<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Discovering unprotected devices in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/444701#M1207</link>
    <description>&lt;P&gt;Thanks. I have posted in that thread.. there is no solution, just a link to this vague document.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/asset-management/about-asset-management.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/asset-management/about-asset-management.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And it is marked as a answer. Funny.&amp;nbsp; What is really funny is it refers to pathfinder as a solution but after several tickets on this, cortex support says it does not work.&amp;nbsp; &amp;nbsp;Honestly, I dont think anyone at cortex knows how pathfinder works..&amp;nbsp; When I run a "test" in pathfinder on an IP, it does EXACTLY what I need in the log, it does a reverse lookup and determines if cortex is installed.&amp;nbsp; But yet network mapper does not pass on the IPs it finds to pathfinder to interrogate.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bottom line... has anyone gotten cortex PRO to report names of devices and or platforms name into asset manager that do NOT have xdr installed?&amp;nbsp; If so, how did you do it?&amp;nbsp; This should be doable.. the field is there..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 01 Nov 2021 14:12:37 GMT</pubDate>
    <dc:creator>ESJosephPrinz</dc:creator>
    <dc:date>2021-11-01T14:12:37Z</dc:date>
    <item>
      <title>Discovering unprotected devices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/444570#M1203</link>
      <description>&lt;P&gt;Has anyone come up with a reliable method to report on devices without xdr running on it?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Oct 2021 20:39:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/444570#M1203</guid>
      <dc:creator>ESJosephPrinz</dc:creator>
      <dc:date>2021-10-31T20:39:45Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering unprotected devices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/444682#M1204</link>
      <description>&lt;P&gt;if you don't have any sort of RMM tool and your running prevent you can do a dump out of cortex and and dump out of AD and run a compare. if your running xdr pro look farther down in the topics and there is a good discussion on how to do this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 13:17:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/444682#M1204</guid>
      <dc:creator>P.Jacob</dc:creator>
      <dc:date>2021-11-01T13:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering unprotected devices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/444696#M1205</link>
      <description>&lt;P&gt;Ive dumped all devices that asset manager reports as no cortex XDR and run a script to reverse DNS.&amp;nbsp; What I found was hundreds of false negatives.&amp;nbsp; In other words, cortex asset manager reports no xdr but xdr is indeed running.&amp;nbsp; So for us anyway, asset manager is erroneous.&amp;nbsp; Perhaps something on our firewall side.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are running Pro,&amp;nbsp; what discussion are you referring to?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ive spoken to a sales engineer and several support tickets. No real solution.&amp;nbsp; Ive been pointing down futile paths however.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ive tried pathfinder and it does not detect non cortex xdr devices only high alerts.&lt;/P&gt;&lt;P&gt;We wont run "open source" software on our network so the DHCP logger is a no go. Not to mention we have many dhcp servers so this would be a large deploy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Options left are perhaps the new 7.5 agent which does a peer to peer discovery. However no documentation on the amount of traffic it generates so we wont enable it on our network without proper docs.&amp;nbsp; And I guess global protect HIP detection. Looking into that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 13:59:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/444696#M1205</guid>
      <dc:creator>ESJosephPrinz</dc:creator>
      <dc:date>2021-11-01T13:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering unprotected devices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/444699#M1206</link>
      <description>&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/best-way-to-detect-endpoints-that-do-not-yet-have-cortex-xdr/td-p/381151" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/best-way-to-detect-endpoints-that-do-not-yet-have-cortex-xdr/td-p/381151&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 14:01:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/444699#M1206</guid>
      <dc:creator>P.Jacob</dc:creator>
      <dc:date>2021-11-01T14:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering unprotected devices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/444701#M1207</link>
      <description>&lt;P&gt;Thanks. I have posted in that thread.. there is no solution, just a link to this vague document.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/asset-management/about-asset-management.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/asset-management/about-asset-management.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And it is marked as a answer. Funny.&amp;nbsp; What is really funny is it refers to pathfinder as a solution but after several tickets on this, cortex support says it does not work.&amp;nbsp; &amp;nbsp;Honestly, I dont think anyone at cortex knows how pathfinder works..&amp;nbsp; When I run a "test" in pathfinder on an IP, it does EXACTLY what I need in the log, it does a reverse lookup and determines if cortex is installed.&amp;nbsp; But yet network mapper does not pass on the IPs it finds to pathfinder to interrogate.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bottom line... has anyone gotten cortex PRO to report names of devices and or platforms name into asset manager that do NOT have xdr installed?&amp;nbsp; If so, how did you do it?&amp;nbsp; This should be doable.. the field is there..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 14:12:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/444701#M1207</guid>
