Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Where is agent v8.5???

Hello all experts,

From Agent Release below, v8.5 supposed to be released by 30Jun2024. 

https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Agent-Releases/Cortex-XDR-Agent-Releases

 

However, 8.5 was not shown from the pull down menu wh

...

SeanDeHarris_0-1721011286748.png

Cortex XQL help

Hello Dear Community, I want to count events based on specified time periods. For example I want to query hosts that scanned more than 50 hosts in 10 seconds. How can I write XQL in that case?  

Cortex XDR 

Cortex XDR CE version

How to know if Cortex XDR version is CE.

 

Will it show on the table when I go to Endpoints ----> All Endpoints and on the Agent Version Field it should have for example 7.9.102CE, if it shows 7.9.102 only then it is a standard version? 

 

Thank you.

Cortex XDR DNS Collectors

Hi community,

 

I have a query regarding Cortex XDR collectors. When installing collectors on the local DOM servers, what types of logs does the Cortex XDR console retrieve? How can these logs help with the investigation of incidents?

Notification via Mail - Improvement

Hello! 

 

Changes are coming with 3.11, but for improvement put this information directly into mail:

 

  • Source
  • Category
  • Action
  • Host
  • Username
  • Starred Alert
  • Excluded Alert
  • Alert ID
  • Incident ID
  • actor_process_image_path
  • actor_process_image_name
  • actor_process_command
...

RFeyertag by L4 Transporter
  • 183 Views
  • 1 replies
  • 0 Likes

Upgrade agent failed

I have encountered the following issue of failed agent upgrade on a Windows laptop, showing the following message:

 

XDR Agent failed to upgrade from version 8.4.0.51691 to version 8.5.0.624 on LAPTOP-xxxxxxx with error: Windows Installer DB: Current

...

BIOC RULE Creation - Workstation IP changed

Hi,

 

How we can monitor the scenario like,  when a cortex connected workstation's IP address change?

 

Whether it is possible to create a rule/bioc in cortex xdr for monitoring the above mentioned scenario ?

Cortex XDR Cortex Data Lake 

 

Thanks

Chr

...

Christy7 by L0 Member
  • 200 Views
  • 1 replies
  • 0 Likes
  • 1873 Posts
  • 78 Subscriptions
This widget could not be displayed.