<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Automation rule to add IP address to EDL in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automation-rule-to-add-ip-address-to-edl/m-p/584626#M6564</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Is it possible to create an automation script or rule to add a remote IP address to an EDL in Cortex XDR?&amp;nbsp; I'm exploring the best way to handle this.&amp;nbsp; For example, after the recent CVE-2024-3400 disclosure, I patched my firewalls, and all is good.&amp;nbsp; However, I still receive daily alerts for the 'Palo Alto Networks GlobalProtect OS Command Injection Vulnerability' attempts.&amp;nbsp; They are blocked and currently, I manually locate the IP address in the alert, right-click, and add it to the EDL.&amp;nbsp; The firewall then processes the updated EDL it in the next cycle.&amp;nbsp; I'm looking to automate this process to avoid repetitive manual tasks. If there’s a better solution, I'm open to suggestions.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Apr 2024 11:46:38 GMT</pubDate>
    <dc:creator>Drew-Browning</dc:creator>
    <dc:date>2024-04-23T11:46:38Z</dc:date>
    <item>
      <title>Automation rule to add IP address to EDL</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automation-rule-to-add-ip-address-to-edl/m-p/584626#M6564</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Is it possible to create an automation script or rule to add a remote IP address to an EDL in Cortex XDR?&amp;nbsp; I'm exploring the best way to handle this.&amp;nbsp; For example, after the recent CVE-2024-3400 disclosure, I patched my firewalls, and all is good.&amp;nbsp; However, I still receive daily alerts for the 'Palo Alto Networks GlobalProtect OS Command Injection Vulnerability' attempts.&amp;nbsp; They are blocked and currently, I manually locate the IP address in the alert, right-click, and add it to the EDL.&amp;nbsp; The firewall then processes the updated EDL it in the next cycle.&amp;nbsp; I'm looking to automate this process to avoid repetitive manual tasks. If there’s a better solution, I'm open to suggestions.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 11:46:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automation-rule-to-add-ip-address-to-edl/m-p/584626#M6564</guid>
      <dc:creator>Drew-Browning</dc:creator>
      <dc:date>2024-04-23T11:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: Automation rule to add IP address to EDL</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automation-rule-to-add-ip-address-to-edl/m-p/584671#M6569</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/367097609"&gt;@Drew-Browning&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is no automated action to add the IP Address from the alerts to the EDL. Maybe adding the IP to a CSV file and then uploading it a few times per day or week can be a better solution. You can upload a file containing IPs or URLs to the EDL using the &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-External-Dynamic-Lists" target="_self"&gt;Action Center&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 18:47:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automation-rule-to-add-ip-address-to-edl/m-p/584671#M6569</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-04-23T18:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: Automation rule to add IP address to EDL</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automation-rule-to-add-ip-address-to-edl/m-p/584775#M6581</link>
      <description>&lt;P&gt;I was afraid of that.&amp;nbsp; Thanks for your response.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 11:55:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automation-rule-to-add-ip-address-to-edl/m-p/584775#M6581</guid>
      <dc:creator>Drew-Browning</dc:creator>
      <dc:date>2024-04-24T11:55:15Z</dc:date>
    </item>
  </channel>
</rss>

