<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inquiry regarding Tenant Backu &amp;amp; Recovery in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/inquiry-regarding-tenant-backu-amp-recovery/m-p/1248288#M9135</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1018431639"&gt;@R.Abdeen&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="105" data-end="328"&gt;The Cortex XDR platform is a fully managed cloud Software-as-a-Service (SaaS) solution. Consequently, Palo Alto Networks manages the backend infrastructure, including regular system backups and disaster recovery procedures.&lt;/P&gt;
&lt;H5 data-start="335" data-end="369"&gt;Automated Backups and Frequency:&lt;/H5&gt;
&lt;P data-start="371" data-end="500"&gt;Palo Alto Networks performs regular internal snapshots and system-level backups to ensure platform resilience and data integrity.&lt;/P&gt;
&lt;P data-start="371" data-end="500"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5 data-start="502" data-end="531"&gt;Standard Recovery Metrics:&lt;/H5&gt;
&lt;P data-start="533" data-end="707"&gt;While the internal snapshot interval is not publicly defined as a specific hourly or daily schedule in technical documentation, the system adheres to strict recovery metrics:&lt;/P&gt;
&lt;UL data-start="709" data-end="864"&gt;
&lt;LI data-start="709" data-end="756"&gt;
&lt;P data-start="711" data-end="756"&gt;&lt;STRONG data-start="711" data-end="746"&gt;Recovery Point Objective (RPO):&lt;/STRONG&gt; 4 hours&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="757" data-end="803"&gt;
&lt;P data-start="759" data-end="803"&gt;&lt;STRONG data-start="759" data-end="793"&gt;Recovery Time Objective (RTO):&lt;/STRONG&gt; 4 hours&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="804" data-end="864"&gt;
&lt;P data-start="806" data-end="864"&gt;&lt;STRONG data-start="806" data-end="831"&gt;Service Availability:&lt;/STRONG&gt; 99.9% monthly uptime objective&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-start="871" data-end="894"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 data-start="871" data-end="894"&gt;Restoration Requests:&lt;/H4&gt;
&lt;P data-start="896" data-end="1051"&gt;The platform does not provide a customer-facing "point-in-time" restoration tool for reverting an entire tenant configuration due to administrative errors.&lt;/P&gt;
&lt;P data-start="896" data-end="1051"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-start="1058" data-end="1085"&gt;Limited Data Restoration:&lt;/H4&gt;
&lt;P data-start="1087" data-end="1260"&gt;If specific critical components like Indicators of Compromise (IOCs) or BIOC rules are accidentally deleted, a limited restoration may be possible through a support request.&lt;/P&gt;
&lt;H4 data-start="1262" data-end="1275"&gt;Procedure&lt;/H4&gt;
&lt;UL data-start="1277" data-end="1500"&gt;
&lt;LI data-start="1277" data-end="1382"&gt;
&lt;P data-start="1279" data-end="1382"&gt;The customer must provide the exact date and time of the deletion and the specific restoration point.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1383" data-end="1500"&gt;
&lt;P data-start="1385" data-end="1500"&gt;TAC engineers will open a JIRA ticket to the Engineering/DevOps team to request a data merge from database backups.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-start="1502" data-end="1524"&gt;Expected Lead Time&lt;/H4&gt;
&lt;UL data-start="1526" data-end="1647"&gt;
&lt;LI data-start="1526" data-end="1647"&gt;
&lt;P data-start="1528" data-end="1647"&gt;These manual data merges are typically performed during the next available maintenance window, commonly Sunday evening.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-start="1649" data-end="1652" /&gt;
&lt;H4 data-start="1654" data-end="1693"&gt;Self-Service Rollback and Management:&lt;/H4&gt;
&lt;P data-start="1695" data-end="1831"&gt;There is currently no native "Undo," "Checkpoint," or "Recycle Bin" feature for administrative configuration changes within the console.&lt;/P&gt;
&lt;HR data-start="1833" data-end="1836" /&gt;
&lt;H4 data-start="1838" data-end="1877"&gt;Change Reconstruction via Audit Logs:&lt;/H4&gt;
&lt;P data-start="1879" data-end="1975"&gt;Administrators must rely on &lt;STRONG data-start="1907" data-end="1932"&gt;Management Audit Logs&lt;/STRONG&gt; to track modifications. These logs record:&lt;/P&gt;
&lt;UL data-start="1977" data-end="2095"&gt;
&lt;LI data-start="1977" data-end="2023"&gt;
