Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

PCSAE exam question

Hi.I thought answers  are A,B,D but some sources say it is BCD or ECD.I don't know which one is true.

 

In which three locations can an engineer try to find information, when troubleshooting a failed integration instance error produced by the test bu

...

PCSAE exam question

Which ones are true?I thought it is BD but some sources say it is CD

 

Which two statements describe how timers are configured to start and stop automatically in a playbook? (Choose two.)

  • A. Use a field of Number to count the number of seconds elapse
...

Update Classifier from API

Hi,
we have an issue regarding classifiers, and we would like to ask if it is possible to interact with them using an automation or from the API.

Specifically, I am interested in understanding:
- Whether XSOAR provides built-in capabilities or tools fo

...

MViafora by L0 Member
  • 236 Views
  • 3 replies
  • 0 Likes

Prod to dev

I want to change my production environment XSOAR to DEV environment, and after that i will create new production environment.

I want to know how to move the production to dev including changing the IP  

Cortex XSOAR report blank page

Hey, we conducted a final test of the phishing playbook, and everything appeared to be functioning properly. Once the playbook completes, it is supposed to generate a report as usual. However, the report is being generated as a blank page, which wasn

...

SQL results into layout

Hi ,

 

I’m running a playbook that generates multiple SQL results. What are the best practices for displaying these effectively in the incident layout? Should I use Markdown, custom sections, or widgets? Any tips for handling this?

 

Thanks!

XSOAR Feature Request

Hello all xsoar enthusiasts,

 

There is a FR that helps us to make xsoar a better place for MS Defender integration. Please upvote this FR here: Add Microsoft Sentinel | Cortex XSOAR Customer Feature Request

FR Description:
Palo Alto offers a range of

...

ServiceNow Developer looking for ideas

Hello all,

 

     I am a ServiceNow developer that is assisting a user that is using the XSOAR integration.  The user is using the XSOAR application to run queries on my SN instance, but is not getting any results.  I have checked his API account and

...

Child Incident Evidence In Parent

Hello!

I need to mark some child incident entries as notes and evidence in the parent incident.

I have found ways in which you can pass the entries to the parent and then mark them as note/evidence in the parent. However, I would like to have an auto

...

nickvus0 by L0 Member
  • 255 Views
  • 1 replies
  • 0 Likes
  • 1127 Posts
  • 36 Subscriptions
Top Solution Authors
Top Liked Authors