Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Not show tasks with errors in the layout when "stop on errors" is set to "no" inside the task.

The incident layout shows the tasks with "Waiting for user"(orange) and "Task with errors"(red). That's important so it can be checked, however some tasks are set with "stop on errors" to "no", because the playbook can be solved without those tasks. How can make this tasks not to show in the layout?

Josep by L4 Transporter
  • 1542 Views
  • 1 replies
  • 0 Likes

Automation Output In Indicator or Incident Layout

Dear all, We have an issue about visulazating the outputs of indicator enrichment via using virus total ( vt-passive-dns-data). To be more specific I am going to share our indicator layout and what we are expecting. As its given in the first screenshot we are using nearly default indicator layout. However to provide more precise informatio...

UmutAK_0-1662462438500.png
UmutAK by L1 Bithead
  • 3441 Views
  • 2 replies
  • 0 Likes

Best way to manage a time based IP blocklist in XSOAR

Hi All, I have been trying to find the best way to manage a list of IP addresses. This is the idea I am trying to achieve. 1) I identify an IP address that is malicious and block it on the PaloAlto firewall in a static object group. 2) I keep track of the IP address along with the time I added it 3) After 48 hours I check the IP addresses I...

Query in Lucene syntax don't get the created data time

Hello, I'm trying to use the automation "SearchIncidentsV2" to get the incidents with two conditions: the name and a range of time. To achieve this, first I created a simple Query to get only the incidentes with a name. name: "name of playbook" It works and a markdown file can be downloaded with all the incidents and other info, like when w...

Josep by L4 Transporter
  • 3103 Views
  • 3 replies
  • 0 Likes

Reload QRadar incident information

Is there a form to reload the QRadar inicial values for the incident in case it didn't extract them? Once QRadar set his values in incident context there's no way to reload them in case of error.

Josep by L4 Transporter
  • 2300 Views
  • 3 replies
  • 0 Likes

Managing Self-signed Certificates

As per the below link it's been mention that by default XSOAR uses self signed certificates for secure HTTP connection. https://docs.paloaltonetworks.com/cortex/cortex-xsoar/6-5/cortex-xsoar-admin/installation/post-installation-checklist/https-with-a-signed-certificate#:~:text=By%20default%20the%20server%20uses%20a%20self%2Dsigned%20certificate%...

DP696 by L2 Linker
  • 1690 Views
  • 1 replies
  • 0 Likes

Resolved! Editing details in xsoar integration

Hi , just want to know if we change the password or any details in a XSOAR integration that fetches incidents do we have to change the “ first fetch time stamp” to fetch new incidents alone ? Or will it just pull new incidents after the password change ? For example : I have an integration xyz that is fetching incidents and I decide to change...

Failed to start Demisto Server Service

Hello Everyone, We recently ran our of disk space on our XSOAR device. I was able to clear out 30GB of old updates/files, ect. I rebooted the server after deleting the files and the Demisto service will not start. When running systemctl status demisto I see the following errors. Sep 14 16:29:43 server systemd[1]: Unit demisto.service entered...

Problem with white spaces in command input

When I try to put a filepath that has white spaces as an input in the command "cs-falcon-rtr-remove-file", I receive the following error: CrowdStrike Falcon The command was failed with the errors: {'d5716ded5d214d61a23884dd9ef64078': 'Max args is 1. 5 were provided'} The complete command used and retrieved from the warrom looks like this: ...

gkindley by L1 Bithead
  • 5256 Views
  • 2 replies
  • 0 Likes

XSOAR CPU been too High

For a while now, our DEV XSOAR server has been holding cpu percentage at 65%. 0 jobs, 0 active workers, less than 10 enabled integrations, and 99 containers. Why is it so high? Any help to diagnose or reduce this percentage is appreciated!

NickyR by L1 Bithead
  • 2054 Views
  • 1 replies
  • 0 Likes

Resolved! Dynamic interactive multi select input inside a playbook

Dears, We are trying to do the following scenario and we want to check if it is doable or not: 1- We have a phishing playbook. 2- We are extracting all the attachments that are included inside an email file (.eml file). 3- the extraction of these files is working properly and we have each file associated with an entry id. 4- we want to su...

  • 1303 Posts
  • 45 Subscriptions