Links

Cortex XSOAR (formerly Demisto) Integration

Create ilert alerts directly from Cortex XSOAR (formerly Demisto).
Cortex XSOAR is the industry’s only extended security orchestration, automation and response platform that unifies case management, automation, real-time collaboration and threat intelligence management to transform every stage of the alert lifecycle. Teams can manage alerts across all sources, standardize processes with playbooks, take action on threat intelligence and automate response for any security use case, resulting in significantly faster responses that require less manual review.

In ilert: Create a Cortex XSOAR alert source

  1. 1.
    Go to Alert sources --> Alert sources and click on Create new alert source
  2. 2.
    Search for Cortex XSOAR in the search field, click on the Cortex XSOAR tile and click on Next.
  3. 3.
    Give your alert source a name, optionally assign teams and click Next.
  4. 4.
    Select an escalation policy by creating a new one or assigning an existing one.
  5. 5.
    Select you Alert grouping preference and click Continue setup. You may click Do not group alerts for now and change it later.
  6. 6.
    The next page show additional settings such as customer alert templates or notification prioritiy. Click on Finish setup for now.
  7. 7.
    On the final page, an API key and / or webhook URL will be generated that you will need later in this guide.

In Cortex XSOAR Server: Add Integration

  1. 1.
    Go to Cortex XSOAR, then to Settings -> Integrations, search for iLert integration and click on the Add instance button
  1. 2.
    On the modal window, name the instance, paste the ilert API Key that that you generated in ilert and click on the Save & exit button
  1. 3.
    Type some available ilert command to test the integration, e.g.
!iLert-submit-event summary="Test alert"

FAQ

Can I connect Cortex XSOAR with multiple alert sources from ilert?
Yes, simply add more integration instances in Cortex XSOAR.