<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block logs to Data Lake from specific endpoint in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-logs-to-data-lake-from-specific-endpoint/m-p/517328#M2984</link>
    <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem is that this endpoint is not listed in Cortex XDR Portal. It was removed from Cortex XDR Portal, agent is still installed on endpoint and sending logs. Do you know how to address this kind of problem?&lt;/P&gt;</description>
    <pubDate>Mon, 10 Oct 2022 16:10:49 GMT</pubDate>
    <dc:creator>tntrust</dc:creator>
    <dc:date>2022-10-10T16:10:49Z</dc:date>
    <item>
      <title>Block logs to Data Lake from specific endpoint</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-logs-to-data-lake-from-specific-endpoint/m-p/517279#M2978</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a case where logs are delivered to Data Lake from endpoint were we're unable to uninstall Cortex XDR agent. We also can't connect to this endpoint to take manual actions to stop receiving logs from it.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Is there any way to block/prevent these endpoint uploading logs to the Data Lake?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;From my knowledge, we could&lt;SPAN class=""&gt;&amp;nbsp;implement Exclusion Policy for endpoint to prevent creating Incidents of any alerts created for that endpoint.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Please answer if you know other solutions to this problem.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 19:33:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-logs-to-data-lake-from-specific-endpoint/m-p/517279#M2978</guid>
      <dc:creator>tntrust</dc:creator>
      <dc:date>2024-04-18T19:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Block logs to Data Lake from specific endpoint</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-logs-to-data-lake-from-specific-endpoint/m-p/517324#M2983</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/244548"&gt;@tntrust&lt;/a&gt;,&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you are unable to connect to the endpoint to manually uninstall the Cortex XDR agent, you are also able to do it on the tenant side from the Action Center.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This can be done by going to Incident Response &amp;gt; Action Center &amp;gt; + New Action&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mfakhouri_0-1665415927062.png" style="width: 658px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44531iCA147DCF3A08D00E/image-dimensions/658x50/is-moderation-mode/true?v=v2" width="658" height="50" role="button" title="mfakhouri_0-1665415927062.png" alt="mfakhouri_0-1665415927062.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Select “Agent Uninstall”, select next, and define your target endpoint. You are able to utilize filtering to define an agent scope for the uninstallation. In your case with an individual endpoint, it may be more useful to select the check mark to the left of the target list for manual selection.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Select next again, review the action summary, and select done. You are able to view the status of the uninstallation under “All Actions” in the Action Center.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mfakhouri_1-1665415927071.png" style="width: 654px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44532iBF75E175B430E1BA/image-dimensions/654x105/is-moderation-mode/true?v=v2" width="654" height="105" role="button" title="mfakhouri_1-1665415927071.png" alt="mfakhouri_1-1665415927071.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Alert exclusions would not work in this scenario since they are designed to suppress alerts, not block them. Though they will be disregarded as alerts by Cortex XDR, the query builder can still be used to search for this data in the Data Lake instance.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this helps!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Further reading:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Uninstall the Cortex XDR agent:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/manage-cortex-xdr-agents/uninstall-the-cortex-agent" target="_blank"&gt;&lt;SPAN&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/manage-cortex-xdr-agents/uninstall-the-cortex-agent&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Alert exclusions:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-response/investigate-endpoint-alerts/alert-exclusions" target="_blank"&gt;&lt;SPAN&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-response/investigate-endpoint-alerts/alert-exclusions&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2022 15:39:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-logs-to-data-lake-from-specific-endpoint/m-p/517324#M2983</guid>
      <dc:creator>mfakhouri</dc:creator>
      <dc:date>2022-10-10T15:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: Block logs to Data Lake from specific endpoint</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-logs-to-data-lake-from-specific-endpoint/m-p/517328#M2984</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem is that this endpoint is not listed in Cortex XDR Portal. It was removed from Cortex XDR Portal, agent is still installed on endpoint and sending logs. Do you know how to address this kind of problem?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2022 16:10:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-logs-to-data-lake-from-specific-endpoint/m-p/517328#M2984</guid>
      <dc:creator>tntrust</dc:creator>
      <dc:date>2022-10-10T16:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: Block logs to Data Lake from specific endpoint</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-logs-to-data-lake-from-specific-endpoint/m-p/517456#M3000</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/244548"&gt;@tntrust&lt;/a&gt;,&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you are unable to view the Cortex XDR agents in the tenant and it is still sending logs to the CDL, we highly recommend contacting our technical assistance team at support.paloaltonetworks.com. They will be able to help identify the issue pertaining to your particular environment and provide any necessary workarounds.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 13:42:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-logs-to-data-lake-from-specific-endpoint/m-p/517456#M3000</guid>
      <dc:creator>mfakhouri</dc:creator>
      <dc:date>2022-10-11T13:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: Block logs to Data Lake from specific endpoint</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-logs-to-data-lake-from-specific-endpoint/m-p/517762#M3016</link>
      <description>&lt;P&gt;Okay, I've contacted with PA Support.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 09:53:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-logs-to-data-lake-from-specific-endpoint/m-p/517762#M3016</guid>
      <dc:creator>tntrust</dc:creator>
      <dc:date>2022-10-13T09:53:53Z</dc:date>
    </item>
  </channel>
</rss>

