsoft Teams). In the #XSOAR event I can see that the processname is ms-teams.exe and the destination ip is ...

tlmarques by L4 Transporter
  • 1961 Views
  • 2 replies
  • 0 Likes

CrowdStrike XDR Use cases with Pala Alto Cortex

Hi Team, Can you please suggest a few case studies where CrowdStrike XDR is integrated with Cortex SOAR and what were the areas and use cases that were implemented and helped the customer? We wanted to present this to a management that already has crowdstrike XDR and we want to showcase how cortex SOAR can help.

AYadav45 by L0 Member
  • 2453 Views
  • 1 replies
  • 0 Likes

Resolved! Playbook waiting for a manual Set task

Hello community, I have some playbooks that are responsible for closing incidents in the various sources (XDR, QRadar, XSOAR, JIRA, ...) once I enter a reason or reason for them to be closed. I have done this using a "Set" automation that waits for input from the user and gives an error as it is a "Set" where the value "value" that is i...

rafaelusano_0-1703592508555.png
rafaelusano_1-1703592616387.png

Per Month Query using Beve Query Syntax

Hi, I am trying to take a sum of incidents over a given time, and divide this sum per month, using Beve Syntax. I there any syntax that would give me a per-month break down? So I can take incidents per month, and display them in a widget using a bar graph. Thanks

No remote "Content Repository" tab despite ui.version.control.show.remote = true

Hi, I am trying to setup remote repositories, in a first step only the dev environment. In About -> Troubleshooting I have set "ui.version.control.show.remote" to "true" (copy-pasting it from the documentation [1] and checking multiple times for typos and additional spaces). However, in the "Advanced" view it does not show the "Content Re...

Charly by L0 Member
  • 1150 Views
  • 1 replies
  • 0 Likes

incidents pulling time

Hi , in my Qradar integration I don't have this parameter , I have enabled the "Long Running Instance" and still it takes too long for the incidents to be fetched. Is there a way to manually configure the Incident Fetch Interval. I'm using IBM QRadar v3

Bar_Magnezi_0-1702974903501.png

Resolved! Custom Widget Xsoar

Hi, I am trying to create a custom widget that calculate follwing (Total Incident+ Total Command Execution) with date paramters adjusted by widget. I tried to implement this with JSON method and Automation Script but unable to get the solution. Can you suggest some solution and how this will be acheieved using automation script. Second questio...

Syedhkt by L2 Linker
  • 2271 Views
  • 1 replies
  • 0 Likes

Resolved! Mapping labels "message" to Incident Context without Regex

Kind of similar to the below link: LIVEcommunity - Cortex XSOAR Context Issue - LIVEcommunity - 437729 (paloaltonetworks.com) I've tried mapping content from the Abnormal Security integration and from the Syslog v2 integration. The Abnormal Security integration dumps the raw logs into labels.messages, meanwhile Syslog dumps the whole raw log i...

Create Slack Channel from XSOAR

I am attempting to create a Slack channel from XSOAR using the slack-create-channel command. After a few minutes, I get the following error:"Reason Error from SlackV3 is : Script failed to run: Timeout Error: Docker code script failed due to timeout, consider changing timeout value for this automation, Error: Failed to decode (loop) data from...

Bug in native playbook 'QRadarFullSearch'

Hello,XSOAR's native playbook named 'QRadarFullSearch' has a task called 'Get QRadar search results'. Everytime we run this task, it fails with the following error log:Failed to execute qradar-get-search-results command.Error:Traceback (most recent call last):File "<string>", line 15863, in mainFile "<string>", line 14390, in qradar_...

adocasar by L1 Bithead
  • 2135 Views
  • 1 replies
  • 1 Likes

Using "GetFailedTasks" with a relative time range of 7 or 30 days lookback

Hello all, I am working with the task 'GetFailedTasks' withing the Integrations & Incidents Health Check playbook. When running this task within this system playbook I am only getting failed tasks from the beginning of the year and this is likely due to the Max_incidents flag for this task. How would I go about adding to the query a relative...

  • 1302 Posts
  • 45 Subscriptions