<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PAN NGFW into XDR best practices in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/pan-ngfw-into-xdr-best-practices/m-p/543113#M4410</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/239366"&gt;@PaulThomas00&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out on LIVEcommunity!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not sure there's a best practices for NGFW logs available.&amp;nbsp; Can you tell me a little more about your issue?&amp;nbsp; I'm assuming the incidents have been investigated and determined to be false positive.&lt;/P&gt;</description>
    <pubDate>Wed, 24 May 2023 01:32:06 GMT</pubDate>
    <dc:creator>anlynch</dc:creator>
    <dc:date>2023-05-24T01:32:06Z</dc:date>
    <item>
      <title>PAN NGFW into XDR best practices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/pan-ngfw-into-xdr-best-practices/m-p/542964#M4400</link>
      <description>&lt;P&gt;Hi there,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have have recently started ingesting PAN NGFW logs into XDR, however they're generating a lot of incidents, for now I have excluded - prevented/terminated events, does anyone have any information on best practices, useful ways to use these?&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 21:15:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/pan-ngfw-into-xdr-best-practices/m-p/542964#M4400</guid>
      <dc:creator>PaulThomas00</dc:creator>
      <dc:date>2023-05-22T21:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: PAN NGFW into XDR best practices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/pan-ngfw-into-xdr-best-practices/m-p/543113#M4410</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/239366"&gt;@PaulThomas00&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out on LIVEcommunity!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not sure there's a best practices for NGFW logs available.&amp;nbsp; Can you tell me a little more about your issue?&amp;nbsp; I'm assuming the incidents have been investigated and determined to be false positive.&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 01:32:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/pan-ngfw-into-xdr-best-practices/m-p/543113#M4410</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2023-05-24T01:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: PAN NGFW into XDR best practices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/pan-ngfw-into-xdr-best-practices/m-p/543118#M4413</link>
      <description>&lt;P&gt;Thanks for the reply,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It may be the way the FW is configured, but currently all events are being sent to XDR including URL filtering, http traversal, suspicous DNS query, which are all prevented/blocked/terminate/detected, I can see how these events maybe useful in context of an incident, but wondering if there is any benefit from ingesting PAN NGFW events directly into XDR?&lt;BR /&gt;The result is an overwhelming number of incidents created. Just wondering the best way to manage these. Any suggestions would be appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 01:39:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/pan-ngfw-into-xdr-best-practices/m-p/543118#M4413</guid>
      <dc:creator>PaulThomas00</dc:creator>
      <dc:date>2023-05-24T01:39:36Z</dc:date>
    </item>
  </channel>
</rss>

