Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! AzureAD/MS Graph User Expire Password

Anyone familiar with MS Graph User integration and using it to expire a password for a user, much like Active Directory Query V2 "!ad-expire-password"? It appears the method with PowerShell is using Connect-AzureAD and updating the passwordProfile attribute. But haven't had a successful test with !msgraph-user-update when trying to update tha...

Resolved! xsoar change incident owner

Hi , is there a way to put a listener on every incident , and every time an incident owner is changing - it will run a playbook or a script.The incident owner can be changed at any time during the playbook of the incident is running.

Issue with Microsoft Graph Mail Single User Integration

I am attempting to integrate Microsoft Graph Mail Single User into our XSOAR platform for Custom. However, I encountered some issues during the process. Errors Encountered: When providing the key, I received the following error: "Please use !msgraph-mail-test instead (85)" [Error timestamp: July 20, 2023 3:40 PM] When I removed the key, I recei...

vhebri by L1 Bithead
  • 5140 Views
  • 8 replies
  • 0 Likes

Palo Alto Support Portal

I am new to xsoar and was wondering if there is an API to connect to the PA support portal. My goal is to connect, register a device and input the host name, address etc... so I can pull down the licenses. Thanks for all the help. Michael

Custom Integration Based on Cert Authentication Giving Error "Got status code 500 with body x509: certificate signed by unknown authority with header"

Hi Team, I have developed a custom integration on XSOAR as the integration is not supported by PA natively hence to authenticate with the API i'm using Certificate based authentication hence when i'm testing the integration it is showing me the below error. "Got status code 500 with body x509: certificate signed by unknown authority with heade...

XSOAR app integration with Microsoft 365 Defender

Hi, PAN has published an Azure AD app for both integration of Microsoft Defender for Endpoint (MDE) and Microsoft 365 Defender (M365D). The instructions to use the app are very clear and it works well for MDE but I had no luck for M365D. PAN reference a different app ID in the documentation specific to M365D but there's no instruction on how ...

Integration with LDAP Authentication

Hi, I am trying to integrate XSOAR with LDAP authentication, in order to allow users to authenticate using AD credentials. But when i test the integration i am getting the below error. Also let me know, that whether i can import users into XSOAR from my AD after successful integration with LDAP authentication. And whether the user must have...

nithink_0-1697455918444.png
nithin.k by L1 Bithead
  • 1329 Views
  • 1 replies
  • 0 Likes

Facing issue when using !ParseCSV command

Hi guys, I am facing an issue when running !ParseCSV command as it is removing specific characters in a field value that is being displayed in the table output.For example, my parsed CSV contains the following: C:\Users\username_1\AppData\Roaming\Microsoft\Windows\Network Shortcuts\~$testing.xls However, after running the command, it shows up in...

Resolved! XSOAR - Simple Dev to Prod Job

Was looking at running a backup job for our custom content with the below playbook. https://cortex.marketplace.pan.dev/marketplace/details/XSOARSimpleDevToProd/ The issue with this is it checks for Demisto REST API to see if the instance Demisto Dev had been created. The Demisto Rest API has been depreciated, so the call !IsDemistoRestAPIInsta...

Resolved! XSOAR O365: All-mailboxes search *A Question from XSOAR O365 Webinar*

Any updates planned regarding the time to search all mailboxes through the integration? In large orgs with 30k+ mailboxes, search can take over an hour to two hours to search all mailboxes, not practical at all and a viable solution. Same search within O365, via GUI or powershell takes just minutes. This question was asked as part of our Corte...

rtsedaka by L6 Presenter
  • 1992 Views
  • 1 replies
  • 0 Likes

Edit Splunk Search Output

Hi,I am running a query in splunk search automation, The output I am getting includes too many brackets. I want to edit the output and I want to further use that output in different task. Can anyone please suggest how can I edit the splunk search output.

Himangi by L2 Linker
  • 2453 Views
  • 5 replies
  • 0 Likes
  • 1298 Posts
  • 45 Subscriptions