&lt;P data-start="1979" data-end="2023"&gt;What configuration was modified or deleted&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2024" data-end="2055"&gt;
&lt;P data-start="2026" data-end="2055"&gt;The timestamp of the change&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2056" data-end="2095"&gt;
&lt;P data-start="2058" data-end="2095"&gt;The user attribution for the action&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-start="2097" data-end="2100" /&gt;
&lt;H4 data-start="2102" data-end="2137"&gt;Best Practices for Manual Backup:&lt;/H4&gt;
&lt;P data-start="2139" data-end="2270"&gt;To mitigate accidental losses, Palo Alto Networks recommends a proactive manual backup strategy for security policies and profiles.&lt;/P&gt;
&lt;H4 data-start="2272" data-end="2292"&gt;1. Manual Export&lt;/H4&gt;
&lt;P data-start="2294" data-end="2368"&gt;Periodically export Prevention Profiles and Policy Rules from the console:&lt;/P&gt;
&lt;UL data-start="2370" data-end="2549"&gt;
&lt;LI data-start="2370" data-end="2466"&gt;
&lt;P data-start="2372" data-end="2466"&gt;Navigate to:&lt;BR data-start="2384" data-end="2387" /&gt;&lt;STRONG data-start="2389" data-end="2464"&gt;Endpoints → Policy Management → Prevention → Profiles (or Policy Rules)&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2467" data-end="2549"&gt;
&lt;P data-start="2469" data-end="2549"&gt;Right-click the desired items and select &lt;STRONG data-start="2510" data-end="2528"&gt;Export Profile&lt;/STRONG&gt; or &lt;STRONG data-start="2532" data-end="2549"&gt;Export Policy&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-start="2551" data-end="2569"&gt;2. Restoration&lt;/H4&gt;
&lt;P data-start="2571" data-end="2646"&gt;Re-import these Base64-encoded files to manually revert settings if needed:&lt;/P&gt;
&lt;UL data-start="2648" data-end="2760"&gt;
&lt;LI data-start="2648" data-end="2730"&gt;
&lt;P data-start="2650" data-end="2730"&gt;Navigate to:&lt;BR data-start="2662" data-end="2665" /&gt;&lt;STRONG data-start="2667" data-end="2728"&gt;Endpoints → Policy Management → Prevention → Policy Rules&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2731" data-end="2760"&gt;
&lt;P data-start="2733" data-end="2760"&gt;Select &lt;STRONG data-start="2740" data-end="2760"&gt;Import from File&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-start="2762" data-end="2765" /&gt;
&lt;H4 data-start="2767" data-end="2788"&gt;API and Automation&lt;/H4&gt;
&lt;P data-start="2790" data-end="2897"&gt;There is currently no documented native API-based method for automated configuration backups or versioning.&lt;/P&gt;
&lt;P data-start="2899" data-end="3077"&gt;While APIs can be used to extract alerts and incidents, configuration objects such as security profiles are not currently supported for automated backup via public API endpoints.&lt;/P&gt;
&lt;P data-start="3079" data-end="3153"&gt;A feature request (CXDR-I-1916) exists for a comprehensive backup utility.&lt;/P&gt;
&lt;HR data-start="3155" data-end="3158" /&gt;
&lt;H4 data-start="3160" data-end="3185"&gt;Additional Information&lt;/H4&gt;
&lt;P data-start="3187" data-end="3319"&gt;For formal documentation regarding disaster recovery plans or contractual SLAs, please contact your Palo Alto Networks Account Team.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
    <pubDate>Mon, 16 Feb 2026 18:02:09 GMT</pubDate>
    <dc:creator>susekar</dc:creator>
    <dc:date>2026-02-16T18:02:09Z</dc:date>
    <item>
      <title>Inquiry regarding Tenant Backu &amp; Recovery</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/inquiry-regarding-tenant-backu-amp-recovery/m-p/1248155#M9129</link>
      <description>&lt;P data-path-to-node="5"&gt;I am looking for detailed information regarding the backup and recovery lifecycle for a Cortex XDR tenant. Specifically, I have the following questions:&lt;/P&gt;
