Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Managing Self-signed Certificates

As per the below link it's been mention that by default XSOAR uses self signed certificates for secure HTTP connection.

https://docs.paloaltonetworks.com/cortex/cortex-xsoar/6-5/cortex-xsoar-admin/installation/post-installation-checklist/https-with-a

...

DP696 by L2 Linker
  • 1144 Views
  • 1 replies
  • 0 Likes

Resolved! Editing details in xsoar integration

Hi ,

just want to know if we change the password or any details in a XSOAR integration that fetches incidents do we have to change the “ first fetch time stamp” to fetch new incidents alone ?  Or will it just pull new incidents after the password cha

...

Failed to start Demisto Server Service

Hello Everyone, 

We recently ran our of disk space on our XSOAR device. I was able to clear out 30GB of old updates/files, ect. I rebooted the server after deleting the files and the Demisto service will not start. When running systemctl status demis

...

Problem with white spaces in command input

When I try to put a filepath that has white spaces as an input in the command "cs-falcon-rtr-remove-file", I receive the following error:

 

CrowdStrike Falcon The command was failed with the errors: {'d5716ded5d214d61a23884dd9ef64078': 'Max args is 1

...

gkindley by L1 Bithead
  • 2826 Views
  • 2 replies
  • 0 Likes

XSOAR CPU been too High

For a while now, our DEV XSOAR server has been holding cpu percentage at 65%. 0 jobs, 0 active workers, less than 10 enabled integrations, and 99 containers. Why is it so high? Any help to diagnose or reduce this percentage is appreciated!

NickyR by L1 Bithead
  • 1183 Views
  • 1 replies
  • 0 Likes

Resolved! python question about importing "msal" module

I want to be able to use this module with my automation scripts:

msal:  https://github.com/AzureAD/microsoft-authentication-library-for-python

 

import msal 
by default fails as the module is not installed or available by default.

 

How would i manual

...

JoshBoyd by L2 Linker
  • 2596 Views
  • 4 replies
  • 0 Likes

Resolved! Indicator enrichment detail in layout

Hi,

 

In one of our playbook there are 2 enrichment type of integrations deployed for ip enrichment (virustotal and abusedb) all works well as expected and they feed indicator itself but shows only verdict in indicator layout although these enrichmen

...

MKececioglu_0-1661949108501.png
MKececioglu_1-1661949119395.png

Playbook task naming in subplaybooks

Hi!

 

I can't find much data on Subplaybook naming numbers - how are they being assign and when do they change?

I've run into the following issue: i had a standalone playbook with some subplaybooks inside. In the main playbook I've been referring to

...

Antanas by L2 Linker
  • 2367 Views
  • 7 replies
  • 0 Likes
  • 997 Posts
  • 31 Subscriptions
This widget could not be displayed.
Top Solution Authors