Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! Sumo Logic integration error: This operation is not allowed for your account type

Hi all, the integration with Sumo Logic failed to work and now I get the error: 2022-04-22 12:41:51.3031 error Could not fetch incidents from SumoLogic instance : SumoLogic_instance_1 [error 'Script failed to run: Status: 403ID: WOXBU-A2PLF-BUHRTCode: forbiddenMessage: This operation is not allowed for your account type. at doReq (script:26:27(1...

Resolved! Error while closing incident

Hi!we are testing XSOAR on a local VM. We have created several incidents via an integration with our Threat intel solution.When we are going to close an incident.. it doesn't close! We get no error from the UI. If we go to the VM console, from /var/log/demisto/server.log we can see this error: We have no idea how to troubleshoot this... Could yo...

migueltubia_0-1650377850811.png

ip list retention

Hi, In our environment we have a list to hold ip addresses with comma seperated format, how can we provide data retention for each ip addresses within the list. Regards.

Resolved! Automation "Remove From List" error

Hi, One of my playbook includes a removefromlist automation but sometimes this step gives the error below, if this step is rerun without any change everything is ok. Do you have any idea why it needs to be rerun sometimes and any ideas about this error ? [DB Version '244586' and Insert version '244585' do not match for id: IP_LIST on bucket [] ...

Resolved! Do content pack updates require downtime

I need to update my QRadar Content Pack which also requires X dependencies be upgraded.What is best practice for content package upgrades?Is it as simple as installing from marketplace or do we have to run a sync after or cycle demisto after?Other than reverting to the previous version is there any other precautions you take like taking a fresh ...

jboyd98 by L2 Linker
  • 2463 Views
  • 1 replies
  • 0 Likes

Resolved! Blueliv integration error

Hi! we are testing XSOAR capacities. For testing purposes, we are creating an integration with our intel solution, Blueliv:https://xsoar.pan.dev/docs/reference/integrations/blueliv-threat-compass When fetching it returns an error. From the mapping editor we get this:>The request sent by the client was syntactically incorrectWe think that is s...

Resolved! Do I have to set Server Configurations per tenant?

Example:https://docs.paloaltonetworks.com/cortex/cortex-xsoar/6-5/cortex-xsoar-admin/docker/docker-hardening-guide/run-docker-with-non-root-internal-users#idb5fe7d70-f021-4270-a328-7439d5574723 I set this on the main account and sync'd all accounts.However I noticed this wasn't set on on the configuration page of a tenant after.I ran the !Docker...

jboyd98_0-1649698693248.png
jboyd98 by L2 Linker
  • 2642 Views
  • 2 replies
  • 0 Likes

Resolved! error 'Missing required field: 'owner' when uploading / creating incident via json

Trying to export a ticket from PROD into DEV.To test I exported a ticket in DEV as a json using this in the playground.!azure-sentinel-get-incident-by-id incident_id="c5dc30e5-6981-4cb0-9895-66967fc3f2e9" raw-response="true"(saved as json) Then n DEV, i tried importing the json per the following instructions:https://docs.paloaltonetworks.com/cor...

jboyd98 by L2 Linker
  • 8231 Views
  • 10 replies
  • 0 Likes

Application Unreachable

Hello,I am having issues working with the Automation Menu. When opening the menu I receive the error "Application Unreachable".It appears a few times yet I am still able to access the automation that I need. What is the reason why I am receiving this error and what is the solution. ThanksCortex XSOAR

XSOAR RSS integration not fetching updated feed content

We have configured the RSS integration in the community supported RSS content pack (https://xsoar.pan.dev/marketplace/details/RSS) to ingest CISA NCAS alerts as incidents for our threat intel teams to investigate. This is using the public feed at https://www.cisa.gov/uscert/ncas/alerts.xml . The integration appears to fetch incidents correctly...

MWeir by L0 Member
  • 2277 Views
  • 1 replies
  • 0 Likes

QRadar Integration Magnitude Query not returning expected results

Got a QRadar integration. It's suppose to pull back offenses with magnitude > 4 However, our metrics are much higher than what the client expects.When reviewing this case got pulled into XSOAR:However, when exporting QRadar, the incident has the following: In the second column you can see magnitude has a value of 2; so in theory I don't think...

jboyd98_0-1648657803907.png
jboyd98_1-1648657953036.png
jboyd98 by L2 Linker
  • 3442 Views
  • 3 replies
  • 0 Likes
  • 1303 Posts
  • 45 Subscriptions