Help regarding accessing trail version for learning
Hi All,Anyone please help me how to use trail version where I can learn and practice cortex xsoar. Thanks in advance.
Hi All,Anyone please help me how to use trail version where I can learn and practice cortex xsoar. Thanks in advance.
I'm confused as to how to use the DedupBy command/script in my Playbook. I have a set command that grabs all the UPNs from a list of alerts in the data. This results in the Context data of:Defender:{UPNs:[0:"[email protected]"1:"[email protected]"2:"[email protected]"3:"[email protected]"]}I'd like to Dedup this list to use later on in my Playbook b...
Has anybody used the O365 Teams (Using Graph API) (Community Contribution) integration to send chat messages and was able to configure the integration successfully? while trying to test integration after configuring it, it is showing the following error message
Hi, I'm looking into how we can use the built-in content repository to push content from the development to the production tenant. In this scenario, Palo Alto will handle the content repository. If I want to manage branching, is it possible to do so without using a private GitHub repository? I would appreciate any insights on this.
As Cortex XSOAR can use the API of Ansible Tower (the normal ansible does not have API so Tower is needed) to trigger playbooks (https://xsoar.pan.dev/docs/reference/integrations/ansible-tower ) for managing many kinds of devices it is interesting if there will be a native integraion with the Terraform Cloud as it also has API like Ansible Towe...
Dear All, I would like to seek support if anyone encounter issue Cortex XSOAR "Mail-Listener-v2" with O365? I have do allow permission and try with different IMAP and Port, but the issue still persist. Appreciate, for any advice to resolve this matter. Best Regards, Sopanha
Cisco Secure Malware Analytics (Threat Grid) v2 is an OOTB integration comes as part of Cisco Secure Malware Analytics content pack to connect with ThreatGrid(TG) platform and achieve various functionalities. Issue background: !threat-grid-sample-list integration command downloads resources for the given sample id from ThreatGrid depending on th...
Hi everyone, I have a question regarding SLA tagged scripts on XSOAR. I have a field-change-triggerred script that starts an SLA timer within automation if the field is changed to certain values. This part is okay and we observe that the sla timer starts succesfully. I want to run an SLA script when breach is triggerred for this timer. I have...
Hi Palo Alto Community, Is there any documentation or configuration for Palo Alto NGFW that can be integrate with some external threat intelligence feed (via TAXII) to block any IoCs list? I need documentation for direct device, but if you have documentation using TIM in Cortex XSOAR, you can share to me. Now I using TIM in Cortex XSOAR to gat...
Currently there are several areas of the Cortex XSOAR platform experience where pop-up windows and drop down menus appear in a static size regardless of available screen real estate. Automatic scaling to the existing window size would be fantastic! Barring that a manual option to resize each instance would suffice. Added a screenshot of the ...
Those of you that work with a Splunk environment with Enterprise Security, what has been your experience? We were fine until we upgraded to ES 8.x...
Hi everyone,I get data from splunk with the "search index=notable" query using Splunkpy. I assign the incoming data to the type named Splunk Generic Notable by default. Here, when an incident occurs, there are fields such as event_code, process_name in "labels". But on the mapper page, the label section comes empty. This data appears in _raw (in...
I have a problem with the incoming mirroring, the comments have not been synced back to XSOAR when using Splunk ES8. As a result I upgraded the splunk content pack to 3.3, but now the entire mirroring is broken. No updates are synced back to XSOAR (Version 6.14.0 Build 3036535). I noticed the developer tools are listed as mandatory but they ar...
As in War Room, it would be very useful to be able to paste an image from the clipboard using Ctrl+V for Add-on type tasks. For example, this could be provided through the add-on pop-up (Screenshot 2) in the Incident Tasks section (Screenshot 1). Cortex XSOAR
Dear All, I have query that return 11587 records, i checked on splunk. I run this query on xsoar but it showed me total record is 11587 but the actual data is 4900 i trying to figure out, i checked event limit size, query setting all fine but still issue. on xsoar side server unable to open file due to too large , any suggestion pls

