Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Cannot add Links between Tasks - messed up in browser.

Hi All, Weird one.. so recently this started and I tried chrome, firefox and edge.. all does the same.. even in private windows. i can edit a playbook, add tasks etc.. but when i try to add the 'link' between tasks, the link either disappears or shows the first 10% of the link only.. the rest just disappears and often pops a blank task instea...

PA_nts by • L4 Transporter
  • 749 Views
  • 1 replies
  • 0 Likes

there any official training environments

I'm dedicated to self-learning the platform but understand the standalone Community Edition may have been discontinued. Since I am not currently a Palo Alto Networks Partner or a paying customer, what are the recommended ways for an individual to get hands-on lab or development access to XSOAR for extended learning? Are there any official trai...

Active Directory Query - Wrong info when null provided

I still consider myself fairly new to XSOAR and haven't written a lot of playbooks so maybe I'm doing this wrong, but here's my issue.When using the Active Directory Query pack's commands (the ad-get-user most recently but I believe ad-disable-account also works this way) it doesn't error when a null value is input. Instead it returns the random...

sackett by • L1 Bithead
  • 1316 Views
  • 3 replies
  • 0 Likes

Resolved! XSOAR Dev to Prod - Builtin content repository

Hi, I'm looking into how we can use the built-in content repository to push content from the development to the production tenant. In this scenario, Palo Alto will handle the content repository. If I want to manage branching, is it possible to do so without using a private GitHub repository? I would appreciate any insights on this.

Resolved! Cortex XSOAR intergration with Terraform Cloud?

As Cortex XSOAR can use the API of Ansible Tower (the normal ansible does not have API so Tower is needed) to trigger playbooks (https://xsoar.pan.dev/docs/reference/integrations/ansible-tower ) for managing many kinds of devices it is interesting if there will be a native integraion with the Terraform Cloud as it also has API like Ansible Towe...

Integration issue Mail Listener v2 with O365

Dear All, I would like to seek support if anyone encounter issue Cortex XSOAR "Mail-Listener-v2" with O365? I have do allow permission and try with different IMAP and Port, but the issue still persist. Appreciate, for any advice to resolve this matter. Best Regards, Sopanha

SopanhaRoth_0-1759309346266.png
SopanhaRoth_1-1759309372281.png

[Proposing Solution] Failure to extract zip file downloaded from ThreatGrid integration command

Cisco Secure Malware Analytics (Threat Grid) v2 is an OOTB integration comes as part of Cisco Secure Malware Analytics content pack to connect with ThreatGrid(TG) platform and achieve various functionalities. Issue background: !threat-grid-sample-list integration command downloads resources for the given sample id from ThreatGrid depending on th...

XSOAR SLA Script

Hi everyone, I have a question regarding SLA tagged scripts on XSOAR. I have a field-change-triggerred script that starts an SLA timer within automation if the field is changed to certain values. This part is okay and we observe that the sla timer starts succesfully. I want to run an SLA script when breach is triggerred for this timer. I have...

Is there Any STIX format for external threat feeds via TAXII Protocol

Hi Palo Alto Community, Is there any documentation or configuration for Palo Alto NGFW that can be integrate with some external threat intelligence feed (via TAXII) to block any IoCs list? I need documentation for direct device, but if you have documentation using TIM in Cortex XSOAR, you can share to me. Now I using TIM in Cortex XSOAR to gat...

A.Faruq by • L1 Bithead
  • 813 Views
  • 0 replies
  • 0 Likes

XSOAR - Scaling for pop-up windows and drop-down menus

Currently there are several areas of the Cortex XSOAR platform experience where pop-up windows and drop down menus appear in a static size regardless of available screen real estate. Automatic scaling to the existing window size would be fantastic! Barring that a manual option to resize each instance would suffice. Added a screenshot of the ...

SplunkPy Integration

Hi everyone,I get data from splunk with the "search index=notable" query using Splunkpy. I assign the incoming data to the type named Splunk Generic Notable by default. Here, when an incident occurs, there are fields such as event_code, process_name in "labels". But on the mapper page, the label section comes empty. This data appears in _raw (in...

  • 1310 Posts
  • 46 Subscriptions
Top Solution Authors