<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IP Address Range - Under network configurations in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ip-address-range-under-network-configurations/m-p/548157#M4690</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create a correlation rule that should identify the assets without XDR agent installed. Dataset you need is "panw_network_mapper_raw", which contain output of Network Mapper scans. You can compare this dataset with "endpoints" dataset mainly with reference to IP address. So basically, first dataset will have completed list of assets&amp;nbsp; and you can subtract assets from second dataset which are having agent installed on them.&lt;/P&gt;
&lt;P&gt;Below is an example query that you can refer and build something according to your use case.&lt;/P&gt;
&lt;P&gt;dataset = panw_network_mapper_raw &lt;BR /&gt;| filter ip not in (dataset = endpoints | arrayexpand ip_address |fields ip_address )&lt;BR /&gt;|fields ip,hostname &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Jul 2023 16:54:04 GMT</pubDate>
    <dc:creator>nsinghvirk</dc:creator>
    <dc:date>2023-07-04T16:54:04Z</dc:date>
    <item>
      <title>IP Address Range - Under network configurations</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ip-address-range-under-network-configurations/m-p/547398#M4650</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have noticed a feature in XDR console as "IP Address Range" under network configurations.&lt;/P&gt;
&lt;P&gt;- We need more details on this feature.&lt;/P&gt;
&lt;P&gt;- How this feature can we utilized?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider gm b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;- How its is usefull?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 12:18:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ip-address-range-under-network-configurations/m-p/547398#M4650</guid>
      <dc:creator>RamyashreeMada</dc:creator>
      <dc:date>2023-06-27T12:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address Range - Under network configurations</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ip-address-range-under-network-configurations/m-p/547420#M4651</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206335"&gt;@RamyashreeMada&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"IP Address Range" allow you to define various internal IP address ranges that belongs to particular department or device types. It helps Cortex XDR to track and identify assets in your network. XDR uses this information to&amp;nbsp;&lt;SPAN&gt;analyse, locate, and display assets.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Following are the few uses cases which utilise this information.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. To identify which all machines have XDR agent installed and which are remaining.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you have thousands of machines and you want to check your deployment status, you can take help from "Network Mapper" applet of Broker VM. In which you need to define the IP address range you want to scan and configure some scan parameters. Network Mapper will scan the IP address range and you can see the output data under Assets-&amp;gt;Asset Inventory. There you can apply filter for column "Has XDR Agent" and find out which machines have XDR agent installed.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Activate-the-Network-Mapper" target="_self"&gt;Activate Network Mapper&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. IP address range is also used by "Pathfinder" applet of Broker VM, which is a non persistent data collector which can collect EDR data from machines which do not have XDR agent installed for limited period of time. While activating this applet you need to define the IP address range.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Activate-Pathfinder" target="_self"&gt;Activate Pathfinder&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 13:39:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ip-address-range-under-network-configurations/m-p/547420#M4651</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2023-06-27T13:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address Range - Under network configurations</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ip-address-range-under-network-configurations/m-p/547926#M4684</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/256101"&gt;@nsinghvirk&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;do we have the possibility to get an alert, when a asset is in the client range and has no agent for one or more days?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I have seen the network configuration affects the asset inventory. But are there more possibilites, like getting alerted?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jul 2023 13:48:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ip-address-range-under-network-configurations/m-p/547926#M4684</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-07-01T13:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address Range - Under network configurations</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ip-address-range-under-network-configurations/m-p/548157#M4690</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create a correlation rule that should identify the assets without XDR agent installed. Dataset you need is "panw_network_mapper_raw", which contain output of Network Mapper scans. You can compare this dataset with "endpoints" dataset mainly with reference to IP address. So basically, first dataset will have completed list of assets&amp;nbsp; and you can subtract assets from second dataset which are having agent installed on them.&lt;/P&gt;
&lt;P&gt;Below is an example query that you can refer and build something according to your use case.&lt;/P&gt;
&lt;P&gt;dataset = panw_network_mapper_raw &lt;BR /&gt;| filter ip not in (dataset = endpoints | arrayexpand ip_address |fields ip_address )&lt;BR /&gt;|fields ip,hostname &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jul 2023 16:54:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ip-address-range-under-network-configurations/m-p/548157#M4690</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2023-07-04T16:54:04Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address Range - Under network configurations</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ip-address-range-under-network-configurations/m-p/548632#M4719</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/256101"&gt;@nsinghvirk&lt;/a&gt;: A very good explanation and a nice XQL! Thank you very much!!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 21:40:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ip-address-range-under-network-configurations/m-p/548632#M4719</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-07-07T21:40:12Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address Range - Under network configurations</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ip-address-range-under-network-configurations/m-p/549190#M4758</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider ga b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;How we can utilize this?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2023 07:12:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ip-address-range-under-network-configurations/m-p/549190#M4758</guid>
      <dc:creator>RamyashreeMada</dc:creator>
      <dc:date>2023-07-13T07:12:36Z</dc:date>
    </item>
  </channel>
</rss>