&lt;OL start="1" data-path-to-node="6"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="6,0,0"&gt;&lt;STRONG data-path-to-node="6,0,0" data-index-in-node="0"&gt;Automated Backups:&lt;/STRONG&gt; Does Palo Alto Networks perform regular backups of tenant-specific configurations (Security Policies, Profiles, XQL queries, etc.)? If so, what is the standard frequency?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="6,1,0"&gt;&lt;STRONG data-path-to-node="6,1,0" data-index-in-node="0"&gt;Restoration Requests:&lt;/STRONG&gt; In the event of an accidental configuration loss, is it possible to request a restoration of a previous backup through support? What is the standard procedure and the expected Lead Time for such a request?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="6,2,0"&gt;&lt;STRONG data-path-to-node="6,2,0" data-index-in-node="0"&gt;Self-Service Rollback:&lt;/STRONG&gt; Does the platform currently offer any "Undo" or "Rollback" features for administrative changes, or are we reliant on manual reconstruction via Audit Logs?&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-path-to-node="7"&gt;Thank you in advance for your insights!&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2026 18:44:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/inquiry-regarding-tenant-backu-amp-recovery/m-p/1248155#M9129</guid>
      <dc:creator>R.Abdeen</dc:creator>
      <dc:date>2026-02-13T18:44:12Z</dc:date>
    </item>
    <item>
      <title>Re: Inquiry regarding Tenant Backu &amp; Recovery</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/inquiry-regarding-tenant-backu-amp-recovery/m-p/1248288#M9135</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1018431639"&gt;@R.Abdeen&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="105" data-end="328"&gt;The Cortex XDR platform is a fully managed cloud Software-as-a-Service (SaaS) solution. Consequently, Palo Alto Networks manages the backend infrastructure, including regular system backups and disaster recovery procedures.&lt;/P&gt;
&lt;H5 data-start="335" data-end="369"&gt;Automated Backups and Frequency:&lt;/H5&gt;
&lt;P data-start="371" data-end="500"&gt;Palo Alto Networks performs regular internal snapshots and system-level backups to ensure platform resilience and data integrity.&lt;/P&gt;
&lt;P data-start="371" data-end="500"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5 data-start="502" data-end="531"&gt;Standard Recovery Metrics:&lt;/H5&gt;
&lt;P data-start="533" data-end="707"&gt;While the internal snapshot interval is not publicly defined as a specific hourly or daily schedule in technical documentation, the system adheres to strict recovery metrics:&lt;/P&gt;
&lt;UL data-start="709" data-end="864"&gt;
&lt;LI data-start="709" data-end="756"&gt;
&lt;P data-start="711" data-end="756"&gt;&lt;STRONG data-start="711" data-end="746"&gt;Recovery Point Objective (RPO):&lt;/STRONG&gt; 4 hours&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="757" data-end="803"&gt;
&lt;P data-start="759" data-end="803"&gt;&lt;STRONG data-start="759" data-end="793"&gt;Recovery Time Objective (RTO):&lt;/STRONG&gt; 4 hours&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="804" data-end="864"&gt;
&lt;P data-start="806" data-end="864"&gt;&lt;STRONG data-start="806" data-end="831"&gt;Service Availability:&lt;/STRONG&gt; 99.9% monthly uptime objective&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-start="871" data-end="894"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 data-start="871" data-end="894"&gt;Restoration Requests:&lt;/H4&gt;
&lt;P data-start="896" data-end="1051"&gt;The platform does not provide a customer-facing "point-in-time" restoration tool for reverting an entire tenant configuration due to administrative errors.&lt;/P&gt;
&lt;P data-start="896" data-end="1051"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-start="1058" data-end="1085"&gt;Limited Data Restoration:&lt;/H4&gt;
&lt;P data-start="1087" data-end="1260"&gt;If specific critical components like Indicators of Compromise (IOCs) or BIOC rules are accidentally deleted, a limited restoration may be possible through a support request.&lt;/P&gt;
&lt;H4 data-start="1262" data-end="1275"&gt;Procedure&lt;/H4&gt;
&lt;UL data-start="1277" data-end="1500"&gt;
&lt;LI data-start="1277" data-end="1382"&gt;
&lt;P data-start="1279" data-end="1382"&gt;The customer must provide the exact date and time of the deletion and the specific restoration point.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1383" data-end="1500"&gt;
&lt;P data-start="1385" data-end="1500"&gt;TAC engineers will open a JIRA ticket to the Engineering/DevOps team to request a data merge from database backups.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-start="1502" data-end="1524"&gt;Expected Lead Time&lt;/H4&gt;
&lt;UL data-start="1526" data-end="1647"&gt;
&lt;LI data-start="1526" data-end="1647"&gt;
