Demo Data / Incidents
For purposes of demo'ing / mocking data for testing; how do you handle that....
Curious is there any import function to mock up incident data within XSOAR?
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
For purposes of demo'ing / mocking data for testing; how do you handle that....
Curious is there any import function to mock up incident data within XSOAR?
I want to change the default column view for all my analyst using the "Incidents" page / "Incidents" table.
Is there a way to change that view, or is the table view user specific only and there is no way to set for everyone?
Hi everyone, I'm struggling to make my use case work.
I need to use a playbook X, to change the owner of a specific incident using IncidentID.
Do you ever had this need?
I think I can do it using RestAPI, but i'm failing.
Thanks
Hi,
I succeeded XSOAR integration with Qradar. But I keep getting timeout warnings. I solved this problem by entering parameter "--env=REQUEST_TIME OUT=1500". But I caught that the real problem is in the query. To give an example of this, I enter the
Hi,
I'm trying to use the condition to check if incident.destinationip is an public IP. But when selecting from context incident.destinationip and then IsRFC1918Address you need to fill in something in the right side. I checked the automation script
...
Relatively new admin to XSOAR; previous admin has left.
Just completed upgrade to latest 6.5 version.
Could anyone help me understand the following:
I have a service account that seems to run xsoar demisto server containers; used ps-ef|grep demisto and
Recently had some performance problems reported from my xsoar users.
Found a tenant crashing. Upon investigating I found the following error in the logs:
App03 host:
error Couldn't calc cores number [error 'open /proc/stat: too many open files']error C
Seeing the following every multiple times a minute in my server.log
Note i replaced the host with <host>
error Some requests to accounts failed for incidents export [error '2 of 18 requests to accounts failed! failing accounts are [acc_Dem01,acc_Demi
...
Dear All ,
FortiSiem integration is failing due to the Auth issues , Your help would be appreciated
I have a field trigger script on dbot status changing; essentially updating a custom field to nothing if the an incident is re-opened.
if field=="dbotStatus" and old=="Closed" and new=="Active" and incidentType=="Azure Sentinel":
demisto.executeComman
Hello,
I am trying to pull a file from the context. I tried pulling the 'EntryId' for the file, but the playbook returned an error saying there was not a file at that file path. Is it possible to pull a file from the context, and if so, how can it be
...
Dear Team ,
We are unable to fetch incidents via web-hook integration , it thrown an error (
{"detail":"Method Not Allowed"} )while testing
your help would be greatly appreciated
We have a MT XSOAR deployment, and I need to move a created account that is on the main host to a different one, when I try to move the account I get the error
"Account acc_XXXX could not be moved to HOST because address phoenix.scilabs.mx: missing p
...
Hello,
I have multiple screenshots from various tasks in the playbook such as Rasterize among others from a Sandbox Integration. I would like to make individual widgets on the Layout that can display these Image Files Separately.
1. Can the images be
...
!py script=`return_results(demisto.executeCommand("azure-sentinel-list-incident-entities", {"incident_id":"xxxxxxx-xxxxxx-xxxxx"}))`
The above works and turns in human readable format; however i want to return the raw json.
This works:
!azure-sentinel-
User | Count |
---|---|
1 | |
1 | |
1 | |
1 |
Subject | Likes |
---|---|
1 Like | |
1 Like | |
1 Like | |
1 Like | |
1 Like |
User | Likes Count |
---|---|
2 | |
1 | |
1 | |
1 | |
1 |