<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rogue Device Discovery with Cortex XDR in Strata Logging Service Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/strata-logging-service/rogue-device-discovery-with-cortex-xdr/m-p/562933#M27</link>
    <description>&lt;P&gt;Thank you for your reply,&lt;/P&gt;
&lt;P&gt;Just two additional questions:&lt;/P&gt;
&lt;P&gt;1. Is Cortex Data Lake license required for this? I can see it on the Broker VM diagram so I just want to make sure this won't be a problem.&lt;/P&gt;
&lt;P&gt;2. Does the discovery scan runs on the Broker VM (what would require the server to have access to all network segments) or on Cortex XDR agents - what would make sure all devices are discovered?&lt;/P&gt;</description>
    <pubDate>Tue, 24 Oct 2023 13:26:41 GMT</pubDate>
    <dc:creator>Piotr_Kowalczyk</dc:creator>
    <dc:date>2023-10-24T13:26:41Z</dc:date>
    <item>
      <title>Rogue Device Discovery with Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/strata-logging-service/rogue-device-discovery-with-cortex-xdr/m-p/562754#M25</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I would like to implement Rogue Device Discovery with Cortex XDR but it is not clear for me what I need to do this. We have Cortex XDR Pro per Endpoint license – do I need anything else (like datalike) to set the solution? Can I expect any issues with it or it is working well?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 18:43:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-logging-service/rogue-device-discovery-with-cortex-xdr/m-p/562754#M25</guid>
      <dc:creator>Piotr_Kowalczyk</dc:creator>
      <dc:date>2024-04-18T18:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue Device Discovery with Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/strata-logging-service/rogue-device-discovery-with-cortex-xdr/m-p/562930#M26</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/248369"&gt;@Piotr_Kowalczyk&lt;/a&gt;, thanks for reaching the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With your license your should be able to install a Broker VM, which is needed to activate the Network Mapper App that runs the scans:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Administrator-Guide/Activate-the-Network-Mapper" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Administrator-Guide/Activate-the-Network-Mapper&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is more info about the Broker VM:&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Broker-VM-Overview" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Broker-VM-Overview&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It should work well, there are not any specific issues reported for now, you need to be sure that the rogue devices respond to the ICMP or TCP port probes from the Broker.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 12:55:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-logging-service/rogue-device-discovery-with-cortex-xdr/m-p/562930#M26</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2023-10-24T12:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue Device Discovery with Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/strata-logging-service/rogue-device-discovery-with-cortex-xdr/m-p/562933#M27</link>
      <description>&lt;P&gt;Thank you for your reply,&lt;/P&gt;
&lt;P&gt;Just two additional questions:&lt;/P&gt;
&lt;P&gt;1. Is Cortex Data Lake license required for this? I can see it on the Broker VM diagram so I just want to make sure this won't be a problem.&lt;/P&gt;
&lt;P&gt;2. Does the discovery scan runs on the Broker VM (what would require the server to have access to all network segments) or on Cortex XDR agents - what would make sure all devices are discovered?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 13:26:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-logging-service/rogue-device-discovery-with-cortex-xdr/m-p/562933#M27</guid>
      <dc:creator>Piotr_Kowalczyk</dc:creator>
      <dc:date>2023-10-24T13:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue Device Discovery with Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/strata-logging-service/rogue-device-discovery-with-cortex-xdr/m-p/562935#M28</link>
      <description>&lt;P&gt;1- CDL is not required, it is required to ingest logs from other sources than Agents, like firewalls or Okta.&lt;/P&gt;
&lt;P&gt;2- The scan is generated from the Broker VM, so yes, you will need to allow the Broker VM and ports/icmp on every segment.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1698154363304.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54646iC8686C4744119F23/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jmazzeo_0-1698154363304.png" alt="jmazzeo_0-1698154363304.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;You can create the IP ranges in Assets - Network Configuration - IP Address Ranges.&lt;/P&gt;
&lt;P&gt;You will see the scan results in Assets - Asset Inventory.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 13:35:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-logging-service/rogue-device-discovery-with-cortex-xdr/m-p/562935#M28</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2023-10-24T13:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue Device Discovery with Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/strata-logging-service/rogue-device-discovery-with-cortex-xdr/m-p/562938#M29</link>
      <description>&lt;P&gt;Sorry, one more question. I've just noticed that that Agents discover network devices and they are placed in Asset Inventory. I can see only IP address without any additional information. Does it work together with Network Mapper somehow?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Piotr_Kowalczyk_0-1698154977744.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54647i04EBDFB20EB2F3C2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Piotr_Kowalczyk_0-1698154977744.png" alt="Piotr_Kowalczyk_0-1698154977744.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Piotr_Kowalczyk_1-1698155150841.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54648i0E06C353B0C79029/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Piotr_Kowalczyk_1-1698155150841.png" alt="Piotr_Kowalczyk_1-1698155150841.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 13:48:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-logging-service/rogue-device-discovery-with-cortex-xdr/m-p/562938#M29</guid>
      <dc:creator>Piotr_Kowalczyk</dc:creator>
      <dc:date>2023-10-24T13:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue Device Discovery with Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/strata-logging-service/rogue-device-discovery-with-cortex-xdr/m-p/562959#M30</link>
      <description>&lt;P&gt;Yes&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/248369"&gt;@Piotr_Kowalczyk&lt;/a&gt;, those are the IPs that the agents connect or lookup inside your network. The Network Mapper findings will show the Source as "Broker Scanner".&lt;/P&gt;
&lt;P&gt;You will only see the IP Address and the last time that was detected, then based on your inventory decide to install or not the agent if it is possible.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 15:42:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-logging-service/rogue-device-discovery-with-cortex-xdr/m-p/562959#M30</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2023-10-24T15:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue Device Discovery with Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/strata-logging-service/rogue-device-discovery-with-cortex-xdr/m-p/562967#M31</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 15:55:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-logging-service/rogue-device-discovery-with-cortex-xdr/m-p/562967#M31</guid>
      <dc:creator>Piotr_Kowalczyk</dc:creator>
      <dc:date>2023-10-24T15:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue Device Discovery with Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/strata-logging-service/rogue-device-discovery-with-cortex-xdr/m-p/563044#M32</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/248369"&gt;@Piotr_Kowalczyk&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Additionally, If you would like to enrich those discovered assets with hostname, mac address or mac address vendor you would have to ingest "Associated DHCP logs covering those assets" to Cortex XDR but that would require &lt;SPAN&gt;Cortex XDR Pro per GB license&lt;/SPAN&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PiyushKohli_0-1698205555151.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54660iB26866C6E1313F6C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PiyushKohli_0-1698205555151.png" alt="PiyushKohli_0-1698205555151.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ref:&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Asset-Inventory" target="_self"&gt;Asset-Inventory&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 03:47:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-logging-service/rogue-device-discovery-with-cortex-xdr/m-p/563044#M32</guid>
      <dc:creator>PiyushKohli</dc:creator>
      <dc:date>2023-10-25T03:47:34Z</dc:date>
    </item>
  </channel>
</rss>

