<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Query SMA for Mails in Quarantine with SecureX Orchestration in Cisco XDR</title>
    <link>https://community.cisco.com/t5/cisco-xdr/query-sma-for-mails-in-quarantine-with-securex-orchestration/m-p/4408111#M9</link>
    <description>&lt;P&gt;Hi Chris&lt;/P&gt;&lt;P&gt;Now the customer is using on-prem ESA managed with SMA. That's why I don't get it how to do that....&lt;/P&gt;</description>
    <pubDate>Tue, 25 May 2021 07:16:46 GMT</pubDate>
    <dc:creator>Markus Sandmeier</dc:creator>
    <dc:date>2021-05-25T07:16:46Z</dc:date>
    <item>
      <title>Query SMA for Mails in Quarantine with SecureX Orchestration</title>
      <link>https://community.cisco.com/t5/cisco-xdr/query-sma-for-mails-in-quarantine-with-securex-orchestration/m-p/4405418#M4</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;How cloud I query the SMA API for mails in quarantine with SecureX orchestration? Do I have to use Threat Response API?&lt;/P&gt;&lt;P&gt;Could anyone assist?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p"&gt;&lt;STRONG&gt;Sample Request&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="p"&gt;&lt;STRONG&gt;GET /sma/api/v2.0/quarantine/messages?endDate=2018-11-21T23:59:00.000Z&amp;amp; limit=25&amp;amp;offset=0&amp;amp;orderBy=date&amp;amp;orderDir=desc&amp;amp;quarantineType=spam&amp;amp;startDate=2018-07-01T00:00:00.000Z&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="p"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What kind of endpoint do I need in SecureX orchestration?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 13:32:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-xdr/query-sma-for-mails-in-quarantine-with-securex-orchestration/m-p/4405418#M4</guid>
      <dc:creator>Markus Sandmeier</dc:creator>
      <dc:date>2021-05-19T13:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: Query SMA for Mails in Quarantine with SecureX Orchestration</title>
      <link>https://community.cisco.com/t5/cisco-xdr/query-sma-for-mails-in-quarantine-with-securex-orchestration/m-p/4405492#M5</link>
      <description>&lt;P&gt;Hi Markus, I would recommend to use a HTTP Request action and drag that into your canvas. You also have to create a HTTP target with the domain of your SMA tenant. You can then select that target in the HTTP Request action and&amp;nbsp; use this as relative URL:&amp;nbsp;&lt;EM&gt;/sma/api/v2.0/quarantine/messages?endDate=2018-11-21T23:59:00.000Z&amp;amp; limit=25&amp;amp;offset=0&amp;amp;orderBy=date&amp;amp;orderDir=desc&amp;amp;quarantineType=spam&amp;amp;startDate=2018-07-01T00:00:00.000Z&lt;/EM&gt;. You will probably have to add some headers and make sure your authorization is working. Please let me know if this helps!&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 15:16:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-xdr/query-sma-for-mails-in-quarantine-with-securex-orchestration/m-p/4405492#M5</guid>
      <dc:creator>chrivand</dc:creator>
      <dc:date>2021-05-19T15:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: Query SMA for Mails in Quarantine with SecureX Orchestration</title>
      <link>https://community.cisco.com/t5/cisco-xdr/query-sma-for-mails-in-quarantine-with-securex-orchestration/m-p/4406299#M6</link>
      <description>&lt;P&gt;Could you make a config example of this HTTP target? How can I configure devices which are connected over SSE as a HTTP target?&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 21:23:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-xdr/query-sma-for-mails-in-quarantine-with-securex-orchestration/m-p/4406299#M6</guid>
      <dc:creator>Markus Sandmeier</dc:creator>
      <dc:date>2021-05-20T21:23:11Z</dc:date>
    </item>
    <item>
      <title>Re: Query SMA for Mails in Quarantine with SecureX Orchestration</title>
      <link>https://community.cisco.com/t5/cisco-xdr/query-sma-for-mails-in-quarantine-with-securex-orchestration/m-p/4406308#M7</link>
      <description>&lt;P&gt;Ah could it be that I only need to use the SecureX Internal Target?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 21:49:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-xdr/query-sma-for-mails-in-quarantine-with-securex-orchestration/m-p/4406308#M7</guid>
      <dc:creator>Markus Sandmeier</dc:creator>
      <dc:date>2021-05-20T21:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: Query SMA for Mails in Quarantine with SecureX Orchestration</title>
      <link>https://community.cisco.com/t5/cisco-xdr/query-sma-for-mails-in-quarantine-with-securex-orchestration/m-p/4408097#M8</link>
      <description>&lt;P&gt;Hi Markus, are you using CES? then you don't have to do this via SSE since CES has a public domain. Here would be an incomplete example:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;PRE&gt;{
  "workflow": {
    "unique_name": "definition_workflow_01OP5RKP52Y1N5lflSPbL09EQJTnrv561Ua",
    "name": "SMA HTTP request example",
    "title": "SMA HTTP request example",
    "type": "generic.workflow",
    "base_type": "workflow",
    "variables": null,
    "properties": {
      "atomic": {
        "is_atomic": false
      },
      "delete_workflow_instance": false,
      "display_name": "SMA HTTP request example",
      "runtime_user": {
        "override_target_runtime_user": false,
        "specify_on_workflow_start": false,
        "target_default": true
