Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Transformer to delete line breaks in a string

Hello, Some data is introduced in XSOAR with line breaks. Example: data1, data2, data3, data4 This data is joined with "," to be introduced in a task. However, data is not parsed correctly and the line breaks are introduced, causing an incorrect output. How can this line breaks be removed?

Josep by L4 Transporter
  • 2942 Views
  • 2 replies
  • 0 Likes

Adding user to Team members of an incident by python script

Hello, There is the section "Team Members" with two fields "Owner" and "Participants". I want to add some users to "Participants" but there isn't this field in the context data. I found in the documentation https://docs.paloaltonetworks.com/cortex/cortex-xsoar/6-9/cortex-xsoar-admin/incidents/incident-access-control-configuration that "Team m...

PachaOne_1-1666882573164.png
PachaOne by L1 Bithead
  • 1994 Views
  • 1 replies
  • 0 Likes

Resolved! How to change a .xlsx file in context data or upload new from python script

Hi all, Could you help me with the following problem? I have an incident with .xlsx file that I handle by pandas and openpyxl. After the file will be handled, I need to save it to the context data to upload it to IRP by IRP integration and process a ticket. but I have a problem: when I save the .xlxs file by the method .save from openpyxl t...

PachaOne by L1 Bithead
  • 2913 Views
  • 1 replies
  • 0 Likes

Command "setList" issue introducing variables from context

Hello, We're using command "demisto.executeCommand("setList",{"listName":listName,"listData":listContent})" in order to introduce data in a json list. Where the "listName" is a json list name and "listContent" is data extracted from the context. The issue: The values introduced in "listContent" are like this example, "IPs" is a context variabl...

Josep by L4 Transporter
  • 3077 Views
  • 4 replies
  • 0 Likes

Resolved! SAML role configuration in XSOAR

Hi, We are using SAML 2.0 integration for user authentication to XSOAR. Can someone help to understand what value need to update on "SAML Roles Mapping" in XSOAR under Settings->User and Roles-> Roles. Thanks, Deepa

DP696 by L2 Linker
  • 2137 Views
  • 1 replies
  • 0 Likes

Resolved! Looking for a way to identify links between our parent and subplaybooks.

This relates to lifecycle management and removing old unused playbooks/subplaybooks. We can use the XSOAR Metrics widget to see when a playbook last executed, however this isn't always a good indicator as we have playbooks for rare events which have never triggered but are still required. This isn't such an issue with our parent playbooks as ...

DHodd1 by L0 Member
  • 2011 Views
  • 1 replies
  • 0 Likes

Convert Multiple Files

Hello, I am trying to convert multiple files with different extensions using the 'ConvertFile' automation, so that it can be display on the layout. However, when there are different types of files in one incident, it keeps giving me an error. What would be the best way to list all files and convert them by EntryID? Here what I currently have con...

axespera_0-1670353410461.png
axespera by L1 Bithead
  • 2715 Views
  • 3 replies
  • 0 Likes

A question from the Malware Pack v2 webinar: Malware pack playbooks optimization

Kudos for all the work on developing these playbooks. Are they optimized so the incidents don't get flagged under System Diagnostics (exceptionally big incidents, exceptionally big context, etc)? Note: This question was asked as part of Cortex XSOAR Customer Success Webinar: Malware Investigation & Response V2

rtsedaka by L6 Presenter
  • 2071 Views
  • 1 replies
  • 0 Likes
  • 1302 Posts
  • 45 Subscriptions