<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User validity via VPN /RDP. in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/user-validity-via-vpn-rdp/m-p/535554#M3918</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203132"&gt;@NivedaR&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out on LIVEcommunity!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've read your question and i'm afraid i'm not entirely sure what you're asking.&amp;nbsp; Can you please be more specific and possibly explain the use case so I can understand your goal a little better.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you so much!&lt;/P&gt;</description>
    <pubDate>Thu, 23 Mar 2023 14:08:04 GMT</pubDate>
    <dc:creator>anlynch</dc:creator>
    <dc:date>2023-03-23T14:08:04Z</dc:date>
    <item>
      <title>User validity via VPN /RDP.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/user-validity-via-vpn-rdp/m-p/535513#M3916</link>
      <description>&lt;P&gt;Hello ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible to do user validity via VPN/RDP through Cortex XDR.&lt;/P&gt;
&lt;P&gt;Or to detect user validity.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 06:44:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/user-validity-via-vpn-rdp/m-p/535513#M3916</guid>
      <dc:creator>NivedaR</dc:creator>
      <dc:date>2023-03-23T06:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: User validity via VPN /RDP.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/user-validity-via-vpn-rdp/m-p/535554#M3918</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203132"&gt;@NivedaR&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out on LIVEcommunity!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've read your question and i'm afraid i'm not entirely sure what you're asking.&amp;nbsp; Can you please be more specific and possibly explain the use case so I can understand your goal a little better.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you so much!&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 14:08:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/user-validity-via-vpn-rdp/m-p/535554#M3918</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2023-03-23T14:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: User validity via VPN /RDP.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/user-validity-via-vpn-rdp/m-p/536131#M3926</link>
      <description>&lt;P&gt;Hello ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The use case is that few machines are isolated from the internet , and to connect with those machines one needs to connect via RDP so to login you have to use VPN to connect to the machine via RDP . so we need to keep record/identify permissions for those users.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 10:20:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/user-validity-via-vpn-rdp/m-p/536131#M3926</guid>
      <dc:creator>NivedaR</dc:creator>
      <dc:date>2023-03-24T10:20:14Z</dc:date>
    </item>
    <item>
      <title>Re: User validity via VPN /RDP.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/user-validity-via-vpn-rdp/m-p/536370#M3935</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203132"&gt;@NivedaR&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think I understand now.&amp;nbsp; In your environment you're using a VPN to connect to a network.&amp;nbsp; Once authenticated to the network via VPN then an RDP session is created to reach the machines that are not connected to the internet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cortex XDR has the ability for you to ingest logs from your VPN client as well as your RDP session (ensure logging is turned on for RDP).&amp;nbsp; I'll walk through the steps at a high level as this is a multi-step process.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Ingest-CSV-Files-as-Datasets" target="_self"&gt;Ingesting&lt;/A&gt; the appropriate logs into Cortex XDR (VPN &amp;amp; RDP)&lt;/P&gt;
&lt;P&gt;2. &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Create-Parsing-Rules" target="_self"&gt;Parsing&lt;/A&gt; those logs&lt;/P&gt;
&lt;P&gt;3. Creating &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Administrator-Guide/Working-with-Correlation-Rules" target="_self"&gt;correlation rules&lt;/A&gt; to create alerts from the logs in step 1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm aware this can be an extensive process especially if it's never been done before.&amp;nbsp; I've included some resources above that I think will help you along your way.&amp;nbsp; I'm also including a &lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-webinars/cortex-xdr-customer-success-webinar-third-party-logs-ingestion/ta-p/518548" target="_self"&gt;link to a webinar&lt;/A&gt; done recently titled "Cortex XDR Customer Success Webinar: Third-Party Logs Ingestion, Parsing, and Custom Correlation". This webinar has some demonstrations to help you through the process as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope I was able to provide with some helpful information.&amp;nbsp; Feel free to respond here if you have any other questions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a great day!&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 17:52:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/user-validity-via-vpn-rdp/m-p/536370#M3935</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2023-03-24T17:52:10Z</dc:date>
    </item>
  </channel>
</rss>

