Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! running polling commands from automations

opsgenie-get-request is a polling command but when it is being run from an automation it results in an error. From CLI or through playbook tasks, the output returns to the war room once it finishes. That's doesn't seem to be the case in automations. Item not found (8) error is thrown with polling commands (polling: True on .yml file). Looking cl...

XSOAR getIncidents command

Hi community, I've been making great use of custom scripts to extract reporting metrics that wouldn't have been possible with the built in widgets. But something I've noticed recently is that querying incidents seems to be causing huge spikes in CPU and memory usage. Most of my scripts are querying the previous months worth of incidents, whic...

Resolved! Docker Image [exit status 120]

I created an 'image' with the 'docker_image_create' command, containing the pymisp and pandas libraries. I'm having a problem now and I can't make sense of it, any ideas?Error from Scripts is : Script failed to run: Container exit with error. container name: [demistoserver_pyexec-xxxxxxxxxx-uploadmisplatest--xxxxx] error: [exit status 120] (2619...

Resolved! XSOAR Delete Messages using Graph API

I know EWS and O365 are current options for the Delete messages playbook however does anyone know it the Graph API is going to be added as an option? Due to certain restrictions I am being forced down the Graph API route for the preferred integration.

DennisO by L1 Bithead
  • 6361 Views
  • 7 replies
  • 0 Likes

How can I surely say that incident is changed from Pending state to Active state during outgoing mirroring?

When we change the incident from Active state to Close state, we get "closeReason", "closingUserId", and "closeNotes" in the delta of "UpdateRemoteSystemArgs". But when the incident is changed from Pending state to Active state, we do not get anything in delta, and due to which I am not able to determine whether something else has changed or the...

Blueliv API integration error

We are testing XSOAR and integrations. We have some problems when we try to fetch incidents in BlueLiv integration. This is the complete error: Error: Script failed to run: Error: [Traceback (most recent call last): File "<string>", line 502, in <module> File "<string>", line 466, in main File "<string>",...

socser by L0 Member
  • 2077 Views
  • 2 replies
  • 0 Likes

Extract Indicator in XSOAR

Hi all,I want to manually extract the 'IOC alarm' coming from XDR. But the incoming IP addresses come in 2 ways as 'action_local_ip' and 'action_remote_ip'. If I extract according to action_local_ip or action_remote_ip, some IOCs get an error (wrong IP). How can I solve this? Which one should I classify it according to? Cortex XSOAR Cortex XDR

Issue with certificates - Encountering SSL handshake failure error

Hi,Created own self-signed certificate, and replaced with the certificate and key in the designated path '/usr/local/demisto/d1.cert.pem & /usr/local/demisto/d1.key.pem' (on XSOAR engine) and given the required permission and ownership to the files. For one of the endpoint that we are looking to integrate with XSOAR is tighten with 2-way SSL...

DP696 by L2 Linker
  • 3654 Views
  • 2 replies
  • 0 Likes

Resolved! Incident fetch reset timestamp

Hi I have a doubt regarding incident fetch -if we reset the timestamp in any integration in xsoar and set the first fetch as 24 hours. Will it fetch only the new incidents or will it fetch incidents from past 24 hours (note - this is for integration that was already working fine )

SMAX Integration Error

Hi Everyone, We have integrated SMAX as the ticketing solution on XSOAR for one of the clients. After configuring, it is giving an unexpected error. I don't think its a network issue or issue with the credentials. Some assistance on the error would be really helpful. Please find the error message below (also present in the screenshot attache...

Dwai by L0 Member
  • 2475 Views
  • 1 replies
  • 0 Likes

Resolved! McAfee Mvision Integration Missing Image

Hello, I am attempting to use the integration provided by EDR-Integrations by Martin Ohl. When performing the test I receive the error "Error response from daemon: pull access denied for mohlcyber/dxl, repository does not exist or may require 'docker login': denied:". After trying to manually pull this image through the CLI of the XSOAR Server ...

Run a command on all tenants from master

hi everyone, I need some help with microsoft graph integrations with multi tenancy I configured an instance of Microsoft Graph Mail Single User integration in the master and want to sync to all the tenants. Simply syncing won't work because the integration has to run at least once to be initialized before the oproxy token expires. msgraph-ma...

Resolved! XSOAR Mirroring - Move all cases from one tenant to another (with all related information)

Hello, We're looking to move all our cases from one tenant to another one.Looking at the XSOAR Mirroring integration to move all cases. We would like to retrieve all content inside every case.The default settings of the integration (below) doesn't mirror all entries. How can we include all entries in the mirroring?Entry Categories = notes,chat...

Apply transformers directly on variables

Hello, I'm creating Json lists introducing data in them. I'm using "addToList" automation. The data introduced example: listData: {"key1":{ "subkey1: ${dataInput1}, "subkey2: ${dataInput2}, "subkey3: ${dataInput3}, "subkey4: ${dataInput4} } Is there a way to transform the variables directly in the input listData with no need to create a set fo...

Josep by L4 Transporter
  • 1837 Views
  • 1 replies
  • 0 Likes
  • 1304 Posts
  • 45 Subscriptions