Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Reload QRadar incident information

Is there a form to reload the QRadar inicial values for the incident in case it didn't extract them? Once QRadar set his values in incident context there's no way to reload them in case of error.

Josep by L4 Transporter
  • 2231 Views
  • 3 replies
  • 0 Likes

Managing Self-signed Certificates

As per the below link it's been mention that by default XSOAR uses self signed certificates for secure HTTP connection. https://docs.paloaltonetworks.com/cortex/cortex-xsoar/6-5/cortex-xsoar-admin/installation/post-installation-checklist/https-with-a-signed-certificate#:~:text=By%20default%20the%20server%20uses%20a%20self%2Dsigned%20certificate%...

DP696 by L2 Linker
  • 1646 Views
  • 1 replies
  • 0 Likes

Resolved! Editing details in xsoar integration

Hi , just want to know if we change the password or any details in a XSOAR integration that fetches incidents do we have to change the “ first fetch time stamp” to fetch new incidents alone ? Or will it just pull new incidents after the password change ? For example : I have an integration xyz that is fetching incidents and I decide to change...

Failed to start Demisto Server Service

Hello Everyone, We recently ran our of disk space on our XSOAR device. I was able to clear out 30GB of old updates/files, ect. I rebooted the server after deleting the files and the Demisto service will not start. When running systemctl status demisto I see the following errors. Sep 14 16:29:43 server systemd[1]: Unit demisto.service entered...

Problem with white spaces in command input

When I try to put a filepath that has white spaces as an input in the command "cs-falcon-rtr-remove-file", I receive the following error: CrowdStrike Falcon The command was failed with the errors: {'d5716ded5d214d61a23884dd9ef64078': 'Max args is 1. 5 were provided'} The complete command used and retrieved from the warrom looks like this: ...

gkindley by L1 Bithead
  • 5154 Views
  • 2 replies
  • 0 Likes

XSOAR CPU been too High

For a while now, our DEV XSOAR server has been holding cpu percentage at 65%. 0 jobs, 0 active workers, less than 10 enabled integrations, and 99 containers. Why is it so high? Any help to diagnose or reduce this percentage is appreciated!

NickyR by L1 Bithead
  • 1980 Views
  • 1 replies
  • 0 Likes

Resolved! Dynamic interactive multi select input inside a playbook

Dears, We are trying to do the following scenario and we want to check if it is doable or not: 1- We have a phishing playbook. 2- We are extracting all the attachments that are included inside an email file (.eml file). 3- the extraction of these files is working properly and we have each file associated with an entry id. 4- we want to su...

Not able to use the context of one closed incident in a new one using Debugger Panel.

Hello, I'd like to use the information I have in a already closed incident into a new one I'm developing just to test it. When I click in the "Debugger Panel"->"Test data" and I search by the id of the closed incident it doesn't show up.Is there a way of importing the context without opening again the incident? Thanks.

Josep by L4 Transporter
  • 1520 Views
  • 1 replies
  • 0 Likes

Resolved! python question about importing "msal" module

I want to be able to use this module with my automation scripts: msal: https://github.com/AzureAD/microsoft-authentication-library-for-python import msal by default fails as the module is not installed or available by default. How would i manually correct?

JoshBoyd by L2 Linker
  • 4703 Views
  • 4 replies
  • 0 Likes

Resolved! Indicator enrichment detail in layout

Hi, In one of our playbook there are 2 enrichment type of integrations deployed for ip enrichment (virustotal and abusedb) all works well as expected and they feed indicator itself but shows only verdict in indicator layout although these enrichments return much more detailed data. I need help about visualize this detailed post-indicator-enric...

MKececioglu_0-1661949108501.png
MKececioglu_1-1661949119395.png

Playbook task naming in subplaybooks

Hi! I can't find much data on Subplaybook naming numbers - how are they being assign and when do they change? I've run into the following issue: i had a standalone playbook with some subplaybooks inside. In the main playbook I've been referring to the results of the subplaybooks by e.g. subplaybook-167.something. It worked fine until I started...

Antanas by L2 Linker
  • 4640 Views
  • 7 replies
  • 0 Likes
  • 1298 Posts
  • 45 Subscriptions