Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Incident classification considering multiple fields

How can I classify an incident while taking multiple fields into consideration?Let's say I have a list of numbers. Whenever an incident is registered I would like to check whether the value of Field A is in that list, if Yes, then classify by Field A, if Not then classify by other Field B.

OZamir by L1 Bithead
  • 2799 Views
  • 1 replies
  • 0 Likes

Avoid empty returns

Hello All In my Playbook I run into an issue with empty returns.My Playbook requests Cherwell with several hosts in an array: ["server-A","server-B"]In Cherwell, "server-B" does not exist, so I do see that in the "Result Tab" of the Task, but the Output is only from the one Host (server-A), which is in the Cherwell DB.The reason is, that I have ...

Resolved! Wildfire Reports missing URL

Hello all I did some PDF-Requests to Wildfire and getting Info back as xml. One of those reports are marked as "Malicious" but I do not see, what/why it is Malicious.So I've investigated and did a curl extract of the sha265 Wildfire Request. And look! There are infos about URLs in the curl-api request (output as xml): <extracted_urls> &...

Resolved! Adding endpoint list to an AD group

Hi, I am currently building a new PlayBook and in one part of that PlayBook, I am trying to add computers, in an XSoar List, to a specific AD group. - I Created a List that contains 2 endpoints separated with a comma ","- My Playbook is using the Active Directory Query v2: ad-add-to-group- Field "computer-name" is filled with the query referenc...

War room: View full content in a new tab. Output in column instead of row

Hello If we press in the war room output to " View full content in a new tab" then the output is a table - and everything in one row.Is it possible to get the output in columns? Even csv is all in one row... so, instead first row with description, put that in one column. then the 2nd row put that in secound column.it is a bit nicer to scroll aro...

Cortex XQL searches in XSOAR - how to?

Hi, I am trying to integrate more and more XSOAR into my environment.I would like to be able to do XQL searches on xdr dataset, but I can't find a way to do that.I have Cortex Data Lake integration, but is seems to cover only logs from firewalls. Thx for help.Best,Przemek

Cortex XDR Halt Playbooks?

So we're utilizing XDR Prevent (not Pro) here. Appears to be all the preparation on PAN's site is carefully equipped towards the Proform, and Github hasn't been exceptionally productive. I'm contemplating whether anybody has any playbooks or work processes or (crosses fingers) contents they're utilizing to cooperate with XDR here?

Timeframe for Script in a widget

How can I get the Timeframe inside a Dashboard into an python script so that I can use it to query splunk for the same timeframe I haven't been able to find anything related to this in the documentation. Thanks, Juan

JuDiaz by L0 Member
  • 3421 Views
  • 3 replies
  • 0 Likes

SplunkPy | Integration test throws error

While testing SplunkPy integration, I am getting the following error. Error from SplunkPy is : Script failed to run:Error: Error [[Traceback (most recent call last): File "<string>", line 1, in <module> ImportError: No module named splunklib.binding]] - Stderr [] (2601) Stderr: Traceback (most recent call last): File "/va...

Resolved! Error: DB Version '##' and Insert version '##' do not match for id: ##### on bucket [] [incidents] (15)

I have a trigger script automation that updates the linked incidents of an incident. The update works, but then it produces the following error and refuses to update the field that triggered the automation. The script works fine if I run it from the command line. It's only when a triggered script runs that there's a problem. Here's a sample ...

DZerkle_0-1614912375236.png
DZerkle by L2 Linker
  • 18141 Views
  • 19 replies
  • 0 Likes
  • 1300 Posts
  • 45 Subscriptions
Top Liked Authors