<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alerting Endpoint misses an endpoint group allocation in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alerting-endpoint-misses-an-endpoint-group-allocation/m-p/526811#M3393</link>
    <description>&lt;P&gt;&lt;FONT size="3"&gt;Hi&amp;nbsp;Rob,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;An out of the box automation is not available. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;However, you may be able to tweak your correlation rule with an XQL query using a Regex expression substitution such as &lt;FONT color="#0000FF"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;replace&lt;/EM&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;. Also, as an example, if you are ingesting the corresponding Windows Event ID for domain name changes (&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;dataset=xdr_data&lt;/EM&gt;&lt;/FONT&gt;) using the&amp;nbsp;&lt;FONT face="courier new,courier" color="#0000FF"&gt;&lt;STRONG&gt;alter&lt;/STRONG&gt; &lt;/FONT&gt;stage which assigns a value to a field name based on the returned value of the function, may yield better results. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;Reference&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-XQL-Language-Reference/Alter" target="_blank" rel="noopener"&gt;Alter • Cortex XDR XQL Language Reference • Reader • Palo Alto Networks documentation portal&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Jan 2023 17:19:10 GMT</pubDate>
    <dc:creator>jtalton</dc:creator>
    <dc:date>2023-01-12T17:19:10Z</dc:date>
    <item>
      <title>Alerting Endpoint misses an endpoint group allocation</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alerting-endpoint-misses-an-endpoint-group-allocation/m-p/525074#M3290</link>
      <description>&lt;P&gt;Hello dear community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as you know, there are sometimes changes (computer names, domains, etc.) on the endpoints.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And know there is also a cortex version from PA, which has the problem too "kicking" out the endpoint from the endpoint group (not really, but the allocation doesn't work).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How do I catch this by alert? I want to be alerted, when the allocation to a group name is not upright.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this possible?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried it with correlation rule on dataset endpoints, but the group name of this endpoint is still the old entry and not the 0 or null entry.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Agent Log doesn't tell me anything what I need to create an alert.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How do you handle this use case with automation/alerting?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Dec 2022 23:06:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alerting-endpoint-misses-an-endpoint-group-allocation/m-p/525074#M3290</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-12-25T23:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: Alerting Endpoint misses an endpoint group allocation</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alerting-endpoint-misses-an-endpoint-group-allocation/m-p/526811#M3393</link>
      <description>&lt;P&gt;&lt;FONT size="3"&gt;Hi&amp;nbsp;Rob,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;An out of the box automation is not available. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;However, you may be able to tweak your correlation rule with an XQL query using a Regex expression substitution such as &lt;FONT color="#0000FF"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;replace&lt;/EM&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;. Also, as an example, if you are ingesting the corresponding Windows Event ID for domain name changes (&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;dataset=xdr_data&lt;/EM&gt;&lt;/FONT&gt;) using the&amp;nbsp;&lt;FONT face="courier new,courier" color="#0000FF"&gt;&lt;STRONG&gt;alter&lt;/STRONG&gt; &lt;/FONT&gt;stage which assigns a value to a field name based on the returned value of the function, may yield better results. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;Reference&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-XQL-Language-Reference/Alter" target="_blank" rel="noopener"&gt;Alter • Cortex XDR XQL Language Reference • Reader • Palo Alto Networks documentation portal&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 17:19:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alerting-endpoint-misses-an-endpoint-group-allocation/m-p/526811#M3393</guid>
      <dc:creator>jtalton</dc:creator>
      <dc:date>2023-01-12T17:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: Alerting Endpoint misses an endpoint group allocation</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alerting-endpoint-misses-an-endpoint-group-allocation/m-p/527618#M3418</link>
      <description>&lt;P&gt;Thanks! I will have a look on it for the case when Domain changes.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But what if the group group is not allocated anymore or not yet?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It would be enough for me, when the endpoints dataset would be in sync, when there are changes in the allocation.&lt;/P&gt;
&lt;P&gt;This should work by design.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 21:30:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alerting-endpoint-misses-an-endpoint-group-allocation/m-p/527618#M3418</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2023-01-18T21:30:46Z</dc:date>
    </item>
  </channel>
</rss>

