<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inquiry regarding Tenant Backu &amp;amp; Recovery in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/inquiry-regarding-tenant-backu-amp-recovery/m-p/1260077#M9462</link>
    <description>&lt;DIV id=":15h" class="Am aiL Al editable LW-avf tS-tW tS-tY" tabindex="1" role="textbox" spellcheck="false" aria-expanded="false" aria-controls=":1ep" aria-owns=":1ep" aria-multiline="true" aria-label="Message Body"&gt;
&lt;DIV dir="ltr"&gt;
&lt;H1&gt;Top 5 Legitimate Crypto curr ency Rec overy Companies: Best Firm to Retrieve Stolen Dig ital A ssets, ZEUS CRYPT O REC OVERY SERVICES&amp;nbsp;&amp;nbsp;&lt;/H1&gt;
&lt;P&gt;&lt;SPAN&gt;Zeus Crypt o Re covery Services is A London-based cryptoc urre ncy recov ery firm founded in 2010 that provides bloc kch ain fore nsics, fund tra cing, and scam re cov ery ser vices. The company helps victims track and rec over sto len dig ital ass ets across wal lets such as Bit coin, Ethe reum, and Meta Mask&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Mon, 27 Jul 2026 22:47:20 GMT</pubDate>
    <dc:creator>zhiqiangweilong</dc:creator>
    <dc:date>2026-07-27T22:47:20Z</dc:date>
    <item>
      <title>Inquiry regarding Tenant Backu &amp; Recovery</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/inquiry-regarding-tenant-backu-amp-recovery/m-p/1248155#M9129</link>
      <description>&lt;P data-path-to-node="5"&gt;I am looking for detailed information regarding the backup and recovery lifecycle for a Cortex XDR tenant. Specifically, I have the following questions:&lt;/P&gt;
&lt;OL start="1" data-path-to-node="6"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="6,0,0"&gt;&lt;STRONG data-path-to-node="6,0,0" data-index-in-node="0"&gt;Automated Backups:&lt;/STRONG&gt; Does Palo Alto Networks perform regular backups of tenant-specific configurations (Security Policies, Profiles, XQL queries, etc.)? If so, what is the standard frequency?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="6,1,0"&gt;&lt;STRONG data-path-to-node="6,1,0" data-index-in-node="0"&gt;Restoration Requests:&lt;/STRONG&gt; In the event of an accidental configuration loss, is it possible to request a restoration of a previous backup through support? What is the standard procedure and the expected Lead Time for such a request?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="6,2,0"&gt;&lt;STRONG data-path-to-node="6,2,0" data-index-in-node="0"&gt;Self-Service Rollback:&lt;/STRONG&gt; Does the platform currently offer any "Undo" or "Rollback" features for administrative changes, or are we reliant on manual reconstruction via Audit Logs?&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-path-to-node="7"&gt;Thank you in advance for your insights!&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2026 18:44:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/inquiry-regarding-tenant-backu-amp-recovery/m-p/1248155#M9129</guid>
      <dc:creator>R.Abdeen</dc:creator>
      <dc:date>2026-02-13T18:44:12Z</dc:date>
    </item>
    <item>
      <title>Re: Inquiry regarding Tenant Backu &amp; Recovery</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/inquiry-regarding-tenant-backu-amp-recovery/m-p/1248288#M9135</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1018431639"&gt;@R.Abdeen&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="105" data-end="328"&gt;The Cortex XDR platform is a fully managed cloud Software-as-a-Service (SaaS) solution. Consequently, Palo Alto Networks manages the backend infrastructure, including regular system backups and disaster recovery procedures.&lt;/P&gt;
&lt;H5 data-start="335" data-end="369"&gt;Automated Backups and Frequency:&lt;/H5&gt;
&lt;P data-start="371" data-end="500"&gt;Palo Alto Networks performs regular internal snapshots and system-level backups to ensure platform resilience and data integrity.&lt;/P&gt;
&lt;P data-start="371" data-end="500"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5 data-start="502" data-end="531"&gt;Standard Recovery Metrics:&lt;/H5&gt;
