Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Splunk custom index not getting incident in xsoar

I am using splunk 60 day free trial non-enterprise edition and created a new custom index in splunk and manually added a sample event csv format file in the new index and all date is 2 days ago sample datasplunk integration with xsoar does not generate any incident, is there a configuration and timestamp problem?

Screen Shot 2022-03-11 at 1.33.40 PM.png
Screen Shot 2022-03-11 at 1.34.28 PM.png
Screen Shot 2022-03-11 at 1.37.39 PM.png

XSOAR test/free license - Paloalto ignoring a request from customer

I have tried to request test/free license of XSOAR using web form - (https://start.paloaltonetworks.com/sign-up-for-community-edition.html). Completely ignored. Then I asked for support - they pointed out to local rep. Local rep can do nothing, they claimed that it seems that PA do not issue that license for European countries. We have been lon...

error Couldn't calc cores number [error 'open /proc/stat: too many open files']

Recently had some performance problems reported from my xsoar users.Found a tenant crashing. Upon investigating I found the following error in the logs:App03 host:error Couldn't calc cores number [error 'open /proc/stat: too many open files']error Couldn't calc cores number [error 'open /proc/stat: too many open files'] I set this on APP03 las...

jboyd98_0-1646331590341.png
jboyd98_1-1646331827555.png
jboyd98_2-1646331889270.png
jboyd98 by L2 Linker
  • 2138 Views
  • 1 replies
  • 0 Likes

Default Admin Account sees more tenants where is SSO Administrator does not

Any thoughts on this -I use my SSO account which is an is in the Administrator role.I see 23 tenants. No filter on.My default admin account which is also in the administrator role shows 36. The tenants my SSO account seems to be missing seem are ones that are stopped (older accounts). Incognito window doesn't make a difference, tried hard relo...

jboyd98_1-1646679096093.png
jboyd98_0-1646679032918.png
jboyd98 by L2 Linker
  • 2059 Views
  • 1 replies
  • 0 Likes

Demo Data / Incidents

For purposes of demo'ing / mocking data for testing; how do you handle that.... Curious is there any import function to mock up incident data within XSOAR?

jboyd98 by L2 Linker
  • 2923 Views
  • 2 replies
  • 0 Likes

Resolved! XSOAR Qradar Integration Set Range Limit

Hi,I succeeded XSOAR integration with Qradar. But I keep getting timeout warnings. I solved this problem by entering parameter "--env=REQUEST_TIME OUT=1500". But I caught that the real problem is in the query. To give an example of this, I enter the first integration query as "status='OPEN' and id > 13061". Then XSOAR automatically changes th...

Using IsRFC1918Address check on context in condition task

Hi, I'm trying to use the condition to check if incident.destinationip is an public IP. But when selecting from context incident.destinationip and then IsRFC1918Address you need to fill in something in the right side. I checked the automation script and that should return True or False. But When testing the condition it always returns not matchi...

KevinThys_1-1646323874844.png

Resolved! Docker running as non-root, but hardening script fails?

Relatively new admin to XSOAR; previous admin has left.Just completed upgrade to latest 6.5 version.Could anyone help me understand the following:I have a service account that seems to run xsoar demisto server containers; used ps-ef|grep demisto and return a number of containers; "demisto" is the user below.demisto 32710 3808 0 10:56 ? ...

jboyd98_0-1646331218200.png
jboyd98 by L2 Linker
  • 3462 Views
  • 2 replies
  • 0 Likes

[error 'open /proc/stat: too many open files']

Recently had some performance problems reported from my xsoar users.Found a tenant crashing. Upon investigating I found the following error in the logs:App03 host:error Couldn't calc cores number [error 'open /proc/stat: too many open files']error Couldn't calc cores number [error 'open /proc/stat: too many open files'] I set this on APP03 las...

jboyd98_0-1646333459707.png
jboyd98_1-1646333459832.png
jboyd98_2-1646333459708.png
jboyd98 by L2 Linker
  • 3586 Views
  • 2 replies
  • 0 Likes

Resolved! X out of X accounts returned an error during a multi-account request

Seeing the following every multiple times a minute in my server.log Note i replaced the host with <host> error Some requests to accounts failed for incidents export [error '2 of 18 requests to accounts failed! failing accounts are [acc_Dem01,acc_DemistoTest][HTTPResponse accountURI:https://<host>:443/acc_Dem01/incident/batch/exportTo...

jboyd98 by L2 Linker
  • 4006 Views
  • 1 replies
  • 0 Likes

Resolved! Field Trigger Script / Broswer Caching Issue?

I have a field trigger script on dbot status changing; essentially updating a custom field to nothing if the an incident is re-opened. if field=="dbotStatus" and old=="Closed" and new=="Active" and incidentType=="Azure Sentinel":demisto.executeCommand("setIncident", {'customFields': {"sentinelclosereason": ""}}) This seems to work as the previou...

jboyd98_0-1646165018375.png
jboyd98_1-1646165158523.png
jboyd98_2-1646165399027.png
jboyd98 by L2 Linker
  • 2629 Views
  • 1 replies
  • 0 Likes
  • 1300 Posts
  • 45 Subscriptions
Top Liked Authors