<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR - How We Distinguish Ourselves From a SIEM Solution in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-how-we-distinguish-ourselves-from-a-siem-solution/m-p/442787#M1175</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="nhussaini_0-1634871886225.jpeg" style="width: 784px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37184i3FB5FAA7C01CA038/image-dimensions/784x121?v=v2" width="784" height="121" role="button" title="nhussaini_0-1634871886225.jpeg" alt="nhussaini_0-1634871886225.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When running a SIEM, you need to have a huge team of many Analysts Level 1, Level 2, Level 3… Escalations to lateral teams (sometimes to take actions such as isolating endpoints/servers, gathering/deleting suspicious files, etc). It is laborious and time consuming to perform simple actions, like creating an alert.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Read&amp;nbsp;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;&lt;A id="link_7" class="page-link lia-link-navigation lia-custom-event" href="https://live.paloaltonetworks.com/t5/cortex-xdr-articles/cortex-xdr-how-we-distinguish-ourselves-from-a-siem-solution/ta-p/442782" target="_blank" rel="noopener"&gt;Cortex XDR - How We Distinguish Ourselves From a SIEM Solution&lt;/A&gt;&lt;/STRONG&gt;&amp;nbsp;&lt;/FONT&gt;to learn more on this topic from our experts!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF6600"&gt;Palo Alto Networks Contributors:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Luis Escobar,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Cortex&lt;/EM&gt;&amp;nbsp;&lt;EM&gt;Customer Success Architect&amp;nbsp;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;Maor Hojberg,&amp;nbsp;&lt;EM&gt;Technical Marketing Engineer&amp;nbsp;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;&lt;EM&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Nov 2021 03:18:17 GMT</pubDate>
    <dc:creator>nhussaini</dc:creator>
    <dc:date>2021-11-05T03:18:17Z</dc:date>
    <item>
      <title>Cortex XDR - How We Distinguish Ourselves From a SIEM Solution</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-how-we-distinguish-ourselves-from-a-siem-solution/m-p/442787#M1175</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="nhussaini_0-1634871886225.jpeg" style="width: 784px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37184i3FB5FAA7C01CA038/image-dimensions/784x121?v=v2" width="784" height="121" role="button" title="nhussaini_0-1634871886225.jpeg" alt="nhussaini_0-1634871886225.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When running a SIEM, you need to have a huge team of many Analysts Level 1, Level 2, Level 3… Escalations to lateral teams (sometimes to take actions such as isolating endpoints/servers, gathering/deleting suspicious files, etc). It is laborious and time consuming to perform simple actions, like creating an alert.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Read&amp;nbsp;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;&lt;A id="link_7" class="page-link lia-link-navigation lia-custom-event" href="https://live.paloaltonetworks.com/t5/cortex-xdr-articles/cortex-xdr-how-we-distinguish-ourselves-from-a-siem-solution/ta-p/442782" target="_blank" rel="noopener"&gt;Cortex XDR - How We Distinguish Ourselves From a SIEM Solution&lt;/A&gt;&lt;/STRONG&gt;&amp;nbsp;&lt;/FONT&gt;to learn more on this topic from our experts!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF6600"&gt;Palo Alto Networks Contributors:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Luis Escobar,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Cortex&lt;/EM&gt;&amp;nbsp;&lt;EM&gt;Customer Success Architect&amp;nbsp;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;Maor Hojberg,&amp;nbsp;&lt;EM&gt;Technical Marketing Engineer&amp;nbsp;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;&lt;EM&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 03:18:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-how-we-distinguish-ourselves-from-a-siem-solution/m-p/442787#M1175</guid>
      <dc:creator>nhussaini</dc:creator>
      <dc:date>2021-11-05T03:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR - How We Distinguish Ourselves From a SIEM Solution</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-how-we-distinguish-ourselves-from-a-siem-solution/m-p/445069#M1208</link>
      <description>&lt;P&gt;Cortex XDR lacks a unified data model which impedes the ability to rapidly perform useful searches across disparate datasets.&amp;nbsp; Are there plans to address that gap?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 20:41:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-how-we-distinguish-ourselves-from-a-siem-solution/m-p/445069#M1208</guid>
      <dc:creator>SStonebraker</dc:creator>
      <dc:date>2021-11-02T20:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR - How We Distinguish Ourselves From a SIEM Solution</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-how-we-distinguish-ourselves-from-a-siem-solution/m-p/445281#M1211</link>
      <description>&lt;P&gt;Hi SStonebraker,&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you mean that Cortex XDR doesn't have a dataset that holds all the datasets, that is correct. But so far we dont need that because&amp;nbsp;in Cortex XDR, you can query and search with XQL any dataset and a combination of them in a very good response time. Creating a dataset of datasets will screw the searches response and so far there is no point to do so.&lt;/P&gt;&lt;P&gt;On top of that we have Cortex XDR Collectors that can collect data/logs from a miriad of sources ftp, linux system logs, windows, webservers of many flavors (IIS, apache, nginx), Fw, you name it. Once that those logs are uploaded in our Cortex management console in the cloud you can perform XQL queries on them.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Additionally you can save the XQL queries in a public area so you and all your work mates can reuse them without reinventing the wheel.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can also save the queries as correlation rules and set the timing to launch them...&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a source for XQL query center documentation, please visit the link:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/search-queries/query-center" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/search-queries/query-center&lt;/A&gt;&lt;/P&gt;&lt;P&gt;From there you can also jump to other very good XQL documentation sources.&lt;/P&gt;&lt;P&gt;Hope this helped.&lt;/P&gt;&lt;P&gt;Kind Regards,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luis&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 16:23:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-how-we-distinguish-ourselves-from-a-siem-solution/m-p/445281#M1211</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2021-11-03T16:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR - How We Distinguish Ourselves From a SIEM Solution</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-how-we-distinguish-ourselves-from-a-siem-solution/m-p/447328#M1239</link>
      <description>&lt;P&gt;PAN Cortex XDR isn't a SIEM!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also PAN check out Cortex XDR 3.0 now with correlation searches and the ability to ingest data from anywhere!!!&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Nov 2021 02:45:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-how-we-distinguish-ourselves-from-a-siem-solution/m-p/447328#M1239</guid>
      <dc:creator>eumbach</dc:creator>
      <dc:date>2021-11-13T02:45:22Z</dc:date>
    </item>
  </channel>
</rss>

