- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-02-2024 05:14 AM
Hi Team,
I have integrated the Instance Cortex XDR - IOC content pack: Cortex XDR by Palo Alto Networks
kindly help me, below which command to push bulk update IOC indicators to Cortex XDR if am wrong kindly guide me.
Instance = Cortex XDR - IOC
Cortex XDR-IOC | |
xdr-iocs-create-sync-file | Creates the sync file for the manual process. Run this command when instructed by the XDR support team. |
xdr-iocs-disable | Disables IOCs in the XDR server. |
xdr-iocs-enable | Enables IOCs in the XDR server. |
xdr-iocs-push | Push modified IOCs to Cortex XDR. |
xdr-iocs-set-sync-time (Deprecated) | Set sync time manually. (Do not use this command unless you understand the consequences.) |
xdr-iocs-sync | Sync your IOC with Cortex XDR and delete the old. |
xdr-iocs-to-keep-file | Create a file with all the IOCs that are going to sync to Cortex XDR. |
07-02-2024 06:05 AM - edited 07-04-2024 04:13 AM
I run the below command for IOC push to XDR but show an error expiration time invalid and date cannot be in the past.
Kindly help me to resolve this error and need to push ioc's to XDR, error screenshot attached for your reference please help me.
Command:
The following IOCs were not pushed due to following errors: 1.179.247.182: Expiration time 1716529790609 is invalid; expiration date cannot be in the past. 45.141.148.220: Expiration time 1716529790609 is invalid; expiration date cannot be in the past.
07-04-2024 02:21 AM - edited 07-04-2024 02:31 AM
Hi Team,
For bulk of IOC Lists i.e 100 no's IP's, Hashes, Domain names. how to push from XSOAR to XDR as a file or any form? does anyone worked this usecase scenario, kindly share!
For Single or Limit of 10 no's (IP , hashes, Domains Name ) the below command was working.
!xdr-iocs-enable indicator="172.15.1.50"
!xdr-iocs-push indicator="172.15.1.50"
!xdr-iocs-push indicator="fea456b3a78e87c2c99c5997b7255f553495a06a29bd7d4096cf72bfcbe1ed9b"
!xdr-iocs-enable indicator="vmtoolsd.exe"
Regards,
Chiranjeevi
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!