Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! MS 365 Defender Integration Error

Hi,

 

I'm installing MS 365 Defender Addon using the guide (https://xsoar.pan.dev/docs/reference/integrations/microsoft-365-defender), and the "Self-Deployed Application - Client Credentials Flow" method.

 

I have registered the app in Azure, and con

...

MTubia_0-1673396136905.png
MTubia by L1 Bithead
  • 2870 Views
  • 6 replies
  • 0 Likes

Resolved! XSOAR Multi tenant Cortex Data Lake Integration

Hi,

 

I'm checking the manual on how to set up integration between XSOAR and CDL.

https://xsoar.pan.dev/docs/reference/integrations/cortex-data-lake

 

If it is a multi-tenant XSOAR environment, what HUB should I go to for set-up(Step1 and Step4)?

 

F

...

Recurrent data input problems in tasks

Hello,

Data key received from API calls don't always have the same format in the context. Example:

Sometimes it could be:

data.[0].results.username

data.results.[0].username

data.[0].results.[0].username

data.results.username

The API call is the one

...

Josep by L4 Transporter
  • 1316 Views
  • 2 replies
  • 0 Likes

XSOAR XDR Query Context Data Delay

Hi everybody,

could you please help me with following issue?

When I use XQL query to XDR dataset (!xdr-xql-generic-query) it returns correct data to the War room but before are this data moved to Context data it takes almost 5 minutes (No matter how

...

Resolved! Problem with setIncident command

I am working on a new automation which gets triggered dynamically from layout where in I need to check a custom attribute has changed in my remote machine, then update it on the xsoar incident. The custom attribute is a list/array. This is what I am

...

sudhesub by L1 Bithead
  • 2067 Views
  • 2 replies
  • 0 Likes

Test sample in the playbook

Hi,

 

Is it possible to influence the sample data that is shown in playbook edit mode, when using Test to validate the data in any task? I find that in some playbooks it can give me to select the latest incident of that type, but on others - it only

...

Antanas by L2 Linker
  • 1180 Views
  • 1 replies
  • 0 Likes
  • 1127 Posts
  • 36 Subscriptions
Top Solution Authors
Top Liked Authors