<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR Host based firewalls visibility in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-host-based-firewalls-visibility/m-p/1236162#M8662</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/231762"&gt;@Tyler_Wood&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I understand you want to see logs/events from your host Fw.&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Once you deploy the host firewall, use the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="guilabel"&gt;Host Firewall Events&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;table to track the enforcement events in your organization. This table provides an aggregated view of the host firewall enforcement events in your network. An enforcement event represents the number of rule hits per endpoint in 60 minutes.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;If you have Cortex XDR Pro license, you can also query the host firewall events using the new host_firewall_events dataset in XQL Search for data and network analysis.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;To collect the log file, right-click the event containing the endpoint you are interested in and select Collect Detailed Host Firewall Logs. Alternatively, you can perform this action for multiple endpoints from Endpoints Administration. So basically from the all Endpoints table, right click on the desired endpoint --&amp;gt; Endpoint Control ---&amp;gt; Collect Detailed Host Firewall Logs&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Please check the following doc for the former info and further info:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Host-firewall" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Host-firewall&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KR,&lt;/P&gt;
&lt;P&gt;Luis&lt;/P&gt;</description>
    <pubDate>Mon, 18 Aug 2025 12:37:38 GMT</pubDate>
    <dc:creator>eluis</dc:creator>
    <dc:date>2025-08-18T12:37:38Z</dc:date>
    <item>
      <title>Cortex XDR Host based firewalls visibility</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-host-based-firewalls-visibility/m-p/1236078#M8656</link>
      <description>&lt;P&gt;We have Cortex XDR Host Firewall enabled and can see rules are allowing and blocking traffic. What’s the best way to view detailed allow/deny logs? I’m not seeing all activity under host firewall&amp;nbsp;events. Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2025 16:52:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-host-based-firewalls-visibility/m-p/1236078#M8656</guid>
      <dc:creator>Tyler_Wood</dc:creator>
      <dc:date>2025-08-15T16:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Host based firewalls visibility</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-host-based-firewalls-visibility/m-p/1236162#M8662</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/231762"&gt;@Tyler_Wood&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I understand you want to see logs/events from your host Fw.&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Once you deploy the host firewall, use the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="guilabel"&gt;Host Firewall Events&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;table to track the enforcement events in your organization. This table provides an aggregated view of the host firewall enforcement events in your network. An enforcement event represents the number of rule hits per endpoint in 60 minutes.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;If you have Cortex XDR Pro license, you can also query the host firewall events using the new host_firewall_events dataset in XQL Search for data and network analysis.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;To collect the log file, right-click the event containing the endpoint you are interested in and select Collect Detailed Host Firewall Logs. Alternatively, you can perform this action for multiple endpoints from Endpoints Administration. So basically from the all Endpoints table, right click on the desired endpoint --&amp;gt; Endpoint Control ---&amp;gt; Collect Detailed Host Firewall Logs&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Please check the following doc for the former info and further info:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Host-firewall" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Host-firewall&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KR,&lt;/P&gt;
&lt;P&gt;Luis&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2025 12:37:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-host-based-firewalls-visibility/m-p/1236162#M8662</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2025-08-18T12:37:38Z</dc:date>
    </item>
  </channel>
</rss>

