Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! Pre-process Rule Assistance

We are trying to create a pre-process rule to link and close the incident when certain field values are identical but still incidents are getting created for identical values. Please find the attached snip.Please note you are posting a public message where community members and experts can provide assistance. Sharing private information such as ...

Resolved! Playbook Creates Incidents from Table.

I'm trying to create incidents from a Cortex XSOAR SIEM integration. The integration allows me to list alerts and I'm trying to create an incident for each one. When I run the playbook, the list alerts command returned multiple entries, but the create incident task is only creating 2 incidents opposed to 10 alerts. I want to ensure that we're ...

Resolved! DEVO integration into XSOAR

Hi we need to integrate DEVO with XSOAR, in order to manage all alerts and be abe to query DEVO. First step is to get all alerts, so we have installed the "Devo v2 (Partner Contribution)" addon into XSOAR and followed the instructions, from https://xsoar.pan.dev/docs/reference/integrations/devo-v2 We have the Token for all tables generated: A...

MTubia_0-1666794019444.png
MTubia_1-1666794048295.png
MTubia_2-1666794133493.png
MTubia by L1 Bithead
  • 2574 Views
  • 2 replies
  • 0 Likes

Open zip file in automation

Hello, I'm downloading a zip file via API with this request: response = doHttpRequest(url=zip, method='GET', headers=headers) it's supposed that my "response" variable now it's the zip file, however when I try to open, I can't, it's like it doesn't exist. How can be unzipped and extract the .txt file inside?

Josep by L4 Transporter
  • 2257 Views
  • 3 replies
  • 0 Likes

Script failed to run: Timeout Error: Docker code script failed due to timeout, consider changing timeout value for this automation, (2604) (2603)

We have a playbook task that sends a query to run on Splunk using the SplunkPy but it keeps failing and returning the following error#22: Splunk Search Query Command: !splunk-search query="index= test blah blah" earliest_time="1666679348" latest_time="1666852148" batch_limit="25000" update_context="true" interval_in_seconds="30"ReasonError from ...

Resolved! Configuration file to playbook

Hi all, I need to provide an externally uploaded configuration file to a playbook whose content varies periodically (it's a list of names). What is the best way to do this? The user who uploads the file can access the XSOAR GUI interface with an Analyst profile.

Rename XSOAR tenant

Receiving more business from a customer for some of their other entities. I need to rename an XSOAR tenant to be more pointed - Is there any instructions on renaming.Can i just stop the tenant and rename the folder on the backend; assume there's more to it than that -

JoshBoyd by L2 Linker
  • 1953 Views
  • 1 replies
  • 0 Likes

Phone call from XSOAR

How can i make Phone calls from a playbook? I found the twilio integration which is able to send SMS, but I'd rather make a phone call to the incident manager somehow. Have you found any solution to this?

McAfee Integration not sending Summary of alerts to XSOAR for ingestion.

I have an integration between McAfee ESM (SIEM) that produces Alerts. 95% of alerts are received by the XSOAR including the "Summary" which is essentially the Alert Packet. Every few days some alerts are received that do not contain the summary. So essentially the time-stamp and the Alert Name appears yet there are no Summary details. The contex...

Resolved! Timeout: Palo Alto Networks WildFire v2

Hello I've configured the Palo Alto Networks WildFire v2 Service with a Wildfire-API Key from our Wildfire-Account at https://eu.wildfire.paloaltonetworks.com/wildfire/accountI also use this Server base URL: https://wildfire.paloaltonetworks.com/publicapi But if I press the Test Button or use this Service in a Playbook, It runs into this:Script ...

Reports generation and download takes alot of time

Hello, I have any issue with generating reports in PDF and CSV formats, as it takes about 10-15mins to generate the report. This issue doesn't exist with word doc. I tried this multiple times as i thought that the docker image for those tasks maybe not local on the server and it took time to download from the Docker Hub registery, but the fac...

Resolved! Xsoar - XDR Public API Unauthorised

I am having difficulty integrating the XDR Integration. I have followed the instructions and have generated an "Advanced Key", copied the Key and the Key ID + URL. I have inserted the relevant details on the Instance Settings. When I perform "Test" I receive "401 Public API Unauthorised". I have tested multiple different roles of API including t...

  • 1298 Posts
  • 45 Subscriptions