Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Create script to close XDR alerts from XSOAR.

Hello,

XSOAR and XDR are used with mirroring, when an incident is closed from XSOAR it's closed in XDR too. However, the alerts in XDR are not. So an script is needed in XSOAR to close those XDR alerts. How is this is script done? where should be set

...

Josep by L4 Transporter
  • 1076 Views
  • 1 replies
  • 0 Likes

Resolved! Uninstall Demisto Server

I am having a little problem uninstalling the demisto server and the documentation isn't clear enough for me to follow(Uninstall Cortex XSOAR (paloaltonetworks.com) I tried the command specifed in the documentation and nothing happened which means th

...

Resolved! Get Dashboard/Widget value from Cortex XSOAR

I created API key in setting and trying to get the dashboard/widget value (e.g. Playbook runs) from XSOAR but failed.

 

 

In the API guideline, there is no example of body parameters in "Get Dashboard Statistics" or "Get Widget Statistics", so I hav

...

ce13_0-1663730334768.png
ce13 by L1 Bithead
  • 2170 Views
  • 2 replies
  • 0 Likes

Automation Output In Indicator or Incident Layout

Dear all,

 

We have an issue about visulazating the outputs of indicator enrichment via using virus total ( vt-passive-dns-data).

 

To be more specific I am going to share our indicator layout and what we are expecting. As its given in the first scre

...

UmutAK_0-1662462438500.png
UmutAK by L1 Bithead
  • 1952 Views
  • 2 replies
  • 0 Likes

Reload QRadar incident information

Is there a form to reload the QRadar inicial values for the incident in case it didn't extract them?

 

Once QRadar set his values in incident context there's no way to reload them in case of error. 

 

 

Josep by L4 Transporter
  • 1338 Views
  • 3 replies
  • 0 Likes
  • 997 Posts
  • 31 Subscriptions
This widget could not be displayed.
Top Solution Authors