      },
      "target": {
        "execute_on_target_group": false,
        "execute_on_workflow_target": false,
        "no_target": true,
        "specify_on_workflow_start": false
      }
    },
    "object_type": "definition_workflow",
    "actions": [
      {
        "unique_name": "definition_activity_01OP5RNIW40KY5sNWRyjrGrWuw01tVRI34J",
        "name": "HTTP Request",
        "title": "SMA HTTP Request",
        "type": "web-service.http_request",
        "base_type": "activity",
        "properties": {
          "action_timeout": 180,
          "allow_auto_redirect": true,
          "continue_on_error_status_code": false,
          "continue_on_failure": false,
          "description": "add SMA target and auth headers",
          "display_name": "SMA HTTP Request",
          "method": "GET",
          "relative_url": "/sma/api/v2.0/quarantine/messages?endDate=2018-11-21T23:59:00.000Z&amp;amp; limit=25&amp;amp;offset=0&amp;amp;orderBy=date&amp;amp;orderDir=desc&amp;amp;quarantineType=spam&amp;amp;startDate=2018-07-01T00:00:00.000Z",
          "runtime_user": {
            "override_target_runtime_user": false,
            "target_default": true
          },
          "skip_execution": false,
          "target": {
            "override_workflow_target": false,
            "override_workflow_target_group_criteria": false,
            "use_workflow_target": true,
            "use_workflow_target_group": false
          }
        },
        "object_type": "definition_activity"
      }
    ],
    "categories": [
      "category_1BMfMXSnJMyt5Ihqi7rWJr5N8cf"
    ]
  }
}&lt;/PRE&gt;</description>
      <pubDate>Tue, 25 May 2021 06:42:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-xdr/query-sma-for-mails-in-quarantine-with-securex-orchestration/m-p/4408097#M8</guid>
      <dc:creator>chrivand</dc:creator>
      <dc:date>2021-05-25T06:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: Query SMA for Mails in Quarantine with SecureX Orchestration</title>
      <link>https://community.cisco.com/t5/cisco-xdr/query-sma-for-mails-in-quarantine-with-securex-orchestration/m-p/4408111#M9</link>
      <description>&lt;P&gt;Hi Chris&lt;/P&gt;&lt;P&gt;Now the customer is using on-prem ESA managed with SMA. That's why I don't get it how to do that....&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 07:16:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-xdr/query-sma-for-mails-in-quarantine-with-securex-orchestration/m-p/4408111#M9</guid>
      <dc:creator>Markus Sandmeier</dc:creator>
      <dc:date>2021-05-25T07:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: Query SMA for Mails in Quarantine with SecureX Orchestration</title>
      <link>https://community.cisco.com/t5/cisco-xdr/query-sma-for-mails-in-quarantine-with-securex-orchestration/m-p/4408473#M10</link>
      <description>&lt;P&gt;hi Markus, if it is on-prem you will either need to poke an inbound hole in the FW (not recommended) or wait until the SecureX orchestration remote connector is released (should be very soon). When it is released you can create internal targets and reach them the same way as I described above &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 19:45:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-xdr/query-sma-for-mails-in-quarantine-with-securex-orchestration/m-p/4408473#M10</guid>
      <dc:creator>chrivand</dc:creator>
      <dc:date>2021-05-25T19:45:47Z</dc:date>
    </item>
    <item>
      <title>Re: Query SMA for Mails in Quarantine with SecureX Orchestration</title>
      <link>https://community.cisco.com/t5/cisco-xdr/query-sma-for-mails-in-quarantine-with-securex-orchestration/m-p/4409440#M11</link>
      <description>&lt;P&gt;Thanks Chris!&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 12:24:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-xdr/query-sma-for-mails-in-quarantine-with-securex-orchestration/m-p/4409440#M11</guid>
      <dc:creator>Markus Sandmeier</dc:creator>
      <dc:date>2021-05-27T12:24:05Z</dc:date>
    </item>
    <item>
      <title>Re: Query SMA for Mails in Quarantine with SecureX Orchestration</title>
      <link>https://community.cisco.com/t5/cisco-xdr/query-sma-for-mails-in-quarantine-with-securex-orchestration/m-p/4409652#M12</link>
      <description>&lt;P&gt;The remote has been released:&amp;nbsp;&lt;A href="https://ciscosecurity.github.io/sxo-05-security-workflows/remote" target="_blank"&gt;https://ciscosecurity.github.io/sxo-05-security-workflows/remote&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 17:29:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-xdr/query-sma-for-mails-in-quarantine-with-securex-orchestration/m-p/4409652#M12</guid>
      <dc:creator>chrivand</dc:creator>
      <dc:date>2021-05-27T17:29:34Z</dc:date>
    </item>
    <item>
      <title>Re: Query SMA for Mails in Quarantine with SecureX Orchestration</title>
      <link>https://community.cisco.com/t5/cisco-xdr/query-sma-for-mails-in-quarantine-with-securex-orchestration/m-p/4411252#M13</link>
      <description>&lt;P&gt;Awesome, thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 07:13:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-xdr/query-sma-for-mails-in-quarantine-with-securex-orchestration/m-p/4411252#M13</guid>
      <dc:creator>Markus Sandmeier</dc:creator>
      <dc:date>2021-06-01T07:13:41Z</dc:date>
    </item>
  </channel>
</rss>

