How do I get network traffic data in XSOAR from the SIEM ingestions?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

How do I get network traffic data in XSOAR from the SIEM ingestions?

L1 Bithead

We have to Generate a report that presents the network traffic data in XSOAR obtained from our SIEM. We would appreciate the guidance on the calculation process and the essential aspects we should include in the report.

 

Thank you
Cortex XSOAR

3 REPLIES 3

L4 Transporter

Very opened ended question, without much details.

 

Depending on what the data us (sessions, opened/closed, blocked, bytes, etc etc) if it's being returned to the context and you then need to operate on it within the context of an Incident, you may need a widget that runs as an automation script to calculate whatever it is you're looking for:

 

https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.11/Cortex-XSOAR-Administrator-Guide/Create...

 

If you need it as a report across a bunch of different Incidents, then the data would need to be in an Incident field. 

 

You'll want to start by referencing the sections on Widgets, Dashboards, and Reports on the Admin Guide:

https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.11/Cortex-XSOAR-Administrator-Guide/Overvi...

I require the data in bytes, specifically the amount of traffic received from the SIEM into XSOAR.

L2 Linker

@SGupta While XSOAR could be used to create the report, I recommend using something like Netflow to gather this data.

  • 1077 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!