Closing an incident on CortexXDR with pre-processing.
Hi all,
I want to mark the Cortex XDR incident coming into XSOAR as TP or FP with preprocessing. Does preprocessing allow this (run a script)? Or does it only do drop processing?
Hi all,
I want to mark the Cortex XDR incident coming into XSOAR as TP or FP with preprocessing. Does preprocessing allow this (run a script)? Or does it only do drop processing?
Hi Support,
We have a special setup on our cortex xsoar which allows podman to use a Proxy A for pulling images from docker repositories (via http_proxy and http_proxy) and a Proxy B for python integration (Via python.extra.keys) to access internet
...
Hi,
I have integrated Panorama with XSOAR, instance is successfully created.
Now I have to block IP using this integration. I want to block ips just using panorama xsoar integration by using Static Address Group
Can anyone please assist how to go forw
incident.labels.source_address_ids:["1.2.3.4']
for above json value when i am parsing/using variable in title field getting error ( i.e. expecting ',' )
is there any way while calling variable we can ignore/exclude characters ( [ and " )
tried
...
Hi all,
In a list field, I want to go through all indexes one by one and if there is *malware* in all indexes(malware execution, malware alert, malware), I want to drop it. However, I could not edit this in the "Conditions for Incoming Incident" fiel
...
I want to attach the CSV file in the Playbook as an attachment to the e-mail and send it. I use Msgraph. If I send it without attachments, the mail is sent. But when I add an attachment, the mail is not sent. I'm using the following command. I tried
...
Hi ,
Is there any option to automatically close Incident when offense closed via Qradar ?
In the integration setting there is the option - "Close Mirrored XSOAR Incident" but it doesn't for work me.
Hello everyone,
What is the best option to add a delay in a playbook, for example I have 2 automated tasks and want task 2 to start after task 1 finishes by 1 hour.
I thought of creating a one-line automation that has time.sleep(amount) and addi
...
Dears,
Hope you are doing well.
We need to close the Incidents on xsoar from preprocess script, How can we close it using a script in preprocess rule?
I dont need other options like: link and close or drop or close. Because there are some mandato
...
Hello,
We'd like to know if a zip file is encrypted inside a playbook or a automation. The way in which XSOAR works with these files does not allow the use of python libraries. Is there a way through the File context value to know if the file is encr
...
Dear Community members,
hope you are all doing well !
I'm wondering if there is an option to include linked incident table (can be added to the incident layout) in email template.
I'm using Mail sender (New) : https://xsoar.pan.dev/docs/referenc
...
Hello,
I have tried many settings and can't seem to quite figure out what text is to be entered into the setup section within Xsoar for the Azure SAML SSO setup. I keep getting this error:
" {"id":"errSAMLLogin","status":400,"title":"Failed to login
...
Hi ,
Is there a way to filter incidents in specific time interval ?
For example -
Filter incidents that occurred From 1/5/2023 to 31/5/2023 only between 7:00 to 14:00
Error Detail:
ContentPackInstaller - Error occurred while setting up machine. string indices must be integers
Any suggestion, what could be the reason. Tried to pass integer values also but no luck.
Hi all,
I have a multi-tenant deployment. I want to run a script or playbook from one tenant to another tenant. How can I do this?
#XSOAR
| Subject | Likes |
|---|---|
| 1 Like | |
| 1 Like | |
| 1 Like | |
| 1 Like |

