<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitor and Collect Enhanced Endpoint Data in XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/monitor-and-collect-enhanced-endpoint-data-in-xdr/m-p/588550#M6781</link>
    <description>&lt;P&gt;Many thanks for taking the time to respond and helping to clarify CDL / Strata logging service.&lt;/P&gt;</description>
    <pubDate>Sun, 02 Jun 2024 23:28:19 GMT</pubDate>
    <dc:creator>DannyMulheran</dc:creator>
    <dc:date>2024-06-02T23:28:19Z</dc:date>
    <item>
      <title>Monitor and Collect Enhanced Endpoint Data in XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/monitor-and-collect-enhanced-endpoint-data-in-xdr/m-p/586431#M6660</link>
      <description>&lt;P&gt;&lt;SPAN class="ng-star-inserted"&gt;When setting the Agent profile in Cortex XDR, Under the check box when enabling "Monitor and Collect Enhanced Endpoint Data" is the following note:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="ng-star-inserted"&gt;Note: Before enabling enhanced endpoint data collection make sure your Strata Logging Service storage capacity and quota allocation can support it. Please refer to the &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVMCA0" target="_blank" rel="noopener"&gt;Strata Logging Service quota configuration&lt;/A&gt; guidelines and &lt;A href="https://apps.paloaltonetworks.com/logging-service-calculator" target="_blank" rel="noopener"&gt;storage calculator&lt;/A&gt; for more details.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="ng-star-inserted"&gt;Can anyone tell me how to do this for a Cortex XDR enviroment. I did not find the documention provided any clarity (although I probably missed something!)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="ng-star-inserted"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="ng-star-inserted"&gt;Danny&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 00:34:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/monitor-and-collect-enhanced-endpoint-data-in-xdr/m-p/586431#M6660</guid>
      <dc:creator>DannyMulheran</dc:creator>
      <dc:date>2024-05-13T00:34:48Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor and Collect Enhanced Endpoint Data in XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/monitor-and-collect-enhanced-endpoint-data-in-xdr/m-p/587930#M6734</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/150849"&gt;@DannyMulheran&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The information provided below refers to the use case for customers who have Cortex XDR Pro Per GB license and Strata Logging service as part of their native data lake licensing. In the old cases, customers would have an option to setup a quota of cortex xdr agent logs and alert logs as a use case.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, with the advent of new data retention and licensing changes, this does not apply for customers who are not on the native data lake licenses(new/existing customers who have purchased/renewed after December, 2022). Example screenshot below:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="neelrohit_3-1716703083651.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60046iC2AD249218C0F395/image-size/large?v=v2&amp;amp;px=999" role="button" title="neelrohit_3-1716703083651.png" alt="neelrohit_3-1716703083651.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, if you go to the current configurations for Strata Logging Service, this field is not applicable anymore because the Cortex Endpoint storage and Endpoint alerts data storage, though one is still separate and is managed as per the default retention policy or your retention licenses procured.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps! Please mark the response as "Accept as Solution" if this helps&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 May 2024 05:58:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/monitor-and-collect-enhanced-endpoint-data-in-xdr/m-p/587930#M6734</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2024-05-26T05:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor and Collect Enhanced Endpoint Data in XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/monitor-and-collect-enhanced-endpoint-data-in-xdr/m-p/588550#M6781</link>
      <description>&lt;P&gt;Many thanks for taking the time to respond and helping to clarify CDL / Strata logging service.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jun 2024 23:28:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/monitor-and-collect-enhanced-endpoint-data-in-xdr/m-p/588550#M6781</guid>
      <dc:creator>DannyMulheran</dc:creator>
      <dc:date>2024-06-02T23:28:19Z</dc:date>
    </item>
  </channel>
</rss>

