Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! XSOAR NSlookup and ThreatVault info

Hi everybody,

 

is there a way how to get following information in XSOAR?

 

- NSLOOKUP - I have an IP address and need to get name from internal DNS server

- Threat Vault info - I have an information from the firewall (threat name and threat ID) and

...

Resolved! integration indicator pull limits?

Hi there,

 

I've just started testing threat feed integration in XSOAR.

For some reason, the integration instance was only downloading 100 indicators on each pull whereas the source has thousands.

Is it because my AWS instance doesn't have a license?

...

boweic by L0 Member
  • 1162 Views
  • 1 replies
  • 0 Likes

Resolved! Extract Indicators from context to Field

Hi,

I have one playbook where I'm using the Builtin ExtractIndicators Function to extract any indicator from one field, and it's working fine:

After this, I call more subplaybooks, and I want, from this subplaybooks, use this indicators for some act

...

MTubia_0-1669885597443.png
MTubia by L1 Bithead
  • 2244 Views
  • 3 replies
  • 0 Likes

fatal Error during ensure repo

Hi everyone,

I am facing a strange issue. I was trying to change the certificate like explained in this link https://docs.paloaltonetworks.com/cortex/cortex-xsoar/6-1/cortex-xsoar-admin/installation/post-installation-checklist/https-with-a-signed-cert

...

arn_stoz by L0 Member
  • 4689 Views
  • 7 replies
  • 0 Likes

Error handling

 
Hi all, with this type of setting (see the img), if in the next task I check $ {lastCompletedTaskEntries} to verify if the previous task is in error, the result is positive even if the second retry task went well. How can I get ar
...

immagine.png

Resolved! Export playbooks, alerts list

Hi All,

 

I am new to xSOAR and wanted to know if  there is a way to export the list of playbooks enabled in my environment

This is to check what playbooks we are using Vs what is available in marketplace

 

Thank you

aparna

aparnaas by L1 Bithead
  • 1274 Views
  • 1 replies
  • 0 Likes

Resolved! Add a comment on an indicator from playbook

Hello,

 

In many indicators' layout there is a comment section where users can add text comment.

 

Is there a way to automatically add comment from a playbook?

 

Looking at setIndicator, I didn't find the right field associated to the comment section

...

customize widget from script

Hi Team,

 

I have developed automation to get all the similar incident names with dictionary return results that have ID and incident name.

 

Once I call the script from the widget, pie, table, or any of them, I get the following error; anyone can he

...

bzahran_0-1669213017794.png
bzahran by L0 Member
  • 1256 Views
  • 2 replies
  • 0 Likes

Extract Domains from Phishing Attached Email

Hi Team,

 

I hope all are doing well; how can I extract the domains from the phishing attached files?

 

I extracted the email using " ParseEmailFilesV2 "; exported all the email parameters such as HTML and others successfully; however, once I tried t

...

bzahran by L0 Member
  • 1894 Views
  • 3 replies
  • 0 Likes
  • 1032 Posts
  • 32 Subscriptions
Top Liked Authors