Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Alarm on disconnected agents..

Hi, we're in the process of migrating our endpoint security on servers and PC clients to Cortex XDR. I'm new to Cortex XDR, but have started to walk thru all kinds of documentation/training..

 

Today's question  :

 

If I, or someone else, disables t

...

Alerts and incidents

Hello Palo Live Community.
Does anyone know what are the criteria that Cortex XDR takes into account to create an incident for a single alert? This is because I have seen that some alerts do not necessarily form an incident, but in other cases, yes. I

...

R.Tuyub by L0 Member
  • 109 Views
  • 1 replies
  • 0 Likes

Azure AD and InTune

Hi Palo Live Community, I'm hoping that someone has worked with Cortex XDR and Azure InTune.

 

I'm trying to find a dynamic way to apply an extension profile  (block USB), in Cortex XDR, targeting specific endpoints that reside in Azure InTune.

 

Bef

...

Agent Configuration - Password strength

Hi, I'm struggelin' to set a new password. Have tried all kind of combinations. Allways get "Does not meet the requirements." 

 

Please see attached for an example..

 

I've seen earlier discussions on this. Something does not seem to be working as in

...

ITDR Honey Users for Cloud Identities

Hi Everyone

 

We're using ITDR module and are manually assigning asset role as described here: https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Asset-Roles

 

Only on-premises identities from AD can be assigned to asset r

...

Rocky-25 by L1 Bithead
  • 79 Views
  • 2 replies
  • 0 Likes

XQL query for incident report

I like to get a hint how i can build simple xql query for  overtime timeframe for incidents. I need to filter that data, but that kind report that i can show example monthly base report for customer. where there are data for each day

T.Nurmi by L0 Member
  • 124 Views
  • 2 replies
  • 0 Likes

XQL Query Help

I'm trying to write a few XQL queries in Cortex XDR, but I’m quite new to it and running into some difficulties. I’d really appreciate any guidance or examples you can provide for any of the following queries:

  1. To detect when the Cortex XDR Agent is u
...

Cortex xdr with RedHat Quay with Clair

Hello PA community,


For all images on customer s OpenShift clusters, they have a policy that all images have to be stored in their RedHat Quay with Clair.

Customer has tried to setup a mirror with the "europe-west4-docker.pkg.dev/xdr-eu-2009645628112

...

Resolved! XQL Query Help

I am trying to create a rule for the case of creating a new user in the admin role. Where's my mistake?
I am grateful for your help.

dataset = xdr_data 
| filter action_evtlog_event_id = 4720

| alter Direct_Role = arrayindex(regextract(action_evtlog_me

...

  • 1989 Posts
  • 78 Subscriptions
Top Liked Authors