Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Question from Playbook Optimization webinar: Sub-Playbook quiet mode

Let's say we fix a sub playbook to run in quiet mode cos it's larger than 150KB. Will this affect the main playbook if it is dependent on the subplaybook output. Also will it fix all the older incidents that have already run ? ** Note: this is a question from our Customer Success Webinar: Playbook optimization in Cortex XSOAR Cortex XSOAR

rtsedaka by L6 Presenter
  • 2169 Views
  • 1 replies
  • 0 Likes

Question from Playbook Optimization webinar: Command modification

Is it possible to modify all instances of a command? For instance, if we wanted to change the "Run without a worker" setting on all usages of sleep - is that possible? Or would I need to do it 1-by-1? Or even possible per playbook maybe with multi-select? ** Note: this is a question from our Customer Success Webinar: Playbook optimization in C...

rtsedaka by L6 Presenter
  • 2016 Views
  • 1 replies
  • 0 Likes

Resolved! SLA changes that are made by field change scripts are getting reverted

Hi, I have a a field trigger script assigned to a status field. When it changes, the script stops an SLA and starts another and these are Time To Assignment and Response SLA respectively. I have one tenant that refuses to keep the changes meaning that it sets the SLAs and then within a second all is reverted. I can clearly see it on the incident...

image.png
image.png
image.png

Resolved! Arcsight base event to layout

Hi, My Playbook is able to get arcsight events those related to a correlation (alarm) but i need to visualize these base events into layout tab but cant find a proper way. Do you have any suggestion ? Regards.

Resolved! Joining two keys with the same subkey value

Hi, I need to join 2 context keys that match value of the same subkey, however I can't find a proper automation or transformation. In context I have 2 keys. One key contains IP's and Hostnames, the other contains IP's and Email Admins. I want to join those that match same IP. E.g. : In the above scenario, as a result I want to have a key, that w...

unnamed (1).png
Antanas by L2 Linker
  • 4763 Views
  • 4 replies
  • 0 Likes

PCSAE Course Free

Hi All, I just wanted to put out there that I have made a course around the PCSAE certification and that it is completely free, the link to the YouTube playlist is https://youtube.com/playlist?list=PL_ZuwXjrdb3j_vcAFCMLQxlJ6oFAi3HYT please have a look, I welcome all feedback especially from this community so let me know what you think.

Task "jira-edit-issue" can not handle arrays in "Description"-Filed (with solution)

HelloI had an issue with an array for several tickets in jira-edit-issue and there in the field "Description".the problem was, that I had several outputs from an other Task.So, the array "output.color": contains:[{"Color":"blue"},{"Color":"green"},{"Color":"red"]Now I had three Jira-Tasks to update.First ticket with following content in the "Des...

  • 1303 Posts
  • 45 Subscriptions