&lt;P data-start="533" data-end="707"&gt;While the internal snapshot interval is not publicly defined as a specific hourly or daily schedule in technical documentation, the system adheres to strict recovery metrics:&lt;/P&gt;
&lt;UL data-start="709" data-end="864"&gt;
&lt;LI data-start="709" data-end="756"&gt;
&lt;P data-start="711" data-end="756"&gt;&lt;STRONG data-start="711" data-end="746"&gt;Recovery Point Objective (RPO):&lt;/STRONG&gt; 4 hours&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="757" data-end="803"&gt;
&lt;P data-start="759" data-end="803"&gt;&lt;STRONG data-start="759" data-end="793"&gt;Recovery Time Objective (RTO):&lt;/STRONG&gt; 4 hours&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="804" data-end="864"&gt;
&lt;P data-start="806" data-end="864"&gt;&lt;STRONG data-start="806" data-end="831"&gt;Service Availability:&lt;/STRONG&gt; 99.9% monthly uptime objective&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-start="871" data-end="894"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 data-start="871" data-end="894"&gt;Restoration Requests:&lt;/H4&gt;
&lt;P data-start="896" data-end="1051"&gt;The platform does not provide a customer-facing "point-in-time" restoration tool for reverting an entire tenant configuration due to administrative errors.&lt;/P&gt;
&lt;P data-start="896" data-end="1051"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-start="1058" data-end="1085"&gt;Limited Data Restoration:&lt;/H4&gt;
&lt;P data-start="1087" data-end="1260"&gt;If specific critical components like Indicators of Compromise (IOCs) or BIOC rules are accidentally deleted, a limited restoration may be possible through a support request.&lt;/P&gt;
&lt;H4 data-start="1262" data-end="1275"&gt;Procedure&lt;/H4&gt;
&lt;UL data-start="1277" data-end="1500"&gt;
&lt;LI data-start="1277" data-end="1382"&gt;
&lt;P data-start="1279" data-end="1382"&gt;The customer must provide the exact date and time of the deletion and the specific restoration point.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1383" data-end="1500"&gt;
&lt;P data-start="1385" data-end="1500"&gt;TAC engineers will open a JIRA ticket to the Engineering/DevOps team to request a data merge from database backups.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-start="1502" data-end="1524"&gt;Expected Lead Time&lt;/H4&gt;
&lt;UL data-start="1526" data-end="1647"&gt;
&lt;LI data-start="1526" data-end="1647"&gt;
&lt;P data-start="1528" data-end="1647"&gt;These manual data merges are typically performed during the next available maintenance window, commonly Sunday evening.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-start="1649" data-end="1652" /&gt;
&lt;H4 data-start="1654" data-end="1693"&gt;Self-Service Rollback and Management:&lt;/H4&gt;
&lt;P data-start="1695" data-end="1831"&gt;There is currently no native "Undo," "Checkpoint," or "Recycle Bin" feature for administrative configuration changes within the console.&lt;/P&gt;
&lt;HR data-start="1833" data-end="1836" /&gt;
&lt;H4 data-start="1838" data-end="1877"&gt;Change Reconstruction via Audit Logs:&lt;/H4&gt;
&lt;P data-start="1879" data-end="1975"&gt;Administrators must rely on &lt;STRONG data-start="1907" data-end="1932"&gt;Management Audit Logs&lt;/STRONG&gt; to track modifications. These logs record:&lt;/P&gt;
&lt;UL data-start="1977" data-end="2095"&gt;
&lt;LI data-start="1977" data-end="2023"&gt;
&lt;P data-start="1979" data-end="2023"&gt;What configuration was modified or deleted&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2024" data-end="2055"&gt;
&lt;P data-start="2026" data-end="2055"&gt;The timestamp of the change&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2056" data-end="2095"&gt;
&lt;P data-start="2058" data-end="2095"&gt;The user attribution for the action&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-start="2097" data-end="2100" /&gt;
&lt;H4 data-start="2102" data-end="2137"&gt;Best Practices for Manual Backup:&lt;/H4&gt;
&lt;P data-start="2139" data-end="2270"&gt;To mitigate accidental losses, Palo Alto Networks recommends a proactive manual backup strategy for security policies and profiles.&lt;/P&gt;
