Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Cortex XDR Halt Playbooks?

So we're utilizing XDR Prevent (not Pro) here. Appears to be all the preparation on PAN's site is carefully equipped towards the Proform, and Github hasn't been exceptionally productive.

I'm contemplating whether anybody has any playbooks or work pro

...

Timeframe for Script in a widget

How can I get the Timeframe inside a Dashboard into an python script so that I can use it to query splunk for the same timeframe 

I haven't been able to find anything related to this in the documentation. 

 

Thanks, 

Juan

JuDiaz by L0 Member
  • 2706 Views
  • 3 replies
  • 0 Likes

SplunkPy | Integration test throws error

While testing SplunkPy integration, I am getting the following error.

 

 

Error from SplunkPy is : Script failed to run:

Error: Error [[Traceback (most recent call last):

 

    File "<string>", line 1, in <module>

  ImportError: No module named splunklib.

...

Resolved! Output JSON for Incident Mapping

Hi all,

We have several incidents that we need to work on the mapping of, but they are relatively rare and are not pulled from the (SplunkPy) integration often enough that they are in any of the events that we get when we do the mapping (6.0) and pull

...

Sean_L by L1 Bithead
  • 10587 Views
  • 5 replies
  • 1 Likes

Issue Working with Files

Hello everyone,

 

I am having some trouble working with files in an incident.
I have integrated an API that need a path to upload a file.

This API checks the file extension in the path and as I have seen, file paths in XSOAR incidents are something like

...

Cortex XDR Prevent playbooks?

So we're using XDR Prevent (not Pro) here. Seems all the training on PAN's site is strictly geared towards the Pro version, and github hasn't been very fruitful yet.

I'm wondering if anyone has any playbooks or workflows or (crosses fingers) scripts t

...

Panorama Query Log Fails

Hello all

 

I run into a failure on Playbook Panorama Query Logs.

The failure is:

"Set vsys for firewall or Device group for Panorama"

 

This happen on the GeneralPolling Playbook and there at the task RunPollingCommand.

 

I've defined Device Group and askin

...

MFA for xSOAR portal

Hello,

 

I am running the Community Edition and have not found anything concerning MFA for xSOAR users. What would be the preferred way to enable MFA for users like Analysts and Administrators?

antjar by L0 Member
  • 7273 Views
  • 9 replies
  • 0 Likes

SAML 2.0 -> message signature failed

Hello

 

I do have problems to get Cortex XSOAR talking to our ADFS Server (Windows AD 2012)

Which certificate is here used? It should be, as fas as I understood, somewhere on Cortex XSOAR, but couldn't find anything...

 

 

Spoiler

Response from ADSF Server:

...

  • 1125 Posts
  • 36 Subscriptions
Top Solution Authors
Top Liked Authors