Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PrismaCloudV2XSIAM #31187

Merged
merged 106 commits into from Jan 2, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
106 commits
Select commit Hold shift + click to select a range
a93d7aa
AWS CloudTrail Misconfiguration
ArikDay Nov 29, 2023
814430e
ReleaseNotes
ArikDay Nov 29, 2023
c3de708
Merge branch 'master' into PrismaCloudV2XSIAM
ArikDay Nov 29, 2023
566277e
AWS IAM Policy Misconfiguration
ArikDay Nov 29, 2023
cd2e863
ReleaseNotes
ArikDay Nov 29, 2023
1c17d32
ReleaseNotes
ArikDay Nov 29, 2023
b4164b6
Merge branch 'PrismaCloudV2XSIAM' of github.com:demisto/content into …
ArikDay Nov 29, 2023
b5f127f
changing trigger ID
ArikDay Nov 29, 2023
60ee633
Azure AKS Misconfiguration
ArikDay Nov 29, 2023
1aff960
ReleaseNotes
ArikDay Nov 29, 2023
149a01b
Small fix
ArikDay Nov 29, 2023
b00787a
AWS EC2 Instance Misconfiguration
ArikDay Dec 3, 2023
52d24dc
fix
ArikDay Dec 3, 2023
e10ad7e
rn fix
ArikDay Dec 3, 2023
919e88e
small fix
ArikDay Dec 3, 2023
d7069c0
Azure Network Misconfiguration
ArikDay Dec 4, 2023
c14b241
rn and trigger
ArikDay Dec 4, 2023
c435659
Azure SQL Misconfiguration
ArikDay Dec 4, 2023
0fab07f
Azure SQL Misconfiguration
ArikDay Dec 4, 2023
da282ba
Azure Storage Misconfiguration
ArikDay Dec 4, 2023
9ae5b1e
GCP Compute Engine Misconfiguration
ArikDay Dec 4, 2023
81e4218
GCP Kubernetes Engine Misconfiguration
ArikDay Dec 4, 2023
ce761e1
Prisma Cloud - VM Alert Prioritization
ArikDay Dec 4, 2023
ac002a2
Merge branch 'master' into PrismaCloudV2XSIAM
ArikDay Dec 4, 2023
83d307e
fix
ArikDay Dec 4, 2023
8845017
Merge branch 'PrismaCloudV2XSIAM' of github.com:demisto/content into …
ArikDay Dec 4, 2023
8acad14
fix
ArikDay Dec 4, 2023
193a1de
Merge branch 'master' into PrismaCloudV2XSIAM
ArikDay Dec 10, 2023
f019dc2
Review Fixes
ArikDay Dec 11, 2023
9a6afd9
Merge branch 'PrismaCloudV2XSIAM' of github.com:demisto/content into …
ArikDay Dec 11, 2023
a0aa81d
classifier update
ArikDay Dec 18, 2023
12814c5
ReleaseNotes
ArikDay Dec 18, 2023
dcd7f75
add ons
ArikDay Dec 18, 2023
04b025d
addons
ArikDay Dec 18, 2023
24f573c
ReleaseNotes
ArikDay Dec 18, 2023
4a8e65b
new layoutscontainer
ArikDay Dec 18, 2023
e16347d
rn
ArikDay Dec 18, 2023
27862af
Merge branch 'master' into PrismaCloudV2XSIAM
ArikDay Dec 18, 2023
2bc70e7
fix
ArikDay Dec 18, 2023
11ca4c7
Merge branch 'PrismaCloudV2XSIAM' of github.com:demisto/content into …
ArikDay Dec 18, 2023
f4683da
fix validation error
ArikDay Dec 18, 2023
aeb5182
rn fix
ArikDay Dec 18, 2023
3656079
fix
ArikDay Dec 20, 2023
a27b409
fix rn
ArikDay Dec 20, 2023
33c00b8
Merge branch 'master' into PrismaCloudV2XSIAM
ArikDay Dec 21, 2023
d8f7742
Merge branch 'master' into PrismaCloudV2XSIAM
ArikDay Dec 24, 2023
cf31159
AWS CloudTrail Misconfiguration
ArikDay Nov 29, 2023
ef508b6
ReleaseNotes
ArikDay Nov 29, 2023
91ace19
AWS IAM Policy Misconfiguration
ArikDay Nov 29, 2023
f53269c
ReleaseNotes
ArikDay Nov 29, 2023
b5f8558
ReleaseNotes
ArikDay Nov 29, 2023
08c5694
changing trigger ID
ArikDay Nov 29, 2023
036e88e
