Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! Polling job for search results, not just search completion

I'd like to take the generic polling concept and make it a little more specific, but I'm coming up short. I'm doing a QRadar search (although I suspect Splunk or anything else would be very similar.) The QRadarFullSearch playbook will poll and wait for the search to finish, and that has worked great so far for what it is. But the search can f...

SAML configuration error with Azure AD

Hi,I am getting following error while trying to login to XSOAR through SSO. I have setup the SAML app on XSOAR with all the attributes provided by AD team. AADSTS50011: The reply URL specified in the request does not match the reply URLs configured for the application: 'https://sts.windows.net/f35a6974-607f-47d4-82d7-ff31d7dc53a5/'. Can someone ...

Send Email to Spesific Mailbox with Incident Details and Analyst Comments

Hi All, We wanna send an email notification, and that email content will be incident details and results of the analyst's analysis.I checked marketplace and GitHub demisto repo but I didn't find development as I mentioned. Our html email body schema is ready for use but I guess we have to develop our own script with the api and email applicatio...

Stopped on waiting

Trying to learn how to use this thing. I've got a very simple playbook set up that uses the Slack integration to send a simple yes/no prompt to a user. Within the Playground, I'm able to successfully send simple messages via slack, so the connection appears to be good, but every time I run the playbook I just get 'Incident playbook task "Ask u...

Resolved! create table show incident close reason group by incident type

I am new to XSOAR and I am trying to create table show incident close reason group by incident type looks like below Ture positiveFalse positiveDuplicateincident type 11211incident type 22433incident type 341622I cant find any widget can do this so I try to look into the automation script but I have no idea how it going to work. If anyone can g...

Secrets

How is everyone else doing secrets?It seems odd to me that everything that might use an API key needs to be an integration instead of an automation.You can't seem to easily hide plain-text apikeys from an automation at all. For example:I have a Contact List for emergencies:I have an API key, that I use to query the owner of certain cloud instanc...

MrDuck by L1 Bithead
  • 4710 Views
  • 3 replies
  • 0 Likes

Cherwell Fetch Incident fails

Hello We use Demisto Version 6.2.0, Build 1271082 If I configure a Cherwell Instance to fetch incident but It fails with the following Error:Spoiler (Highlight to read)Error OccurredFailed to get samples from instanceError detailsScript failed to run: Error: [Traceback (most recent call last): File "<string>", line 1017, in <mod...

Get Qualys credentials in python script

Hi -The built in Qualys commands from an instance don't quite do what I want to do so I have a python script that uses the api to grab the last report from a map scan, filter it for systems that have specific ports open, and then upload the ip addresses of those systems to an asset group. Runs fine from my pc but I need it to kick off on its own...

sforslev by L0 Member
  • 4357 Views
  • 3 replies
  • 0 Likes

Resolved! Fetched several incidents without mapping

Hello,I recently fetched several incidents using an integration without any classification/mapping configured. I have since configured it correctly, is there any way to re-fetch or re-ingest these incidents so they get mapped and processed correctly?

jtorvald by L1 Bithead
  • 3718 Views
  • 2 replies
  • 0 Likes

Cortex XSOAR Context Issue

Hi Everyone, I have Cortex XSOAR with SplunkPY running and fetching incidents. I am using Splunk classifier and Splunk incoming mapper by default. Drill down is being enriched successfully and i can see it parsed at both classifier & mapper stages - see below screenshotdrilldown parsed in classifier&mapperHowever, context is not splittin...

2021-09-30_181850.png
2021-09-30_182723.png
Rawabdeh by L1 Bithead
  • 9008 Views
  • 9 replies
  • 0 Likes

demisto-py - Specify Playbook

Hello All, I have a python script using demisto-py that creates tickets based on an input Word document. However, specifying the playbook isn't working. When I call demisto_client.demisto_api.CreateIncidentRequest() with the "playbookid" field is populated with the Playbook name, as found in Playbooks page. I thought this field invoked the p...

twjolson by L0 Member
  • 3478 Views
  • 2 replies
  • 0 Likes
  • 1307 Posts
  • 46 Subscriptions
Top Solution Authors
Top Liked Posts
Top Liked Authors