Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Installation of cortex SOAR offline

Dear All, i was trying to install COrtext SOAR in an Airgap (offline)Enviorment with no internet where i was refering cortex offline installation guide, and i i could not complte the installation and stuck in uploading docker dependaci file to which explain below , did any one here installed XSOAR offline and get sucsess, if yes please help m...

Bulk Changing Incident Status from Pending to Active

I have created an integration that produces many alerts and I have a few thousand incidents that are currently in the Pending state. The plabyook has yet to run etc. What I would like to is select the incidents from the "Incident" page and change the status for these incidents from pending to active without entering each incident manually. I hav...

Why is the severity became "unknown"?

Hello All, I have a question, i have mapped an incident from qradar with the playbook i've created. At first it's worked, the incident severity was "high". but later until now, the severity become "unknown". What is the main cause of this issue?Thank You

awarman by L0 Member
  • 2065 Views
  • 2 replies
  • 0 Likes

Getting data from multiple incident contexts?

Hi! I want to extract specific key data from context of multiple incidents. The context key I'm looking for is not under "incident". Specifically, I have many incidents of type "Phishing" and want to output the contents of "Recipient Selection.Answers.0" key from all of them. I thought of using SearchIncidentsV2 but it does not seem to include...

Antanas by L2 Linker
  • 2595 Views
  • 1 replies
  • 0 Likes

Resolved! XSOAR 8 API - Attachment upload with entryID

The code below, creates an incident with attachment uploaded but in the incident itself, when I see the context, I dont see any file. Since there is no entryID for the file, I cannot read the attachment and also cannot run the playbooks. Any change I need to make to make the attachment appear as File with entryID? https://docs-cortex.pal...

Cortex XSOAR

Morning everyone, I hope that you are doing well I have a little problem. We have implemented the XSOAR in our customer environment and configure th EWS O365 content pack for phishing attacks but since we do not have a case, we cannot show to the customer how it work in a real case. We alrea;dy gernerated incident with the onboarding content...

Ingest Taxii feed into XSOAR 6.12

Hi, I am trying to ingest our taxii feed into XSOAR 6.12 with following steps: installed XSOAR 6.12 on ubuntu 22.0.4 LTS launched the web portal, and installed TAXII Feed (1.x) pack from marketplace Ingest feed using "Integration Instance Settings" Typed in the parameters such as name, discovery service URL, username/password, collection nam...

TonyZhu by L2 Linker
  • 8078 Views
  • 16 replies
  • 0 Likes

Resolved! Reruning playbook and preventing communication tasks from being rerun

Hello All, I have been working on the XSOAR Platform for a long time and there is something which I haven't been able to find a solution for. I would like to rerun a playbook for multiple incidents and I use the !setPlaybook to do this. I do this after rectifying the issue on the playbook for example task error or similar. The problem is that m...

new host does not appear in the ACCOUNT MANAGEMENT

Hi!I'm installing XSOAR multi tenant environment. Currently its a Community edition for POC.Installed main host and tenant host as per documentation. Both Ubuntu 22.04I am unable to connect tenant host to main host.Settings - account management - new account - host/HA group only shows main host:hostname:443They are both in same subnet, main host...

Did not get the expected value from test (85) issue with Remedy Integration

- Hi, While doing the customized Remedy integration test, getting-"Did not get the expected value from test (85)" but able to fetch the incident status via "remedy-incident-get incidentID", OAuth test successful via "remedy-auth-test" in playground through queries and also generating the Incidents. Could anyone assist me with this?

  • 1307 Posts
  • 46 Subscriptions