Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

new host does not appear in the ACCOUNT MANAGEMENT

Hi!I'm installing XSOAR multi tenant environment. Currently its a Community edition for POC.Installed main host and tenant host as per documentation. Both Ubuntu 22.04I am unable to connect tenant host to main host.Settings - account management - new account - host/HA group only shows main host:hostname:443They are both in same subnet, main host...

Did not get the expected value from test (85) issue with Remedy Integration

- Hi, While doing the customized Remedy integration test, getting-"Did not get the expected value from test (85)" but able to fetch the incident status via "remedy-incident-get incidentID", OAuth test successful via "remedy-auth-test" in playground through queries and also generating the Incidents. Could anyone assist me with this?

Resolved! Dynamic Section using Context

I was wondering how we can add splunk results into Incident layout. Possibly a CSV file or markdown. We use splunk to search our email logs to see other recipients who got phishing email. Wanted to display that in the Incident layout. Any advise is highly appreciated. Thank you.

Getting null in output

Hi, I am using a splunk search automation and passing a query in input and I am getting appropriate result without any null value. So I have added a new task after that to convert the output in csv, I am using Exporttocsv automation, but here the input value is consisting of null followed by the result of splunk search because of which I am ge...

Himangi_1-1698821557749.png
Himangi_0-1698821510351.png
Himangi by • L2 Linker
  • 1777 Views
  • 2 replies
  • 0 Likes

Qradar Integration

Hi , Is there a way to make the the system pull incidents more often , now it takes about 3 min since the offense first appears in the Qradar until it appears in the Demisto.

Resolved! Using Dev/Prod Configuration as a test environment for noisy integrations

Hello all, I am working with XSOAR 8 Hosted and configuring a Dev/Prod environment. I have two critical questions regarding this. Can the dev environment be used to test noisy integrations that produce many alerts in a controlled way without impacting the prod environment ? Secondly, the main intention for us with the dev/prod configuration is...

urlscan.io alternatives?

Hi all, I'm looking for urlscan.io alternatives that are available in the marketplace. Ideally, something that'll allow "browsing" from a different location, like GeoPeeker. Thanks!

Upgrade XSOAR Offline

Our environment cannot connect to the internet. We have installed XSOAR 6.11 offline before, and now we want to upgrade to version 6.12. So I would like to ask, can I upgrade offline? I have read the official documentation of XSOAR and there is no mention of offline upgrade method.

Resolved! AzureAD/MS Graph User Expire Password

Anyone familiar with MS Graph User integration and using it to expire a password for a user, much like Active Directory Query V2 "!ad-expire-password"? It appears the method with PowerShell is using Connect-AzureAD and updating the passwordProfile attribute. But haven't had a successful test with !msgraph-user-update when trying to update tha...

Resolved! xsoar change incident owner

Hi , is there a way to put a listener on every incident , and every time an incident owner is changing - it will run a playbook or a script.The incident owner can be changed at any time during the playbook of the incident is running.

Issue with Microsoft Graph Mail Single User Integration

I am attempting to integrate Microsoft Graph Mail Single User into our XSOAR platform for Custom. However, I encountered some issues during the process. Errors Encountered: When providing the key, I received the following error: "Please use !msgraph-mail-test instead (85)" [Error timestamp: July 20, 2023 3:40 PM] When I removed the key, I recei...

vhebri by • L1 Bithead
  • 6062 Views
  • 8 replies
  • 0 Likes
  • 1310 Posts
  • 46 Subscriptions
Top Solution Authors