Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! Dynamic interactive GUI elements in incident layouts?

I couldn't find anything in the documentation about this. However, I'm brand new to XSOAR development, so maybe I'm missing it. So, before I go digging more, can anyone let me know if this capability exists or not? I want dynamic interactive elements on an incident layout. The user should be able to pick one of multiple items that wouldn't be...

DZerkle by L2 Linker
  • 14576 Views
  • 14 replies
  • 0 Likes

Issue Working with Files

Hello everyone, I am having some trouble working with files in an incident.I have integrated an API that need a path to upload a file.This API checks the file extension in the path and as I have seen, file paths in XSOAR incidents are something like 80_916@80. I would need to have access to an absolute path or a way to get a path with the file n...

Cortex XDR Prevent playbooks?

So we're using XDR Prevent (not Pro) here. Seems all the training on PAN's site is strictly geared towards the Pro version, and github hasn't been very fruitful yet.I'm wondering if anyone has any playbooks or workflows or (crosses fingers) scripts they're using to interact with XDR here?

Panorama Query Log Fails

Hello all I run into a failure on Playbook Panorama Query Logs.The failure is:"Set vsys for firewall or Device group for Panorama" This happen on the GeneralPolling Playbook and there at the task RunPollingCommand. I've defined Device Group and asking Panorama - but the failure still occours.Does anyone have any Idea, what this could be? thanksr...

MFA for xSOAR portal

Hello, I am running the Community Edition and have not found anything concerning MFA for xSOAR users. What would be the preferred way to enable MFA for users like Analysts and Administrators?

antjar by L0 Member
  • 9261 Views
  • 9 replies
  • 0 Likes

SAML 2.0 -> message signature failed

Hello I do have problems to get Cortex XSOAR talking to our ADFS Server (Windows AD 2012)Which certificate is here used? It should be, as fas as I understood, somewhere on Cortex XSOAR, but couldn't find anything... Spoiler (Highlight to read)Response from ADSF Server:The verification of the SAML message signature failed.Message issuer: http://...

XSOAR HTTPS certificate issues

Hi All, I have an issue where I have replaced the self-signed auto generated certificate in XSOAR, the problem is that when I reboot the server the web service doesn't seem to come up, there is no service listening on port 443.Any help would be greatly appreciated.

Resolved! jira-issue-query (jira-v2) dosen't show all info in output

Hallo Community My Jira request dosn't show all Info in the output but there is everything in Results.Example: In the output I do see:Spoiler (Highlight to read)Ticket[{"Assignee": "aaa","Creator": "bbb","Id": "12345","Key": "ccc-123","Status": "Open","Summary": "ddd"}Ticket[{"Assignee": "aaa","Creator": "bbb","Id": "12345","Key": "ccc-123","Sta...

Get "Details" from an Jira Ticket

Hello all How do I get details from an Jira Ticket in Cortex XSOAR?If I do some "get" and "query" I do get only these output, which I may use in further Tasks:Spoiler (Highlight to read)Ticket[{"Assignee": "aaa","Creator": "bbb","Id": "1234","Key": "ccc-123","Status": "Open","Summary": "ddd"}Ticket[{"Assignee": "aaa","Creator": "bbb","Id": "1234...

Resolved! Cortex XSOAR: Add a Job: First Friday of the Month

Hello allWe are using Cortex XSOAR Version Version 6.0.0; Build 79522 and having problems to generate a valid schedule in the Jobs.I would like to add a Job, which runs on first Firday of the Month.The Human View part has no Monthly recurring tasks.The Cron View does not unterstand these settings: 0 21 ? * 6#1 -> the background turns red on "...

XSOAR cant connect to marketplace

Hiinstalled a new instance of XSOAR community edition - but cant seem to connect to the marketplace - when i try curl to storage.googleapis.comcurl: (56) Recv failure: Connection reset by peercurl to: https://xsoar.pan.dev works the firewall is not dropping traffic to those destination IP's either - one thing i did notice on my instance is that ...

spandor by L0 Member
  • 3579 Views
  • 2 replies
  • 0 Likes

Integration classifier by workflow

Hi,I have been thinking about this a few times by now. I have a mail listener that fetches incoming mails as incidents. To classify them I would like to send them through a playbook, as a classification key doesn't provide enough context to choose the right incident type. Did anyone else try this before? Looking for some advice here 🙂

Docker issues with xSOAR

Hello, A beginner here. It seems that after initial installation when trying to install new integrations and addons from Marketplace, I keep getting warnings about missing Docker images. If I list all the images with /docker_images I see the ones that the warning claims are missing, but the versions are older than in the warning message. I have ...

antjar by L0 Member
  • 7180 Views
  • 3 replies
  • 0 Likes
  • 1298 Posts
  • 45 Subscriptions