Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

ElasticSearch integration es-eql

Can someone, anyone, post a properly formatted (working) !es-eql-query command run in XSOAR.  I am apparently too dumb to get it working.  For context, here's the ES|QL query I'm trying to make work.

FROM logs-* | WHERE winlog.event_data.LogonProcessN

...

Increasing docker image pull timeout

Hey everyone,

I am looking for a way to increase the docker image pull timeout from its 5 minutes default.

The error occurs due to a combination of very slow network connection (a traffic shaping option which I cannot change) and big images (e.g. dem

...

JanDrees by L0 Member
  • 860 Views
  • 1 replies
  • 0 Likes

Urgent !! Cortex XSOAR User Licence Support

Would you please assists on picking a user for cortex xsoar, we have been bought a 1 year license for cortex xsoar starter (1 in quantity with support 2 users) and full user (4 in quantity) which is total of 6 users. However, currently we are plannin

...

Yonas_A by L0 Member
  • 565 Views
  • 1 replies
  • 0 Likes

Reminder Follow-Up Mail Playbook

I need to create a simple JOB in Demisto that does the following:


Sends an email to the user - with the text "Reminder to perform action XXX"
Give the user half an hour to reply by email (the user can reply with any text they want),
Wait half an hour
If

...

NivNet by L1 Bithead
  • 888 Views
  • 3 replies
  • 0 Likes

Help with retrieving list of XSOAR items

Hi all, 

I am looking to build an inventory list of everything we have within XSOAR, such as:
All playbooks, dashboards, integrations regardless of whether or not we use them.

Extra points if we also know the author of each item, and / or the last per

...

Demisto-sdk upload doesn't allow override

Hi Community!

 

I have a question since i can't find answer anywhere.

I wonder how the demisto-sdk community update the content pack when there is a code change, in my experience. i need to upload the same pack sometimes because I changed one script

...

warm20 by L0 Member
  • 596 Views
  • 0 replies
  • 0 Likes

Query on V8

Hi Team,

A standard customer has some query on (cluster V8 on-prem) structure. Please find it below:

 

1. If we don't setup VIP in cluster configuration, we could access the Web GUI by access to any IP of the nodes ? If the node is down, is it need t

...

  • 1255 Posts
  • 43 Subscriptions
Top Solution Authors
Top Liked Authors