<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Incorporating NGFW and Active Directory information into the management console in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incorporating-ngfw-and-active-directory-information-into-the/m-p/502174#M2159</link>
    <description>&lt;P&gt;We have the Prevent license and I am curious if anyone has been able to take their PA NGFW data and send it to the XDR console? I know this can be done with the Pro license for increased forensics and threat detection but I am not sure if I can do it with Prevent.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also looking to implement the Cloud Identity solution. Has anyone done that before? What are your thoughts/tips/concerns with the process?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Jun 2022 11:10:21 GMT</pubDate>
    <dc:creator>CraigV123</dc:creator>
    <dc:date>2022-06-09T11:10:21Z</dc:date>
    <item>
      <title>Incorporating NGFW and Active Directory information into the management console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incorporating-ngfw-and-active-directory-information-into-the/m-p/502174#M2159</link>
      <description>&lt;P&gt;We have the Prevent license and I am curious if anyone has been able to take their PA NGFW data and send it to the XDR console? I know this can be done with the Pro license for increased forensics and threat detection but I am not sure if I can do it with Prevent.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also looking to implement the Cloud Identity solution. Has anyone done that before? What are your thoughts/tips/concerns with the process?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2022 11:10:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incorporating-ngfw-and-active-directory-information-into-the/m-p/502174#M2159</guid>
      <dc:creator>CraigV123</dc:creator>
      <dc:date>2022-06-09T11:10:21Z</dc:date>
    </item>
    <item>
      <title>Re: Incorporating NGFW and Active Directory information into the management console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incorporating-ngfw-and-active-directory-information-into-the/m-p/502186#M2160</link>
      <description>&lt;P&gt;Also keep in mind you can integrate virus total and autofocus as well. I have the&amp;nbsp;&lt;SPAN&gt;Cloud Identity solution (basically ad integration)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;it was super simple.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2022 11:59:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incorporating-ngfw-and-active-directory-information-into-the/m-p/502186#M2160</guid>
      <dc:creator>P.Jacob</dc:creator>
      <dc:date>2022-06-09T11:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: Incorporating NGFW and Active Directory information into the management console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incorporating-ngfw-and-active-directory-information-into-the/m-p/502411#M2170</link>
      <description>&lt;P&gt;Hi CraigV123,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With Cortex XDR Prevent, only the XDR Agent information can be ingested into XDR console, an XDR Pro license allows you to ingest alerts from 3rd party sources (including NGFW) and a Pro per TB license allows you to ingest the raw logs.&amp;nbsp; Please refer to this doc page with detailed information on capabilities per license type (&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/cortex-xdr-overview/cortex-xdr-licenses/features-by-cortex-xdr-license-type#features-by-cortex-xdr-license-type" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/cortex-xdr-overview/cortex-xdr-licenses/features-by-cortex-xdr-license-type#features-by-cortex-xdr-license-type&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Correction: You can use the AD integration feature to bring in data from AD for alerts and incidents.&amp;nbsp; It's the Identity Analytics that you won't be able to utilize.&amp;nbsp; Check out&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/get-started-with-cortex-xdr-pro/set-up-cloud-identity-engine" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/get-started-with-cortex-xdr-pro/set-up-cloud-identity-engine&lt;/A&gt;&amp;nbsp;for information on configuring this.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2022 19:47:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incorporating-ngfw-and-active-directory-information-into-the/m-p/502411#M2170</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2022-06-09T19:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: Incorporating NGFW and Active Directory information into the management console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incorporating-ngfw-and-active-directory-information-into-the/m-p/502578#M2171</link>
      <description>&lt;P&gt;I appreciate the response and additional information. Trying to get our organization to see the benefit in the upgrade. This sort of stuff helps.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 10:34:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incorporating-ngfw-and-active-directory-information-into-the/m-p/502578#M2171</guid>
      <dc:creator>CraigV123</dc:creator>
      <dc:date>2022-06-10T10:34:40Z</dc:date>
    </item>
  </channel>
</rss>

