Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! Field Trigger Script / Broswer Caching Issue?

I have a field trigger script on dbot status changing; essentially updating a custom field to nothing if the an incident is re-opened. if field=="dbotStatus" and old=="Closed" and new=="Active" and incidentType=="Azure Sentinel":demisto.executeCommand("setIncident", {'customFields': {"sentinelclosereason": ""}}) This seems to work as the previou...

jboyd98_0-1646165018375.png
jboyd98_1-1646165158523.png
jboyd98_2-1646165399027.png
jboyd98 by L2 Linker
  • 2658 Views
  • 1 replies
  • 0 Likes

Error trying to move an account to a different host

We have a MT XSOAR deployment, and I need to move a created account that is on the main host to a different one, when I try to move the account I get the error "Account acc_XXXX could not be moved to HOST because address phoenix.scilabs.mx: missing port in address" Why is this happening?

Captura de pantalla 2022-02-23 123157.jpg

Resolved! Creating Multiple Widgets on Layout to Show Different Images

Hello,I have multiple screenshots from various tasks in the playbook such as Rasterize among others from a Sandbox Integration. I would like to make individual widgets on the Layout that can display these Image Files Separately. 1. Can the images be displayed in different Widgets such as through !setincident... from a playbook level ?2. Can the...

trying to return raw output vs formatted

!py script=`return_results(demisto.executeCommand("azure-sentinel-list-incident-entities", {"incident_id":"xxxxxxx-xxxxxx-xxxxx"}))`The above works and turns in human readable format; however i want to return the raw json. This works:!azure-sentinel-list-incident-entities incident_id=xxxx-xxxx-xxxx raw-response=true However this does not: !py sc...

JoshBoyd by L2 Linker
  • 3775 Views
  • 3 replies
  • 0 Likes

Resolved! Xsoar Twitter Entegration

Hi Everyone, We try to use twitter api on XSOAR.We created instince and try to test connection and get error: AttributeError: 'Client' object has no attribute 'say_hello' Anyone saw this error? Thanks for helps.

sentinel integration, azure-sentinel-update-incident, not able to set to active

I can close an azure incident in xsoar war-room with the following:!azure-sentinel-update-incident incident_id="xx-xxxxx-xxxxx" status="Closed" classification="Undetermined" However when i try to re-open the incident in azure from war-room with the following i get the subsequent error:!azure-sentinel-update-incident incident_id="xx-xxxxx-xxxxx" ...

jboyd98 by L2 Linker
  • 3184 Views
  • 2 replies
  • 0 Likes

Resolved! Is it possible to use nested variables in XSOAR?

Hi all,A customer of ours is trying a curious thing and I am not sure if it is possible in general, so I guessed the best way would be to ask right away. Our customer created a XSOAR list, that contains a html string with context data variables in it, like ${testinput}.In a playbook with test incidents he has set the key (e.g. ${testinput} = "te...

araka by L1 Bithead
  • 4285 Views
  • 2 replies
  • 0 Likes

Resolved! XSOAR Qradar Ingestion

I am attempting to ingest Qradar into the XSOAR using the Integration. I need to pull custom fields from the SIEM and what I need to understand is as follows;Is it preferable to pull these fields within an AQL Search at the playbook stage ?Or is it preferable to pull these fields from Qradar Integration setting ? The use case is as follows;I am...

Search in XSOAR for Timers (active incidents)

Hi allI would like to search in Cortex XSOAR for running timers that exceed a certain time. I tried it but it didn't worked out.It should work like this that I can search for an timer (in this case detectionsla the total duration) and afterwards it should show all INC that are still running (active) where the decetion sla is over 16 hoursWhile r...

Bildschirmfoto 2022-02-19 um 12.27.02.png
Bildschirmfoto 2022-02-19 um 12.32.04.png
lslschr1 by L0 Member
  • 2735 Views
  • 1 replies
  • 0 Likes
  • 1302 Posts
  • 45 Subscriptions