Azure AKS Misconfiguration
ArikDay Nov 29, 2023
3eb1cda
ReleaseNotes
ArikDay Nov 29, 2023
b061c6e
Small fix
ArikDay Nov 29, 2023
ed154c6
AWS EC2 Instance Misconfiguration
ArikDay Dec 3, 2023
1b4c8cb
fix
ArikDay Dec 3, 2023
589adea
rn fix
ArikDay Dec 3, 2023
054ab3f
small fix
ArikDay Dec 3, 2023
c8f7d19
Azure Network Misconfiguration
ArikDay Dec 4, 2023
3a81fc3
rn and trigger
ArikDay Dec 4, 2023
1b40aad
Azure SQL Misconfiguration
ArikDay Dec 4, 2023
57405ac
Azure SQL Misconfiguration
ArikDay Dec 4, 2023
9afc2ff
Azure Storage Misconfiguration
ArikDay Dec 4, 2023
5579207
GCP Compute Engine Misconfiguration
ArikDay Dec 4, 2023
c645787
GCP Kubernetes Engine Misconfiguration
ArikDay Dec 4, 2023
5f310b7
Prisma Cloud - VM Alert Prioritization
ArikDay Dec 4, 2023
2dbdbf5
fix
ArikDay Dec 4, 2023
847c350
fix
ArikDay Dec 4, 2023
094ad09
Review Fixes
ArikDay Dec 11, 2023
fae5920
classifier update
ArikDay Dec 18, 2023
eb2f169
ReleaseNotes
ArikDay Dec 18, 2023
77f0c67
add ons
ArikDay Dec 18, 2023
0be3d82
addons
ArikDay Dec 18, 2023
a32be77
ReleaseNotes
ArikDay Dec 18, 2023
1cbf815
new layoutscontainer
ArikDay Dec 18, 2023
20610bc
rn
ArikDay Dec 18, 2023
d6a1071
fix
ArikDay Dec 18, 2023
081c21d
fix validation error
ArikDay Dec 18, 2023
209adeb
rn fix
ArikDay Dec 18, 2023
f3d0add
fix
ArikDay Dec 20, 2023
472202d
fix rn
ArikDay Dec 20, 2023
51a2a8e
Merge branch 'PrismaCloudV2XSIAM' of github.com:demisto/content into …
ArikDay Dec 24, 2023
4538762
Merge branch 'master' of github.com:demisto/content
ArikDay Dec 24, 2023
f7620ec
fix
ArikDay Dec 24, 2023
dd15d03
Merge branch 'master' into PrismaCloudV2XSIAM
ArikDay Dec 24, 2023
90bb1a1
Merge branch 'master' of github.com:demisto/content into PrismaCloudV…
ArikDay Dec 27, 2023
8d2b1e6
ReleaseNotes
ArikDay Dec 27, 2023
670e697
rn
ArikDay Dec 27, 2023
7b562d7
Merge branch 'master' into PrismaCloudV2XSIAM
ArikDay Dec 27, 2023
4ebc099
Merge branch 'master' of github.com:demisto/content into PrismaCloudV…
ArikDay Dec 31, 2023
f6427ab
fixed rn
ArikDay Dec 31, 2023
fd97ca9
Merge branch 'PrismaCloudV2XSIAM' of github.com:demisto/content into …
ArikDay Dec 31, 2023
4ddfff4
rn
ArikDay Dec 31, 2023
a5b3bd5
Merge branch 'master' into PrismaCloudV2XSIAM
ArikDay Dec 31, 2023
82b073a
fix prev rn
ArikDay Dec 31, 2023
129622e
Merge branch 'master' into PrismaCloudV2XSIAM
ArikDay Dec 31, 2023
b283b5d
Merge branch 'master' of github.com:demisto/content into PrismaCloudV…
ArikDay Dec 31, 2023
4894c32
Merge branch 'PrismaCloudV2XSIAM' of github.com:demisto/content into …
ArikDay Dec 31, 2023
4b54923
bump
ArikDay Dec 31, 2023
3659ab4
bump
ArikDay Dec 31, 2023
bedbf23
Merge branch 'master' into PrismaCloudV2XSIAM
ArikDay Dec 31, 2023
649c63f
Merged master into current branch.
Jan 1, 2024
b410f92
Bump pack from version CommonTypes to 3.3.98.
Jan 1, 2024
f79f003
Merge branch 'master' into PrismaCloudV2XSIAM
ArikDay Jan 2, 2024
99b1601
Merge branch 'master' into PrismaCloudV2XSIAM
sapirshuker Jan 2, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Jump to
Jump to file
Failed to load files.
