<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DNS resolution was wrong for Firewall alerts in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dns-resolution-was-wrong-for-firewall-alerts/m-p/544536#M4475</link>
    <description>&lt;P&gt;Dear LIVEcommunity,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did anyone encounter problem such as hostname does not match with the IP address for alert ingested from NGFW?&lt;/P&gt;
&lt;P&gt;This is especially true when come to host that doesn't have Cortex XDR agent installed. Now, if the host cannot install with Cortex XDR agent for whatever reason, is there any way that I could improve the accuracy of the DNS resolution?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="myu06kkn_1-1685698402054.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50619iB78C83A3AFD7E09D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="myu06kkn_1-1685698402054.png" alt="myu06kkn_1-1685698402054.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Right now, I'm considering DNS server log ingestion. But I'm uncertain that it will solve the issue.&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Jun 2023 09:35:13 GMT</pubDate>
    <dc:creator>Antony_Chan</dc:creator>
    <dc:date>2023-06-02T09:35:13Z</dc:date>
    <item>
      <title>DNS resolution was wrong for Firewall alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dns-resolution-was-wrong-for-firewall-alerts/m-p/544536#M4475</link>
      <description>&lt;P&gt;Dear LIVEcommunity,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did anyone encounter problem such as hostname does not match with the IP address for alert ingested from NGFW?&lt;/P&gt;
&lt;P&gt;This is especially true when come to host that doesn't have Cortex XDR agent installed. Now, if the host cannot install with Cortex XDR agent for whatever reason, is there any way that I could improve the accuracy of the DNS resolution?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="myu06kkn_1-1685698402054.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50619iB78C83A3AFD7E09D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="myu06kkn_1-1685698402054.png" alt="myu06kkn_1-1685698402054.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Right now, I'm considering DNS server log ingestion. But I'm uncertain that it will solve the issue.&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 09:35:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dns-resolution-was-wrong-for-firewall-alerts/m-p/544536#M4475</guid>
      <dc:creator>Antony_Chan</dc:creator>
      <dc:date>2023-06-02T09:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: DNS resolution was wrong for Firewall alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dns-resolution-was-wrong-for-firewall-alerts/m-p/544860#M4493</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/202190"&gt;@Antony_Chan&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm looking into this issue and i'll get back to you as soon as I have something.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 20:56:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dns-resolution-was-wrong-for-firewall-alerts/m-p/544860#M4493</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2023-06-05T20:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: DNS resolution was wrong for Firewall alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dns-resolution-was-wrong-for-firewall-alerts/m-p/546054#M4578</link>
      <description>&lt;P&gt;Hi Myu06kkn,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;Since you have a Pro per TB license, you can ingest your Microsoft DHCP logs which will help improve this data (assuming that the endpoint in question is receiving an IP address assignment from DHCP).&amp;nbsp; These logs can be ingested with the &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Ingest-Logs-from-Windows-DHCP-using-Elasticsearch-Filebeat?tocId=JANxyCY9tIF4GTt6_GoPXQ" target="_self"&gt;XDR Collector&amp;nbsp;&lt;/A&gt;and configuring it to ingest Microsoft DHCP log files.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 16:57:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dns-resolution-was-wrong-for-firewall-alerts/m-p/546054#M4578</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2023-06-14T16:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: DNS resolution was wrong for Firewall alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dns-resolution-was-wrong-for-firewall-alerts/m-p/546101#M4581</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/219403"&gt;@afurze&lt;/a&gt;&amp;nbsp;Thanks for the input. In my case, it was static IP address that assigned to servers. So DHCP log ingestion may not be applicable. I'll keep that in mind if the same issue occurred to DHCP hosts.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 06:06:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dns-resolution-was-wrong-for-firewall-alerts/m-p/546101#M4581</guid>
      <dc:creator>Antony_Chan</dc:creator>
      <dc:date>2023-06-15T06:06:28Z</dc:date>
    </item>
  </channel>
</rss>

