Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Problem with white spaces in command input

When I try to put a filepath that has white spaces as an input in the command "cs-falcon-rtr-remove-file", I receive the following error:

 

CrowdStrike Falcon The command was failed with the errors: {'d5716ded5d214d61a23884dd9ef64078': 'Max args is 1

...

gkindley by L1 Bithead
  • 3715 Views
  • 2 replies
  • 0 Likes

XSOAR CPU been too High

For a while now, our DEV XSOAR server has been holding cpu percentage at 65%. 0 jobs, 0 active workers, less than 10 enabled integrations, and 99 containers. Why is it so high? Any help to diagnose or reduce this percentage is appreciated!

NickyR by L1 Bithead
  • 1467 Views
  • 1 replies
  • 0 Likes

Resolved! python question about importing "msal" module

I want to be able to use this module with my automation scripts:

msal:  https://github.com/AzureAD/microsoft-authentication-library-for-python

 

import msal 
by default fails as the module is not installed or available by default.

 

How would i manual

...

JoshBoyd by L2 Linker
  • 3287 Views
  • 4 replies
  • 0 Likes

Resolved! Indicator enrichment detail in layout

Hi,

 

In one of our playbook there are 2 enrichment type of integrations deployed for ip enrichment (virustotal and abusedb) all works well as expected and they feed indicator itself but shows only verdict in indicator layout although these enrichmen

...

MKececioglu_0-1661949108501.png
MKececioglu_1-1661949119395.png

Playbook task naming in subplaybooks

Hi!

 

I can't find much data on Subplaybook naming numbers - how are they being assign and when do they change?

I've run into the following issue: i had a standalone playbook with some subplaybooks inside. In the main playbook I've been referring to

...

Antanas by L2 Linker
  • 3054 Views
  • 7 replies
  • 0 Likes

Resolved! Get command arguments in Powershell scripts

Hi all

 

I'm trying to get Command-Arguments in a self-made script in Powershell.

 

On Python it is:
demisto.args().get('<command-argument>')

 

What is it in Powershell? Because I tried it with:
$demisto.Args()["<command-argument>"]

But this didn't worked on

...

Resolved! Upload IOC from file to firewall via XSOAR

Hi, 

 

I want to find a way of maximum automatization of the next process: IOC are extracted from CSV file to Cortex XSOAR and than only this indicators are uploaded to firewalls. 

 

I found automations for each step separately but maybe exist any pl

...

asernova by L0 Member
  • 1840 Views
  • 1 replies
  • 0 Likes
  • 1159 Posts
  • 38 Subscriptions