Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! Wildfire Reports missing URL

Hello all

 

I did some PDF-Requests to Wildfire and getting Info back as xml.

 

One of those reports are marked as "Malicious" but I do not see, what/why it is Malicious.
So I've investigated and did a curl extract of the sha265 Wildfire Request.

 

And look

...

Resolved! Adding endpoint list to an AD group

Hi,

 

I am currently building a new PlayBook and in one part of that PlayBook, I am trying to add computers, in an XSoar List, to a specific AD group.

 

- I Created a List that contains 2 endpoints separated with a comma ","

- My Playbook is using the Act

...

Cortex XDR Halt Playbooks?

So we're utilizing XDR Prevent (not Pro) here. Appears to be all the preparation on PAN's site is carefully equipped towards the Proform, and Github hasn't been exceptionally productive.

I'm contemplating whether anybody has any playbooks or work pro

...

Timeframe for Script in a widget

How can I get the Timeframe inside a Dashboard into an python script so that I can use it to query splunk for the same timeframe 

I haven't been able to find anything related to this in the documentation. 

 

Thanks, 

Juan

JuDiaz by L0 Member
  • 2514 Views
  • 3 replies
  • 0 Likes

SplunkPy | Integration test throws error

While testing SplunkPy integration, I am getting the following error.

 

 

Error from SplunkPy is : Script failed to run:

Error: Error [[Traceback (most recent call last):

 

    File "<string>", line 1, in <module>

  ImportError: No module named splunklib.

...

Resolved! Output JSON for Incident Mapping

Hi all,

We have several incidents that we need to work on the mapping of, but they are relatively rare and are not pulled from the (SplunkPy) integration often enough that they are in any of the events that we get when we do the mapping (6.0) and pull

...

Sean_L by L1 Bithead
  • 8987 Views
  • 5 replies
  • 1 Likes
  • 953 Posts
  • 30 Subscriptions
Top Solution Authors
Top Liked Authors