Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Find playbooks and subplaybooks not being used

Hello,

 

Our XSOAR complexity has increased during the years, this means more playbooks and subplaybooks deployed.

However, some of them are not used anymore, many reasons about it.

 

How can these unnecessary playbooks and subplaybooks detected and

...

Josep by L4 Transporter
  • 1455 Views
  • 2 replies
  • 0 Likes

XSOAR ON AZURE MARKETPLACE

Hello All,

 

Has anyone deployed XSOAR using Azure Marketplace?

 

I was able to deploy one for testing, but I couldn't logon to the GUI, I believe there should be a default admin password created when the VM was created just as documented when using

...

ORufai by L0 Member
  • 1492 Views
  • 2 replies
  • 0 Likes

Resolved! Read Email Body

I am trying to write a playbook that will read the email body and understand what the email is related to base on keywords or patterns. Is there a script or integration that could do that? My best idea is to use Machine Learning for it, but I am not

...

axespera by L1 Bithead
  • 2498 Views
  • 2 replies
  • 0 Likes

Resolved! Resetting Qradar integration and keep mapped alerts.

Hello colleagues,

I'm using Qradar integration with all the alerts mapped and parameters configured. In order to solve a "fetch events" puntual problem is recommended to reset the integration with empty parameters and the use again the already workin

...

Josep by L4 Transporter
  • 1587 Views
  • 1 replies
  • 0 Likes

Resolved! Pre-process Rule Assistance

We are trying to create a pre-process rule to link and close the incident when certain field values are identical but still incidents are getting created for identical values. Please find the attached snip.



Please note you are posting a public message...

Resolved! Playbook Creates Incidents from Table.

I'm trying to create incidents from a Cortex XSOAR SIEM integration. The integration allows me to list alerts and I'm trying to create an incident for each one. When I run the playbook, the list alerts command returned multiple entries, but the creat

...

Resolved! DEVO integration into XSOAR

Hi

we need to integrate DEVO with XSOAR, in order to manage all alerts and be abe to query DEVO. First step is to get all alerts, so we have installed the "Devo v2 (Partner Contribution)" addon into XSOAR and followed the instructions, from https://x

...

MTubia_0-1666794019444.png
MTubia_1-1666794048295.png
MTubia_2-1666794133493.png
MTubia by L1 Bithead
  • 2165 Views
  • 2 replies
  • 0 Likes

Open zip file in automation

Hello,

I'm downloading a zip file via API with this request:

  • response = doHttpRequest(url=zip, method='GET', headers=headers)

it's supposed that my "response" variable now it's the zip file, however when I try to open, I can't, it's like it doesn't e

...

Josep by L4 Transporter
  • 1872 Views
  • 3 replies
  • 0 Likes

Script failed to run: Timeout Error: Docker code script failed due to timeout, consider changing timeout value for this automation, (2604) (2603)

 

We have a playbook task that sends a query to run on Splunk using the SplunkPy but it keeps failing and returning the following error
#22: Splunk Search Query


Command
!splunk-search query="index= test blah blah" earliest_time="1666679348" latest_ti

...

  • 1247 Posts
  • 43 Subscriptions
Top Solution Authors
Top Liked Authors