sub-playbook looping behavior
Do sub-playbooks self loop on arrays or just lists?
I can get a sub-playbook to loop “for each input” of a list, but not an array of the same data.
Thx
Do sub-playbooks self loop on arrays or just lists?
I can get a sub-playbook to loop “for each input” of a list, but not an array of the same data.
Thx
Hello everyone, I would like to ask how to get the user.name value from this context data.
I tried using the syntax ${incident.labels.user.name}, but it didn’t work.
Here's the context structure:
{
incident: {
...
labels: {
user.name: ...
Hey,
We are offline users
We updated from 6.12 -> 6.14, Then after the update, the docker images changed, and it's causing a lot of ": Script failed to run: failed to pull docker Image "demisto/python 3:3.11.10.113941"
Now, to fix it I need to chan
...
Is there a script or command line call that can be used to download an entry from the War Room?
I have a script assigned to a button that generates a report and the report download is then entered into a War Room entry when executed/generated.
I
...
I have MS Sentinel subscription that generate alert. I used "Microsoft Sentinel" to fetch the alert, now I want to run some KQL base on the alert information, what integration I should use? is that "Azure Log Analytics"
Tried to remove a value of a field to "empty"
For example "setIncident fieldname=None and !setIncident fieldname=""
But that doesn't work, does anyone how how to remove the value?
Hi Team,
The customer has did the DR to DC failover but DR backup server has " Make this the production server" tab enabled blue.
The client pointing that the option show be disabled. If it is enabled, any person can make backup server as production
...
Hello Team,
I want to populate a custom script output in playbook to Dashboards and Reports.
This playbook is triggered on incident and took same data from incident modify it and also uses some third-party custom app data to enrich.
I want to p
...
Hello,
I would like to enable email notifications for every new incident.
I've configured an O365 EWS instance successfully, and set server.notification.using.send-mail to use its instance name.
For now, I just want all notifications to be sent t
...
I see the classify, map and playbook logic in XSOAR and I see that a playbook can ask/pull/poll for info *from* and external tool, which might be done through an integration. But is there a way for an external tool to aynchronously *send/push* an *a
...
I'm trying to perform whois queries on an array that contains the list of IPs.
My understanding is that I can pass the array to the Inputs of the "ip (whois)" script.
However, since there are over 1000 IPs, submitting them all at once results in an e
...
When I use the XSOAR 8 SearchIncidentsv2 script with reason argument it return no results for example reason:False Positive returns nothing. Why is that? Is there some specific formatting to use?
Hi team!
First of all, thank you very much in advance for your help.
I want to add an SLA to an incident in XSOAR so that if the SLA is breached, the incident is automatically closed. In theory, this is straightforward to implement by setting a t
...
Hello all,
I have an XSOAR 8.+ tenant and need to store my incidents from up to two years ago. I understand that by default XSOAR retention policy retains incidents based on license etc. Is there a way to export the data that is half a year old to a
...| Subject | Likes |
|---|---|
| 1 Like | |
| 1 Like |

