Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! 8.9 On-Prem Update Fails to Update

I have a very-small XSOAR setup of one dev and one prod server on-prem 8.9.0-8.9.0.140-b55c42e1. There are currently no workloads on these servers as they are replacing some 6.x servers that are in production currently. I received a notification afte

...

sackett by L1 Bithead
  • 380 Views
  • 1 replies
  • 0 Likes

Mass Closure of XSIAM Incidents

Hello team!
I would like to know if there is an option for mass closure of incidents in XSIAM.
I have the following scenario of 2000 open incidents and I would like to perform mass closure of these open cases. Is there any way to do this?

Resolved! Access a list from an integration

To access a list from an automation I use something like:

json = json.loads(demisto.executeCommand("getList", {"listName": "blabla"})

However, from an integration I cannot use the executeCommand method. Is there any way to access a list from an inte

...

rdevega by L1 Bithead
  • 3774 Views
  • 6 replies
  • 0 Likes

Use of Microsoft Graph Security

Hi,

 

Has anyone used the msg-list-security-incident command from the Microsoft Graph Security integration with an odata query. It is specified in the documentation as an optional parameter, but when I try to use it I get an error stating odata is no

...

Use of a Certificate in a Script

Hi,

 

I am wanting to connect to the MicrosoftExchangeOnline (EXO) powershell module in a scrip. I have the module working but to connect to EXO from a script you must use a managed identity with a certificate. It does not support a secret key. I see

...

SplunkPy Integration

Hi everyone,
I get data from splunk with the "search index=notable" query using Splunkpy. I assign the incoming data to the type named Splunk Generic Notable by default. Here, when an incident occurs, there are fields such as event_code, process_name

...

  • 1232 Posts
  • 43 Subscriptions
Top Solution Authors
Top Liked Authors