- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
12-15-2022 05:32 AM
- Second, the command !qradar-reset-last-run is not working (reading the documentation, the command don't use any parameters), getting this error: 'Context data is missing keys: mirrored_offenses_queried or mirrored_offenses_finished' (screenshot attached).
12-15-2022 10:00 PM
If you try running the mirror manually with the debug commands listed here https://xsoar.pan.dev/docs/integrations/mirroring_integration#debugging like get-modified-remote-data do you get any useful output?
Do you have offenses newer than your configured First fetch timestamp parameter?
12-16-2022 04:11 AM
Hi @chrking , thanks for your answer.
I ran the get-modified-remote-data, but I obtained an error for the QRadar integration (attached screenshot):
skip update. error: Failed to execute get-modified-remote-data command.
Error:
'lastUpdate'
What I really don't understand is that even the get-modified-remote-data debug command for Crowdstrike Integration (which is working, is mirroring the incidents of Crowdstrike as Incidents in Cortex XSOAR) is giving me an error (screenshot attached).
Maybe this is related to the command qradar-reset-last-run failing too? The strange thing is that the integration is working, what is not working is the mirroring.
My first fetch timestamp parameter is 30 days, and I have new Offenses from yesterday and from today, and nothing was mirrored.
Thanks for your help.
12-16-2022 05:48 AM
Now (I don't know why), but the command qradar-reset-last-run is working (screenshot attached), but still the Offenses of QRadar are not being mirroring with Incidents in Cortex XSOAR. After the execution of the command, I generated a new Offense, and nothing happen.
Thanks for your help.
12-16-2022 06:15 AM
And now is working the Mirroring, and I really don't know what changed (screenshot attached).
The only thing that I changed on the QRadar server side, is that I changed the timezone of the server, from UTC to GMT-3 (Argentina time zone), the same time zone that Cortex SOAR server has. Maybe that was the problem?
Any opinions?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!