Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

No download Link

Hello I have received my license over email but the email does not contain any download link. Where can I get the files? Thanks.

JDiaz15 by L1 Bithead
  • 2615 Views
  • 5 replies
  • 0 Likes

XSOAR Ideal Development Environment

Hi everyone, we are a small team of 3 and trying to understand if we request more resources than necessary from our admins. We all have our own xsoar instances for development because we don't want to write to the same automation someone else is working on , basically we want isolation. Multi tenancy allows tenant level content upload but there ...

Teams integration in xsoar

Hi , I have few queries reg teams integration in xsoar. If we are integrating teams Using Cortex XSOAR rerouting1. what port should be opened from XSOAR2. What Urls should be whitelisted from XSOAR 3.if we are Creating the Demisto Bot in Microsoft Teams from Microsoft Developer Portal we will be able to generate client secret , should this be ad...

Import XSOAR incidents into MySQL DB

Hello all, I have MySQL DB to collect data from different projects/products and using Metabase to create dashboards. I would like to import all incidents into MySQL DB from XSOAR. Is there any integration can do it directly or I have to write python code to retrieve all incidents through XSOAR API? If API is the only option, should I use "Se...

ce13 by L1 Bithead
  • 1659 Views
  • 2 replies
  • 0 Likes

Cannot Impersonate user using the EWS O365 Integration in XSOAR

I'm trying to send mail from our service desk address and everytime DBOT produces an error "The user account which was used to submit this request does not have the right to send mail on behalf of the specified sending account., Cannot submit message." The azure app that the EWS O365 integration uses has the necessary API access to send mail a...

Splinter by L0 Member
  • 2425 Views
  • 2 replies
  • 0 Likes

Resolved! Content package is not able to update

Hi Friends, we are trying to update the content package and integrate it with any package into XSOAR it's showing the error: Could not install pack: could not create content item from file 'Lists/list-PrivateIPs.json'. invalid content item type 'list' Can anyone help me to solve this problem? Regards Vinay Cortex XSOAR

VinayKumarTM_0-1677851287923.png

Resolved! Running XQL Query to XDR from an Automation Script : Receiving 500 Bad Synatax from valid query

Hello all, I am attempting to run an XQL query from an automation script. The query is valid and can be run manually and this works well both on XSOAR and on the Query Editor section on XDR. Essentially we refer to the query under a variable and then reference the variable under the execute command.... The error I receive is 500 - token recogni...

Propagation labels problem

Hi everybody, I am really having a hard time syncing content with tenants because propagation labels aren't working properly for me. To give you an example, I create an xsoarcommunity tenant and set the propagation label to carbon_test so that I can't sync cortex xdr content with this tenant by mistake. Palo Alto Networks Cortex XDR - Investigat...

EnesOzdemir_0-1657001869742.png
EnesOzdemir_1-1657001968955.png
EnesOzdemir_2-1657002019975.png
EnesOzdemir_3-1657002057104.png

Resolved! File upload from XSOAR war room to Sentinel watchlist

Hi, Newbie to Xsoar and working on an automation when a csv file is uploaded to war room, it should upload the csv to Azure Sentinel watchlist. From what I understand, I can do this by grabbing the file entry id of the latest file uploaded and then using the entry id upload it to Sentinel watchlist. Is there a better way to do this ? If n...

A_Menon by L0 Member
  • 2864 Views
  • 2 replies
  • 0 Likes
  • 1298 Posts
  • 45 Subscriptions