Resolved! Add a screenshot to indicator layout using rasterize url
Currently using rasterize url to add screenshots to incidents, any way to do the same for indicators? Thanks for any help
Currently using rasterize url to add screenshots to incidents, any way to do the same for indicators? Thanks for any help
When we change the incident from Active state to Close state, we get "closeReason", "closingUserId", and "closeNotes" in the delta of "UpdateRemoteSystemArgs". But when the incident is changed from Pending state to Active state, we do not get anything in delta, and due to which I am not able to determine whether something else has changed or the...
We are testing XSOAR and integrations. We have some problems when we try to fetch incidents in BlueLiv integration. This is the complete error: Error: Script failed to run: Error: [Traceback (most recent call last): File "<string>", line 502, in <module> File "<string>", line 466, in main File "<string>",...
Hi all,I want to manually extract the 'IOC alarm' coming from XDR. But the incoming IP addresses come in 2 ways as 'action_local_ip' and 'action_remote_ip'. If I extract according to action_local_ip or action_remote_ip, some IOCs get an error (wrong IP). How can I solve this? Which one should I classify it according to? Cortex XSOAR Cortex XDR
Hi,Created own self-signed certificate, and replaced with the certificate and key in the designated path '/usr/local/demisto/d1.cert.pem & /usr/local/demisto/d1.key.pem' (on XSOAR engine) and given the required permission and ownership to the files. For one of the endpoint that we are looking to integrate with XSOAR is tighten with 2-way SSL...
Hi I have a doubt regarding incident fetch -if we reset the timestamp in any integration in xsoar and set the first fetch as 24 hours. Will it fetch only the new incidents or will it fetch incidents from past 24 hours (note - this is for integration that was already working fine )
Hi Everyone, We have integrated SMAX as the ticketing solution on XSOAR for one of the clients. After configuring, it is giving an unexpected error. I don't think its a network issue or issue with the credentials. Some assistance on the error would be really helpful. Please find the error message below (also present in the screenshot attache...
Hello, I am attempting to use the integration provided by EDR-Integrations by Martin Ohl. When performing the test I receive the error "Error response from daemon: pull access denied for mohlcyber/dxl, repository does not exist or may require 'docker login': denied:". After trying to manually pull this image through the CLI of the XSOAR Server ...
hi everyone, I need some help with microsoft graph integrations with multi tenancy I configured an instance of Microsoft Graph Mail Single User integration in the master and want to sync to all the tenants. Simply syncing won't work because the integration has to run at least once to be initialized before the oproxy token expires. msgraph-ma...
Hello, We're looking to move all our cases from one tenant to another one.Looking at the XSOAR Mirroring integration to move all cases. We would like to retrieve all content inside every case.The default settings of the integration (below) doesn't mirror all entries. How can we include all entries in the mirroring?Entry Categories = notes,chat...
Hello, I'm creating Json lists introducing data in them. I'm using "addToList" automation. The data introduced example: listData: {"key1":{ "subkey1: ${dataInput1}, "subkey2: ${dataInput2}, "subkey3: ${dataInput3}, "subkey4: ${dataInput4} } Is there a way to transform the variables directly in the input listData with no need to create a set fo...
When the get-remote-data is being called, I am getting below errors when returning entries to the GetRemoteDataResonse. The command is executes successfully, but I do not get entries in the XSOAR incident which I have passed to the GetRemoteDataResponse. Even the incident is not getting closed though I have returned an entry with "dbotIncidentCl...
I wanted to block ips via using xsoar, on Pan-os panorama. We have integrated xsoar and panoroma but non of the automations provide us a blocking on panorama. In addition to that I tried to give inputs to Block IP Generic v3 playbook(which is provided by palo alto). Our aim is blocking IP **WITHOUT** using edl or static list, which corresponds D...
Hello, i am trying to close duplicated tickets on XSOAR and Splunk automatically using pre processing rules (for closing on XSOAR) and post processing rule (for closing on Splunk) which i wrote a script for However i cannot test the post processing scripts because the pre processing script closes the tickets and i cannot reopen them or access ...
Hi, When testing Cisco ISE OOTB integration in XSOAR getting ' Wait time:1m0s. Note that command is supported from engine version 6.0 and above' error. But we are running on 6.9 version. Can someone help me with this please. Thanks,
| Subject | Likes |
|---|---|
| 1 Like | |
| 1 Like |

