Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Query in Lucene syntax don't get the created data time

Hello, I'm trying to use the automation "SearchIncidentsV2" to get the incidents with two conditions: the name and a range of time. To achieve this, first I created a simple Query to get only the incidentes with a name. name: "name of playbook" It works and a markdown file can be downloaded with all the incidents and other info, like when w...

Josep by L4 Transporter
  • 3046 Views
  • 3 replies
  • 0 Likes

Reload QRadar incident information

Is there a form to reload the QRadar inicial values for the incident in case it didn't extract them? Once QRadar set his values in incident context there's no way to reload them in case of error.

Josep by L4 Transporter
  • 2265 Views
  • 3 replies
  • 0 Likes

Managing Self-signed Certificates

As per the below link it's been mention that by default XSOAR uses self signed certificates for secure HTTP connection. https://docs.paloaltonetworks.com/cortex/cortex-xsoar/6-5/cortex-xsoar-admin/installation/post-installation-checklist/https-with-a-signed-certificate#:~:text=By%20default%20the%20server%20uses%20a%20self%2Dsigned%20certificate%...

DP696 by L2 Linker
  • 1662 Views
  • 1 replies
  • 0 Likes

Resolved! Editing details in xsoar integration

Hi , just want to know if we change the password or any details in a XSOAR integration that fetches incidents do we have to change the “ first fetch time stamp” to fetch new incidents alone ? Or will it just pull new incidents after the password change ? For example : I have an integration xyz that is fetching incidents and I decide to change...

Failed to start Demisto Server Service

Hello Everyone, We recently ran our of disk space on our XSOAR device. I was able to clear out 30GB of old updates/files, ect. I rebooted the server after deleting the files and the Demisto service will not start. When running systemctl status demisto I see the following errors. Sep 14 16:29:43 server systemd[1]: Unit demisto.service entered...

Problem with white spaces in command input

When I try to put a filepath that has white spaces as an input in the command "cs-falcon-rtr-remove-file", I receive the following error: CrowdStrike Falcon The command was failed with the errors: {'d5716ded5d214d61a23884dd9ef64078': 'Max args is 1. 5 were provided'} The complete command used and retrieved from the warrom looks like this: ...

gkindley by L1 Bithead
  • 5205 Views
  • 2 replies
  • 0 Likes

XSOAR CPU been too High

For a while now, our DEV XSOAR server has been holding cpu percentage at 65%. 0 jobs, 0 active workers, less than 10 enabled integrations, and 99 containers. Why is it so high? Any help to diagnose or reduce this percentage is appreciated!

NickyR by L1 Bithead
  • 2024 Views
  • 1 replies
  • 0 Likes

Resolved! Dynamic interactive multi select input inside a playbook

Dears, We are trying to do the following scenario and we want to check if it is doable or not: 1- We have a phishing playbook. 2- We are extracting all the attachments that are included inside an email file (.eml file). 3- the extraction of these files is working properly and we have each file associated with an entry id. 4- we want to su...

Not able to use the context of one closed incident in a new one using Debugger Panel.

Hello, I'd like to use the information I have in a already closed incident into a new one I'm developing just to test it. When I click in the "Debugger Panel"->"Test data" and I search by the id of the closed incident it doesn't show up.Is there a way of importing the context without opening again the incident? Thanks.

Josep by L4 Transporter
  • 1555 Views
  • 1 replies
  • 0 Likes

Resolved! python question about importing "msal" module

I want to be able to use this module with my automation scripts: msal: https://github.com/AzureAD/microsoft-authentication-library-for-python import msal by default fails as the module is not installed or available by default. How would i manually correct?

JoshBoyd by L2 Linker
  • 4764 Views
  • 4 replies
  • 0 Likes
  • 1300 Posts
  • 45 Subscriptions
Top Liked Authors