IBM QRadar SOAR

IBM QRadar SOAR

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Outbound email integration - using OAuth 2

    Posted Thu December 14, 2023 01:00 AM

    Hello experts,

    I want to integrate outbound email SOAR application to my Microsoft exchange online using OAuth 2. I am following this Microsoft documentation  https://learn.microsoft.com/en-us/azure/energy-data-services/how-to-generate-refresh-token#get-a-refresh-token to retrieve both access token and refresh token, however when I tried to retrieve the refresh token from a bash terminal using the authorization code I get the error message ( as shown below) that my authorization code has expired. I know this is related to Microsoft, but I will appreciate if anyone can assist here.  How can I obtain a new authorization code ? I keep receiving the same authorization code anytime I request for a new one.

    Error message: {"error":"invalid_grant","error_description":"AADSTS70008: The provided authorization code or refresh token has expired due to inactivity. ................................}

    Thank you,



    ------------------------------
    benlinux
    ------------------------------


  • 2.  RE: Outbound email integration - using OAuth 2

    Posted Thu December 14, 2023 12:41 PM

    Hi Benlinux 

    I have reached out to the development team for assistance.

    Will keep you posted on their feedback ...

    Regards

    John



    ------------------------------
    John Quirke
    ------------------------------



  • 3.  RE: Outbound email integration - using OAuth 2

    Posted Thu December 14, 2023 03:29 PM

    Hello John,

    Thank you. I have fixed the issue. Integration works fine now.

    Regards,



    ------------------------------
    benlinux
    ------------------------------



  • 4.  RE: Outbound email integration - using OAuth 2

    Posted Mon December 18, 2023 04:58 AM

    That's great Benlinux.

    Did the development team reach out to you to help resolve ?

    John



    ------------------------------
    John Quirke
    ------------------------------



  • 5.  RE: Outbound email integration - using OAuth 2

    Posted Mon December 18, 2023 05:34 AM

    Hello John,

    They didn't engage me. 

    Thank you 



    ------------------------------
    benlinux
    ------------------------------



  • 6.  RE: Outbound email integration - using OAuth 2

    Posted Tue December 19, 2023 02:01 AM

    Hello John,

    Trust you are doing great.

    I am having another issue related to Cisco Umbrella investigate - Function(Threadgrid sample information for a hash). It seems the python script is breaking for this particular function.

    The Cisco Umbrealla investigate app from ibm app exchange: https://exchange.xforce.ibmcloud.com/api/hub/extensionsNew/d0bf3f6a27742c3deefa1426eab8b4fa/Resilient_Integrations_Function_Guide_for_Cisco_Umbrella_Investigate.pdf

    Traceback (most recent call last):

      File "/opt/app-root/lib64/python3.9/site-packages/fn_cisco_umbrella_inv/components/umbrella_threat_grid_sample.py", line 151, in _umbrella_threat_grid_sample_function

        rtn = rinv.sample(hash, **params)

      File "/opt/app-root/lib64/python3.9/site-packages/investigate/investigate.py", line 292, in sample

        return self.get_parse(uri, params)

      File "/opt/app-root/lib64/python3.9/site-packages/investigate/investigate.py", line 107, in get_parse

        return self._request_parse(self.get, uri, params)

      File "/opt/app-root/lib64/python3.9/site-packages/investigate/investigate.py", line 100, in _request_parse

        r.raise_for_status()

      File "/opt/app-root/lib64/python3.9/site-packages/requests/models.py", line 1021, in raise_for_status

        raise HTTPError(http_error_msg, response=self)

    requests.exceptions.HTTPError: 400 Client Error: Bad Request for url: https://investigate.umbrella.com/sample/44d88612fea##f######b02f?limit=2&offset=0

    Please i will appreciate your help here.



    ------------------------------
    benlinux
    ------------------------------



  • 7.  RE: Outbound email integration - using OAuth 2

    Posted Tue December 19, 2023 07:12 AM

    Hi Benlinux

     

    That does look like a bug ,I have reached out to the team for guidance.

    Will keep you posted.

    John

     






  • 8.  RE: Outbound email integration - using OAuth 2

    Posted Tue December 19, 2023 10:45 AM

    Hello John,

    I have opened a case: TS015021656

    Please assist.



    ------------------------------
    benlinux
    ------------------------------