&lt;H4 data-start="2272" data-end="2292"&gt;1. Manual Export&lt;/H4&gt;
&lt;P data-start="2294" data-end="2368"&gt;Periodically export Prevention Profiles and Policy Rules from the console:&lt;/P&gt;
&lt;UL data-start="2370" data-end="2549"&gt;
&lt;LI data-start="2370" data-end="2466"&gt;
&lt;P data-start="2372" data-end="2466"&gt;Navigate to:&lt;BR data-start="2384" data-end="2387" /&gt;&lt;STRONG data-start="2389" data-end="2464"&gt;Endpoints → Policy Management → Prevention → Profiles (or Policy Rules)&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2467" data-end="2549"&gt;
&lt;P data-start="2469" data-end="2549"&gt;Right-click the desired items and select &lt;STRONG data-start="2510" data-end="2528"&gt;Export Profile&lt;/STRONG&gt; or &lt;STRONG data-start="2532" data-end="2549"&gt;Export Policy&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-start="2551" data-end="2569"&gt;2. Restoration&lt;/H4&gt;
&lt;P data-start="2571" data-end="2646"&gt;Re-import these Base64-encoded files to manually revert settings if needed:&lt;/P&gt;
&lt;UL data-start="2648" data-end="2760"&gt;
&lt;LI data-start="2648" data-end="2730"&gt;
&lt;P data-start="2650" data-end="2730"&gt;Navigate to:&lt;BR data-start="2662" data-end="2665" /&gt;&lt;STRONG data-start="2667" data-end="2728"&gt;Endpoints → Policy Management → Prevention → Policy Rules&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2731" data-end="2760"&gt;
&lt;P data-start="2733" data-end="2760"&gt;Select &lt;STRONG data-start="2740" data-end="2760"&gt;Import from File&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-start="2762" data-end="2765" /&gt;
&lt;H4 data-start="2767" data-end="2788"&gt;API and Automation&lt;/H4&gt;
&lt;P data-start="2790" data-end="2897"&gt;There is currently no documented native API-based method for automated configuration backups or versioning.&lt;/P&gt;
&lt;P data-start="2899" data-end="3077"&gt;While APIs can be used to extract alerts and incidents, configuration objects such as security profiles are not currently supported for automated backup via public API endpoints.&lt;/P&gt;
&lt;P data-start="3079" data-end="3153"&gt;A feature request (CXDR-I-1916) exists for a comprehensive backup utility.&lt;/P&gt;
&lt;HR data-start="3155" data-end="3158" /&gt;
&lt;H4 data-start="3160" data-end="3185"&gt;Additional Information&lt;/H4&gt;
&lt;P data-start="3187" data-end="3319"&gt;For formal documentation regarding disaster recovery plans or contractual SLAs, please contact your Palo Alto Networks Account Team.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Mon, 16 Feb 2026 18:02:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/inquiry-regarding-tenant-backu-amp-recovery/m-p/1248288#M9135</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-02-16T18:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: Inquiry regarding Tenant Backu &amp; Recovery</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/inquiry-regarding-tenant-backu-amp-recovery/m-p/1260077#M9462</link>
      <description>&lt;DIV id=":15h" class="Am aiL Al editable LW-avf tS-tW tS-tY" tabindex="1" role="textbox" spellcheck="false" aria-expanded="false" aria-controls=":1ep" aria-owns=":1ep" aria-multiline="true" aria-label="Message Body"&gt;
&lt;DIV dir="ltr"&gt;
&lt;H1&gt;Top 5 Legitimate Crypto curr ency Rec overy Companies: Best Firm to Retrieve Stolen Dig ital A ssets, ZEUS CRYPT O REC OVERY SERVICES&amp;nbsp;&amp;nbsp;&lt;/H1&gt;
&lt;P&gt;&lt;SPAN&gt;Zeus Crypt o Re covery Services is A London-based cryptoc urre ncy recov ery firm founded in 2010 that provides bloc kch ain fore nsics, fund tra cing, and scam re cov ery ser vices. The company helps victims track and rec over sto len dig ital ass ets across wal lets such as Bit coin, Ethe reum, and Meta Mask&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 27 Jul 2026 22:47:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/inquiry-regarding-tenant-backu-amp-recovery/m-p/1260077#M9462</guid>
      <dc:creator>zhiqiangweilong</dc:creator>
      <dc:date>2026-07-27T22:47:20Z</dc:date>
    </item>
  </channel>
</rss>

