Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! XSOAR Incident Workflow implementation

hi,is there a possibility in xsoar to prevent an incident from being closed if certain conditions are not met? I would like to implement in incident workflow where one part is executed automatically and the other by the analyst, then if certain fields are not valorised prevent the closure of the incident.Thank you very muchregards

Resolved! Error "Docker timeout" while using datetime library

Hi all, We were experiencing issues with integrations that are making use of the library "datetime" When trying to execute this piece of code:   It returns the following error:   We've tried using different Docker images, creating our own images from scratch and running the code in different hosts but we are getting the same error all ...

MicrosoftTeams-image (3).png
MicrosoftTeams-image (4).png

Resolved! Use DT format inside an automation.

Hello, We are working on an automation which calls many different lists of nested dicts. Example: upField: 0: field1:value1 field2: value2 1: field1:value3 field2: value4 In a playbook it will be easy to call only field1 using this expression: ${upField.field1} . It will create an array with these values: [value1, value3] However, if we want t...

Josep by L4 Transporter
  • 3146 Views
  • 2 replies
  • 0 Likes

Shorten returned values in query

I'm creating a widget so I can have a report run returning certain Managment Audit log information. One of the fields, "Management_Auditing_type" has values that are quite long that I would like to truncate. For example, have "MANAGEMENT_AUDIT_ACTION_CENTER" changed to "Action Center", and "Management_Audit_Policy_Profiles" changed to just "Po...

Onboarding Playbook Questions

Hi, I am needing to build a playbook for onboarding new accounts into Active Directory. I do know they have some Premium Playbooks but I don't have that budget so building our own. How do I take in to account the aspect if the username is already taken and how to adjust for that? Is there a task to create an email account when Hybrid 365 is u...

War Room showing limited outputs

Hello, We are executing a long playbook. This playbook started to work incorrectly. To check what was happening, we looked inside the War Room, but it only showed a limited number of outputs. In order to check more outputs, we had to scroll up inside the War Room, however, it took too long to load just a couple of new outputs. How can we obtain ...

Josep by L4 Transporter
  • 2194 Views
  • 3 replies
  • 0 Likes

ElasticSearch Integration(insert/select/delete)

Hello, I have some questions about ElasticSearch Intergration.This integration imports only events as incidents?If I want to execute (run) insert/select/delete commands in ElasticSearch should I update the integration? Or did you have any other way to do it that could be a better idea? Automate or update the integration duplicated?Thanks

Delete List using automation/command?

Hi All, I wanted to delete a list using a playbook tasks, but I dont find any automation that can achieve it. It only have createList, and remove data from List May I know any workaround for it? Regards,Jia Kai

JOng39 by L1 Bithead
  • 3896 Views
  • 3 replies
  • 0 Likes

Resolved! ParseExcel automation issue

hello,using XSOAR I wanted to parse an excel from an e-mail and insert the information into a table. I created a Grid field by inserting it inside the incident, used ParseExcel inside a playbook setting as "Mapping" inside the automation to identify the output and then inserted it inside the created Grid field as you can see from the image. Unf...

FrancescoBarducci_0-1695725938445.png

Upgrade issue with the description of incident field

Hi community. We have issue with the upgrade scenario of the description (tooltip) of the incident field for the Dataminr Pulse integration for XSOAR. We have updated the description of the incident fields: Dataminr Pulse Post Link and Dataminr Pulse Expand Alert URL. After upgrading pack from 1.0.5 to 1.0.6, we are not able to see the tool...

Resolved! How to access incidents a user is participant of

Roles field is a good way to restrict access to incidents. but in my case I just want to assign a group of people to manage an incident and not restrict the incidents to other people. In order to do that I am adding users to the incident as a team member. Team member is used mainly because it can add team members by tagging '@' Once these use...

Resolved! Create clean Notes in the layout

Hello, We'd like to create Notes in the layout. We can use the option "Mark results as note", but it shows the command executed. We'd like to show a clean note, nothing else.

Josep by L4 Transporter
  • 2872 Views
  • 3 replies
  • 1 Likes

"taskComplete isAutoRun=True" not working

Hello, We are using a playbook to run again tasks which are already running. Just to reset the task. However, when the command "taskComplete isAutoRun=True" is used, it doesn't run again. How can we avoid this? Is there another option?

Josep by L4 Transporter
  • 1701 Views
  • 2 replies
  • 0 Likes

XSOAR - Microsoft Integrations - Authentication - Office365 Mail not authenticating

Hi all! Thanks a lot in advanced for your help. We are trying to connect to a mail server using the newest release of the Microsoft Exchange Integration. We've followed the instructions detailed here: https://xsoar.pan.dev/docs/reference/articles/microsoft-integrations---authentication#self-deployed-application Both, using the Cortex XSOAR...

MicrosoftTeams-image.png
Outlook.png

Resolved! Splunk Integration

Hi, I have been trying to integrate Splunk Enterprise with xsoar and I keep getting this error message with url: /services/auth/login (Caused by SSLError(SSLError(1, '[SSL: WRONG_VERSION_NUMBER] wrong version number (_ssl.c:1007)'))) ] (2604) (2603) how can I fix this and get the integration to work. pls I need help

  • 1298 Posts
  • 45 Subscriptions