      <dc:creator>ESJosephPrinz</dc:creator>
      <dc:date>2021-11-01T14:12:37Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering unprotected devices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/447329#M1240</link>
      <description>&lt;P&gt;Have you looked at network discovery from 7.5?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/asset-management/about-asset-management.html" target="_blank"&gt;About Asset Management (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Nov 2021 02:51:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/447329#M1240</guid>
      <dc:creator>eumbach</dc:creator>
      <dc:date>2021-11-13T02:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering unprotected devices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/447470#M1241</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176081"&gt;@ESJosephPrinz&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe the Network Mapper could help you?&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/broker-vm/set-up-broker-vm/activate-the-network-mapper" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/broker-vm/set-up-broker-vm/activate-the-network-mapper&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Nov 2021 08:36:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/447470#M1241</guid>
      <dc:creator>epalcev</dc:creator>
      <dc:date>2021-11-14T08:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering unprotected devices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/447645#M1243</link>
      <description>&lt;P&gt;thank you I am going to try this&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 15:20:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/447645#M1243</guid>
      <dc:creator>P.Jacob</dc:creator>
      <dc:date>2021-11-15T15:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering unprotected devices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/470759#M1615</link>
      <description>&lt;P&gt;Wanted to update this.. what we found is in our environment the solution was to install cortex dhcp log collector on all Windows dhcp servers and make sure the global protect HIP data was being sent to the cortex lake.&amp;nbsp; This have us all DHCP devices into asset manager so we could report on devices with the agent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, currently the match between asset manager and endpoint admin is IP.. So it is the "join" if you will. Problem is the IP is not updated in endpoint admin when it changes for a long time so we have many false positives. working on a xql report to resolve but dont know if this will be possible yet. But at least we have devices to audit.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Mar 2022 16:37:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/470759#M1615</guid>
      <dc:creator>ESJosephPrinz</dc:creator>
      <dc:date>2022-03-06T16:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering unprotected devices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/470768#M1617</link>
      <description>&lt;P&gt;hello I am very interested in doing this. not too sure what the "cortex dhcp log collector"? I will look it up, also can you do this with the prevent subscription? vs the pro subscription?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Mar 2022 18:52:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/470768#M1617</guid>
      <dc:creator>P.Jacob</dc:creator>
      <dc:date>2022-03-06T18:52:58Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering unprotected devices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/470769#M1618</link>
      <description>&lt;P&gt;Might be pro only but not sure.&amp;nbsp; &amp;nbsp;The filebeat.yml is a bear.. be wary of SPACES!!&amp;nbsp; &amp;nbsp; You will know what I mean if you proceed &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Mar 2022 19:16:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/470769#M1618</guid>
      <dc:creator>ESJosephPrinz</dc:creator>
      <dc:date>2022-03-06T19:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering unprotected devices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/535430#M3912</link>
      <description>&lt;P&gt;Incase anyone else has this issue, here is an XQL Query that will result in which DHCP Devices are not in the Cortex Endpoints Dataset&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;dataset = microsoft_dhcp_raw
| filter hostName != "" and ipAddress != "" //first few lines are same as OP
| alter FormattedName = if (hostname contains ".domain.local",replace(hostname,".domain.local",""),hostname)//replace .domain.local with your domain when running
| join conflict_strategy = left type = left (dataset = endpoints ) as ed ed.endpoint_name = FormattedName //left join ensures that all is returned from DHCP, and only matches from Endpoint
| alter conditional = if(FormattedName = endpoint_name, 1, 0)//if there is a match, it returns 1, otherwise, 0
| fields FormattedName , endpoint_name, conditional
| comp sum(conditional) as totalconnections by FormattedName // by summing on the conditional, if the sum is 0, that means there are 0 logs where DHCP matched with one of your endpoints
| filter (totalconnections = 0) // if you changed this to &amp;gt;0, you will get all devices in DHCP that ARE matched in the Cortex List&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 22 Mar 2023 14:28:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/535430#M3912</guid>
      <dc:creator>nigsmi51</dc:creator>
      <dc:date>2023-03-22T14:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering unprotected devices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/535448#M3914</link>
      <description>&lt;P&gt;This is a great solution, it's a shame that it's Pro/TB and MS DHCP but it's a great solution.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 15:30:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/discovering-unprotected-devices/m-p/535448#M3914</guid>
      <dc:creator>eumbach</dc:creator>
      <dc:date>2023-03-22T15:30:36Z</dc:date>
    </item>
  </channel>
</rss>