&lt;P data-start="1528" data-end="1647"&gt;These manual data merges are typically performed during the next available maintenance window, commonly Sunday evening.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-start="1649" data-end="1652" /&gt;
&lt;H4 data-start="1654" data-end="1693"&gt;Self-Service Rollback and Management:&lt;/H4&gt;
&lt;P data-start="1695" data-end="1831"&gt;There is currently no native "Undo," "Checkpoint," or "Recycle Bin" feature for administrative configuration changes within the console.&lt;/P&gt;
&lt;HR data-start="1833" data-end="1836" /&gt;
&lt;H4 data-start="1838" data-end="1877"&gt;Change Reconstruction via Audit Logs:&lt;/H4&gt;
&lt;P data-start="1879" data-end="1975"&gt;Administrators must rely on &lt;STRONG data-start="1907" data-end="1932"&gt;Management Audit Logs&lt;/STRONG&gt; to track modifications. These logs record:&lt;/P&gt;
&lt;UL data-start="1977" data-end="2095"&gt;
&lt;LI data-start="1977" data-end="2023"&gt;
&lt;P data-start="1979" data-end="2023"&gt;What configuration was modified or deleted&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2024" data-end="2055"&gt;
&lt;P data-start="2026" data-end="2055"&gt;The timestamp of the change&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2056" data-end="2095"&gt;
&lt;P data-start="2058" data-end="2095"&gt;The user attribution for the action&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-start="2097" data-end="2100" /&gt;
&lt;H4 data-start="2102" data-end="2137"&gt;Best Practices for Manual Backup:&lt;/H4&gt;
&lt;P data-start="2139" data-end="2270"&gt;To mitigate accidental losses, Palo Alto Networks recommends a proactive manual backup strategy for security policies and profiles.&lt;/P&gt;
&lt;H4 data-start="2272" data-end="2292"&gt;1. Manual Export&lt;/H4&gt;
&lt;P data-start="2294" data-end="2368"&gt;Periodically export Prevention Profiles and Policy Rules from the console:&lt;/P&gt;
&lt;UL data-start="2370" data-end="2549"&gt;
&lt;LI data-start="2370" data-end="2466"&gt;
&lt;P data-start="2372" data-end="2466"&gt;Navigate to:&lt;BR data-start="2384" data-end="2387" /&gt;&lt;STRONG data-start="2389" data-end="2464"&gt;Endpoints → Policy Management → Prevention → Profiles (or Policy Rules)&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2467" data-end="2549"&gt;
&lt;P data-start="2469" data-end="2549"&gt;Right-click the desired items and select &lt;STRONG data-start="2510" data-end="2528"&gt;Export Profile&lt;/STRONG&gt; or &lt;STRONG data-start="2532" data-end="2549"&gt;Export Policy&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-start="2551" data-end="2569"&gt;2. Restoration&lt;/H4&gt;
&lt;P data-start="2571" data-end="2646"&gt;Re-import these Base64-encoded files to manually revert settings if needed:&lt;/P&gt;
&lt;UL data-start="2648" data-end="2760"&gt;
&lt;LI data-start="2648" data-end="2730"&gt;
&lt;P data-start="2650" data-end="2730"&gt;Navigate to:&lt;BR data-start="2662" data-end="2665" /&gt;&lt;STRONG data-start="2667" data-end="2728"&gt;Endpoints → Policy Management → Prevention → Policy Rules&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2731" data-end="2760"&gt;
&lt;P data-start="2733" data-end="2760"&gt;Select &lt;STRONG data-start="2740" data-end="2760"&gt;Import from File&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-start="2762" data-end="2765" /&gt;
&lt;H4 data-start="2767" data-end="2788"&gt;API and Automation&lt;/H4&gt;
&lt;P data-start="2790" data-end="2897"&gt;There is currently no documented native API-based method for automated configuration backups or versioning.&lt;/P&gt;
&lt;P data-start="2899" data-end="3077"&gt;While APIs can be used to extract alerts and incidents, configuration objects such as security profiles are not currently supported for automated backup via public API endpoints.&lt;/P&gt;
&lt;P data-start="3079" data-end="3153"&gt;A feature request (CXDR-I-1916) exists for a comprehensive backup utility.&lt;/P&gt;
&lt;HR data-start="3155" data-end="3158" /&gt;
&lt;H4 data-start="3160" data-end="3185"&gt;Additional Information&lt;/H4&gt;
&lt;P data-start="3187" data-end="3319"&gt;For formal documentation regarding disaster recovery plans or contractual SLAs, please contact your Palo Alto Networks Account Team.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Mon, 16 Feb 2026 18:02:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/inquiry-regarding-tenant-backu-amp-recovery/m-p/1248288#M9135</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-02-16T18:02:09Z</dc:date>
    </item>
  </channel>
</rss>

