Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Bucket not found

Our deploymentt is multi-tenant deployment. When i run "!Github-get-file-content" command, i get an error some tenants (Bucket not found) but other tenants it work.

What is cause of this error?

 

 

 

Cortex XSOAR 

YilmazDincer_0-1683537421281.png

Resolved! Microsoft 365 defender advance hunting query

Hi,

 

I'm trying to build an advance hunting query in Microsoft 365 defender integration, but still giving me error.

 

!microsoft-365-defender-advanced-hunting limit=10 query="""AlertInfo | where alertId = fa85caf1c0-b9b9-bc29-f600-08db44a419b9"""

 

...

Error creating or updating RTIR ticket

I've been trying the #RTIR integration, to create a new ticket indicating a text content, and the execution seems to work but no ticket is created (without indicating text, it works perfectly

Also try to create an empty ticket, and next update with t

...

Pascual by L0 Member
  • 1331 Views
  • 3 replies
  • 0 Likes

Resolved! Problem with Slack Notifications

Email notifications are working fine and I want to see the same notification on Slack too. On mentions in the war room, slack should send a notification to users dm. Even though I have notifications enabled for SlackV3 I am not receiving anything on

...

EnesOzdemir_1-1683280310326.png
EnesOzdemir_0-1683280130237.png

Resolved! indicator extract data

im working on a project with xsoar indicators, we want to add a extra field to the layout that describes what the analist have to look for when certain indicators are present, now that problem that im running into is im trying to make a dynamic secti

...

rune.man by L0 Member
  • 1517 Views
  • 2 replies
  • 0 Likes

Resolved! running polling commands from automations

opsgenie-get-request is a polling command but when it is being run from an automation it results in an error. From CLI or through playbook tasks, the output returns to the war room once it finishes. That's doesn't seem to be the case in automations.

...

XSOAR getIncidents command

Hi community, 

 

I've been making great use of custom scripts to extract reporting metrics that wouldn't have been possible with the built in widgets. But something I've noticed recently is that querying incidents seems to be causing huge spikes in C

...

Resolved! Docker Image [exit status 120]

I created an 'image' with the 'docker_image_create' command, containing the pymisp and pandas libraries. I'm having a problem now and I can't make sense of it, any ideas?


Error from Scripts is : Script failed to run: Container exit with error. contain

...

Resolved! XSOAR Delete Messages using Graph API

I know EWS and O365 are current options for the Delete messages playbook however does anyone know it the Graph API is going to be added as an option? Due to certain restrictions I am being forced down the Graph API route for the preferred integration

...

DennisO by L1 Bithead
  • 2760 Views
  • 7 replies
  • 0 Likes

Blueliv API integration error

We are testing XSOAR and integrations. We have some problems when we try to fetch incidents in BlueLiv integration. 

 

This is the complete error:

Error: Script failed to run: Error: [Traceback (most recent call last): File "<string>", line 5...

socser by L0 Member
  • 1317 Views
  • 2 replies
  • 0 Likes

Extract Indicator in XSOAR

Hi all,

I want to manually extract the 'IOC alarm' coming from XDR. But the incoming IP addresses come in 2 ways as 'action_local_ip' and 'action_remote_ip'. If I extract according to action_local_ip or action_remote_ip, some IOCs get an error (wrong

...

  • 1106 Posts
  • 34 Subscriptions