During an investigation of an alert with a completed playbook, it is determined that no indicators exist from the email "indicator@test.com" in the Key Assets & Artifacts tab of the parent incident. Which command will determine if Cortex XSIAM has been configured to extract indicators as expected?
The correct answer is C, the !checkIndicatorExtraction text='indicator@test.com' command.
This command specifically verifies if Cortex XSIAM has been correctly configured to extract indicators from given text. It ensures that the text provided ('indicator@test.com') would indeed be recognized and extracted as an indicator under the current configuration of Cortex XSIAM.
Other provided commands do not directly verify the indicator extraction configuration:
Option A: IcreateNewIndicator manually creates an indicator; it does not validate extraction capability.
Option B: !extractIndicators attempts extraction immediately but does not verify existing configuration explicitly.
Option D: Iemailvalue command is generally for creating or querying email indicators, not verifying extraction configuration.
Therefore, the explicit functionality for checking if indicator extraction is configured correctly within Cortex XSIAM is precisely covered by !checkIndicatorExtraction.
Reference Extract from Official Document:
'Verify if Cortex XSIAM is correctly configured to extract indicators using the command !checkIndicatorExtraction text=<value>.'
This exact description confirms that option C is the correct answer to validate the configuration explicitly.
India
3 days agoTemeka
9 days agoShelia
14 days agoCecily
19 days agoCherrie
24 days agoRobt
29 days agoRima
2 months agoDoug
2 months agoMose
2 months agoChu
2 months agoTiffiny
2 months agoAntione
3 months agoArdella
3 months agoMarisha
3 months agoKendra
3 months agoCristen
3 months agoMalinda
3 months agoLizbeth
4 months ago