<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XDR Log and Quarantine Disk Space Retention in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-log-and-quarantine-disk-space-retention/m-p/596394#M7133</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192661"&gt;@bbarmanroy&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Next question is: how?&lt;/P&gt;
&lt;P&gt;In the File Quarantine Details list, or in the Incident/Alert View with a right click, there is only Restore but no (Permanently) Delete.&lt;/P&gt;
&lt;P&gt;It is not easy directly on the enpoint as well. As the file is naturally moved from its original folder and renamed with random numbers in quarantine folder, how can one know which file is the right one?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 30 Aug 2024 07:08:01 GMT</pubDate>
    <dc:creator>AbdBgc</dc:creator>
    <dc:date>2024-08-30T07:08:01Z</dc:date>
    <item>
      <title>XDR Log and Quarantine Disk Space Retention</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-log-and-quarantine-disk-space-retention/m-p/503510#M2189</link>
      <description>&lt;P&gt;Hello-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know the following details to how the product manages the retention for logs and quarantine?&lt;BR /&gt;&lt;BR /&gt;I understand you can set the log quota to a specific size.&amp;nbsp; This will leverage that on local disk.&amp;nbsp; What I am not clear on are the following items.&lt;BR /&gt;&lt;BR /&gt;What types of log data are included in this quota (some or all)?&lt;BR /&gt;How does the product "clean up" after itself?&amp;nbsp; Is it possible the local disk could become full and I would have to manually clean up or is there a mechanism to perform this maintenance automatically?&lt;BR /&gt;How about the quarantine folder?&amp;nbsp; Same type of question.&amp;nbsp; Does it clean up automatically or require manual intervention to remove the files/logs?&lt;BR /&gt;&lt;BR /&gt;Thanks in advance for sharing of your knowledge.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 13:14:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-log-and-quarantine-disk-space-retention/m-p/503510#M2189</guid>
      <dc:creator>Marc_Denman</dc:creator>
      <dc:date>2022-06-14T13:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Log and Quarantine Disk Space Retention</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-log-and-quarantine-disk-space-retention/m-p/504017#M2207</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/205611"&gt;@Marc_Denman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For your first question, you can refer to the documentation &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/customizable-agent-settings/endpoint-data-collected-by-cortex-xdr" target="_blank"&gt;here&lt;/A&gt; which lists the data that is collected by XDR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For your 2nd and 3rd question, they have been addressed earlier &lt;A href="http://&amp;nbsp;https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantine-retention-period/td-p/327764" target="_self"&gt;here.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;To add on to the response in 3rd question: the reasoning behind quarantining is to typically isolate a file and block it from being executed on the endpoints. This gives the investigation team the time to conduct their analysis to determine whether the file is benign or malicious. If the file is benign, you can manually "un-quarantine" the file. Else, the file should be removed from the endpoint as per your organization's information security policies. XDR does not delete a file from the endpoint even after quarantining as it might affect business processes etc.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 02:47:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-log-and-quarantine-disk-space-retention/m-p/504017#M2207</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-06-16T02:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Log and Quarantine Disk Space Retention</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-log-and-quarantine-disk-space-retention/m-p/596394#M7133</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192661"&gt;@bbarmanroy&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Next question is: how?&lt;/P&gt;
&lt;P&gt;In the File Quarantine Details list, or in the Incident/Alert View with a right click, there is only Restore but no (Permanently) Delete.&lt;/P&gt;
&lt;P&gt;It is not easy directly on the enpoint as well. As the file is naturally moved from its original folder and renamed with random numbers in quarantine folder, how can one know which file is the right one?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 07:08:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-log-and-quarantine-disk-space-retention/m-p/596394#M7133</guid>
      <dc:creator>AbdBgc</dc:creator>
      <dc:date>2024-08-30T07:08:01Z</dc:date>
    </item>
  </channel>
</rss>