Diff view
Diff view
@@ -0,0 +1,27 @@
{
"associatedToAll": true,
"caseInsensitive": true,
"cliName": "statusreason",
"closeForm": false,
"content": true,
"editForm": true,
"group": 0,
"hidden": false,
"id": "incident_statusreason",
"isReadOnly": false,
"locked": false,
"name": "Status Reason",
"neverSetAsRequired": false,
"openEnded": false,
"ownerOnly": false,
"required": false,
"sla": 0,
"system": false,
"threshold": 72,
"type": "shortText",
"unmapped": false,
"unsearchable": true,
"useAsKpi": false,
"version": -1,
"fromVersion": "6.10.0"
}
4 changes: 4 additions & 0 deletions Packs/CommonTypes/ReleaseNotes/3_3_98.md
@@ -0,0 +1,4 @@

#### Incident Fields

- New: **Status Reason**
2 changes: 1 addition & 1 deletion Packs/CommonTypes/pack_metadata.json
Expand Up @@ -2,7 +2,7 @@
"name": "Common Types",
"description": "This Content Pack will get you up and running in no-time and provide you with the most commonly used incident & indicator fields and types.",
"support": "xsoar",
"currentVersion": "3.3.97",
"currentVersion": "3.3.98",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down
Expand Up @@ -1949,7 +1949,11 @@
"accessor": "lastModifiedOn",
"filters": [],
"root": "policy",
"transformers": []
"transformers": [
{
"operator": "TimeStampToDate"
}
]
}
},
"Last Seen": {
Expand Down Expand Up @@ -2073,7 +2077,11 @@
"complex": {
"filters": [],
"root": "alertTime",
"transformers": []
"transformers": [
{
"operator": "TimeStampToDate"
}
]
}
},
"RRN": {
Expand Down Expand Up @@ -2159,6 +2167,13 @@
"transformers": []
}
},
"Status Reason": {
"complex": {
"filters": [],
"root": "reason",
"transformers": []
}
},
"Subscription Assigned By": {
"complex": {
"accessor": "data.properties.metadata.assignedBy",
Expand Down
68 changes: 68 additions & 0 deletions Packs/PrismaCloud/LayoutRules/Prisma_Cloud_V2.json
@@ -0,0 +1,68 @@
{
"rule_id": "Prisma_Cloud_V2_Layout_Rule",
"layout_id": "Prisma Cloud V2",
"description": "display for Prisma Cloud alerts.",
"rule_name": "Prisma Cloud V2 Layout Rule",
"alerts_filter": {
"filter": {
"OR": [
{
"SEARCH_FIELD": "alert_type",
ArikDay marked this conversation as resolved.
Show resolved Hide resolved
"SEARCH_TYPE": "EQ",
"SEARCH_VALUE": "AWS CloudTrail Misconfiguration"
},
{
"SEARCH_FIELD": "alert_type",
"SEARCH_TYPE": "EQ",
"SEARCH_VALUE": "AWS EC2 Instance Misconfiguration"
},
{
"SEARCH_FIELD": "alert_type",
"SEARCH_TYPE": "EQ",
"SEARCH_VALUE": "AWS IAM Policy Misconfiguration"
},
{
"SEARCH_FIELD": "alert_type",
"SEARCH_TYPE": "EQ",
"SEARCH_VALUE": "Azure AKS Misconfiguration"
},
{
"SEARCH_FIELD": "alert_type",
"SEARCH_TYPE": "EQ",
"SEARCH_VALUE": "Azure Network Misconfiguration"
},
{
"SEARCH_FIELD": "alert_type",
"SEARCH_TYPE": "EQ",
"SEARCH_VALUE": "Azure SQL Misconfiguration"
},
{
"SEARCH_FIELD": "alert_type",
"SEARCH_TYPE": "EQ",
"SEARCH_VALUE": "Azure Storage Misconfiguration"
},
{
"SEARCH_FIELD": "alert_type",
"SEARCH_TYPE": "EQ",
"SEARCH_VALUE": "GCP Compute Engine Misconfiguration"
},
{
"SEARCH_FIELD": "alert_type",
"SEARCH_TYPE": "EQ",
"SEARCH_VALUE": "GCP Kubernetes Engine Misconfiguration"
},
{
"SEARCH_FIELD": "alert_type",
"SEARCH_TYPE": "EQ",
"SEARCH_VALUE": "Prisma Cloud - VM Alert Prioritization"
},
{
"SEARCH_FIELD": "alert_type",
"SEARCH_TYPE": "EQ",
"SEARCH_VALUE": "Prisma Cloud"
}
]
}
},
"fromVersion": "6.10.0"
}