Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! Output JSON for Incident Mapping

Hi all,

We have several incidents that we need to work on the mapping of, but they are relatively rare and are not pulled from the (SplunkPy) integration often enough that they are in any of the events that we get when we do the mapping (6.0) and pull

...

Sean_L by L1 Bithead
  • 10356 Views
  • 5 replies
  • 1 Likes

Issue Working with Files

Hello everyone,

 

I am having some trouble working with files in an incident.
I have integrated an API that need a path to upload a file.

This API checks the file extension in the path and as I have seen, file paths in XSOAR incidents are something like

...

Cortex XDR Prevent playbooks?

So we're using XDR Prevent (not Pro) here. Seems all the training on PAN's site is strictly geared towards the Pro version, and github hasn't been very fruitful yet.

I'm wondering if anyone has any playbooks or workflows or (crosses fingers) scripts t

...

Panorama Query Log Fails

Hello all

 

I run into a failure on Playbook Panorama Query Logs.

The failure is:

"Set vsys for firewall or Device group for Panorama"

 

This happen on the GeneralPolling Playbook and there at the task RunPollingCommand.

 

I've defined Device Group and askin

...

MFA for xSOAR portal

Hello,

 

I am running the Community Edition and have not found anything concerning MFA for xSOAR users. What would be the preferred way to enable MFA for users like Analysts and Administrators?

antjar by L0 Member
  • 7139 Views
  • 9 replies
  • 0 Likes

SAML 2.0 -> message signature failed

Hello

 

I do have problems to get Cortex XSOAR talking to our ADFS Server (Windows AD 2012)

Which certificate is here used? It should be, as fas as I understood, somewhere on Cortex XSOAR, but couldn't find anything...

 

 

Spoiler

Response from ADSF Server:

...

XSOAR HTTPS certificate issues

Hi All,

 

I have an issue where I have replaced the self-signed auto generated certificate in XSOAR, the problem is that when I reboot the server the web service doesn't seem to come up, there is no service listening on port 443.

Any help would be great

...

Get "Details" from an Jira Ticket

Hello all

 

How do I get details from an Jira Ticket in Cortex XSOAR?

If I do some "get" and "query" I do get only these output, which I may use in further Tasks:

Spoiler
Ticket
[
{
"Assignee": "aaa",
"Creator": "bbb",
"Id": "1234",
"Key": "ccc-123",
"Status": "
...

XSOAR cant connect to marketplace

Hi
installed a new instance of XSOAR community edition - but cant seem to connect to the marketplace - 
when i try curl to storage.googleapis.com
curl: (56) Recv failure: Connection reset by peer
curl to: https://xsoar.pan.dev works 

the firewall is not d

...

spandor by L0 Member
  • 2817 Views
  • 2 replies
  • 0 Likes

Integration classifier by workflow

Hi,

I have been thinking about this a few times by now. I have a mail listener that fetches incoming mails as incidents. To classify them I would like to send them through a playbook, as a classification key doesn't provide enough context to choose th

...

  • 1104 Posts
  • 34 Subscriptions
Top Solution Authors