<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Automatic retrive alert data on VDI XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-retrive-alert-data-on-vdi-xdr/m-p/581885#M6424</link>
    <description>&lt;P&gt;Hello, &lt;BR /&gt;In my company, we have many non-persistent VDIs, and sometimes an alert arises and I couldn't perform the 'Retrieve alert data' because when i see alert the user has already logged out of the VDI.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;My question is, is it possible in the &lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;Tenant create an automatic rule so that in the case of the machine being a VDI or being in a specific group, it automatically performs the 'retrieve alert data' for the tenant?&lt;/P&gt;</description>
    <pubDate>Wed, 27 Mar 2024 14:29:33 GMT</pubDate>
    <dc:creator>tlmarques</dc:creator>
    <dc:date>2024-03-27T14:29:33Z</dc:date>
    <item>
      <title>Automatic retrive alert data on VDI XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-retrive-alert-data-on-vdi-xdr/m-p/581885#M6424</link>
      <description>&lt;P&gt;Hello, &lt;BR /&gt;In my company, we have many non-persistent VDIs, and sometimes an alert arises and I couldn't perform the 'Retrieve alert data' because when i see alert the user has already logged out of the VDI.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;My question is, is it possible in the &lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;Tenant create an automatic rule so that in the case of the machine being a VDI or being in a specific group, it automatically performs the 'retrieve alert data' for the tenant?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 14:29:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-retrive-alert-data-on-vdi-xdr/m-p/581885#M6424</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-03-27T14:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic retrive alert data on VDI XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-retrive-alert-data-on-vdi-xdr/m-p/581904#M6427</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Technically, VDI instances should ideally not generate alerts as they may have been segregated and fine tuned during the &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.7/Cortex-XDR-Agent-Administrator-Guide/Cortex-XDR-Agent-for-Virtual-Environments-and-Desktops" target="_blank" rel="noopener"&gt;agent deployment&lt;/A&gt; when the golden images are scanned. As a result, the VDI images are meant to be provisioned clean so that the same FP does not affect the entire production environment. However, as you cited, there are always corner cases.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In occurences of such situations, you can configure your policy rules for VDI instances(I am assuming you may have separate policy for them as we always recommend a slightly different setting for VDI subgroups), to automatically upload alert data upon alert triggers. Though it is highly subjective to how much time does the user give for the endpoint to be online so that the dump is uploaded, but from Cortex XDR agent side this is very much possible.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The agent settings profile allows you to configure automatic upload of alert data and also choose the size of the dump that you want to upload to the cloud. Considering VDI instances are mostly clean and are meant to behave the same way, an alert spinning up on a VDI instance alert can possibly come across all devices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a result, you should be able to capture from atleast one of the endpoints automatically.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To enable, go to XDR prevention profiles &amp;gt; agent settings&amp;gt; Alerts data.&lt;BR /&gt;You can choose the size of alert data dump and then enable "Automatically Upload Alert Data Dump File".&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;This should initiate alert dump to be automatically uploaded to the cloud and you should be able to download it next time you navigate to alerts&amp;gt; Retrieve Alert Data&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-03-28 at 12.04.54 AM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58705i607B8FB37E4B6B25/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2024-03-28 at 12.04.54 AM.png" alt="Screenshot 2024-03-28 at 12.04.54 AM.png" /&gt;&lt;/span&gt;&lt;BR /&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please feel free to mark the response as "Accept as Solution" if it answers your query&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 16:10:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-retrive-alert-data-on-vdi-xdr/m-p/581904#M6427</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2024-03-27T16:10:28Z</dc:date>
    </item>
  </channel>
</rss>

