Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Cortex XSOAR Context Issue

Hi Everyone, I have Cortex XSOAR with SplunkPY running and fetching incidents. I am using Splunk classifier and Splunk incoming mapper by default. Drill down is being enriched successfully and i can see it parsed at both classifier & mapper stages - see below screenshotdrilldown parsed in classifier&mapperHowever, context is not splittin...

2021-09-30_181850.png
2021-09-30_182723.png
Rawabdeh by • L1 Bithead
  • 9169 Views
  • 9 replies
  • 0 Likes

demisto-py - Specify Playbook

Hello All, I have a python script using demisto-py that creates tickets based on an input Word document. However, specifying the playbook isn't working. When I call demisto_client.demisto_api.CreateIncidentRequest() with the "playbookid" field is populated with the Playbook name, as found in Playbooks page. I thought this field invoked the p...

twjolson by • L0 Member
  • 3540 Views
  • 2 replies
  • 0 Likes

Read-Only role assignment issue

I have deployed a number of other roles using SAML successfully. Now when it comes to assigning the Read-only role this has become a challenge. Unlike the other previously configured roles that also included not only the SAML mapping but also the Shift assignments, which work. The Read-Only role does not, this issue is specific to the role and i...

jpadro by • L0 Member
  • 2466 Views
  • 1 replies
  • 0 Likes

Integration "Palo Alto Networks PAN-OS" Question

HelloI'll try to get a API request from our Panoramas.The curl request looks like;curl -X GET "https://<panorama>/api/?key=<api-key>&type=op&<show><devices><all></all></devices></show>"So, I tried with the Integration "Palo Alto Networks PAN-OS"There is a command "panorama", where I mitgh e...

Does XSOAR API Batch Close Incidents Endpoint Work?

I am attempting to close a single incident via the XSOAR API and the Batch Close Incidents endpoint (POST /incident/batchClose). The information about my request and the response are posted below. The status of the incident was new before I sent the close request and does not appear to have changed after sending the request even though the respo...

Snader by • L1 Bithead
  • 3154 Views
  • 1 replies
  • 0 Likes

Send Email with Integration Got any error

Hello Everyone, If any integration(RSA Netwitness or Syslog) in XSOAR is failed and got some error then can I send mail to any team member as integration got some error. I have already configured System diagnostic but it cannot work.I need any alternative way or solution for this.

Priyash7 by • L0 Member
  • 3296 Views
  • 1 replies
  • 0 Likes

Wildfire Report "Results" into "Outputs"

Hello When I request a Wildfire request then I do not get a lot of Information in the "Output" to work with other tasks.To get more infos, I do in the Demisto CLI this: !wildfire-report format=xml hash=<sha256-Hash> verbose=true raw-response="true" extend-context=contextKey=JsonOutputPath But then all infos are in the "Resuls"-"Tab" instea...

update data to rawjson key fails

The integration created does pull the tickets .However i couldn't see rawjson field getting updated though using the below line.I couldn't do field mapping as i can't see the data on choosing instance under classification and mapping rawJSON : JSON.stringify(case.records[i])

rr449 by • L0 Member
  • 2294 Views
  • 1 replies
  • 0 Likes

XSoar API Create Incident Mapping

Looking for some help on create an API integration for creating incidents and mapping those fields to normalized fields. I can create an incident just fine, I can assign the incident type, the issue I'm running into is the field normalization. IE lets take the following field called Souce IP in XSoar. The script that I'm using calls it OriginIp....

Resolved! ServerLogs integration does not work.

I have the integration enabled and configured using the requirements stated in the Marketplace, but when I try to load the dashboard it says I don't have the SSH integration enabled. But I do, and I have a local user and have tested it manually, so I don't think this is credential related. It just looks like the integration is not able to access...

Update an incident via API XSOAR

Hi, I need help about How get via API an incident update. I don't see this option (sorry), I can set a new incident but I don't update an incident. This way must be API, I use this route "/incident". Can you help me, plase? Regards

sanaya by • L0 Member
  • 6986 Views
  • 4 replies
  • 1 Likes

Resolved! Update an incident via API in CORTEX XSOAR

Hi, I need help about How get via API update an incident. I don't see this option (sorry), I can set a new incident but I don't update an incident. This way must be API, I use this route "/incident". URL API: https://cortexip/incident Can you help me, plase? Regards Cortex XSOAR

sanaya by • L0 Member
  • 4567 Views
  • 2 replies
  • 0 Likes
  • 1310 Posts
  • 46 Subscriptions
Top Solution Authors