Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4356 Views
  • 0 replies
  • 3 Likes

Cortex XDR - All Actions export

Greeting to all!I have faced an interesting use case with Cortex XDR and I haven't seen solution to it ever before. Short description of the situation - We have a successful vulnerability exploitation event. We know for sure, that it was exploited and data was stolen. Now we need to investigate logs from impacted endpoint for at least last 30 da...

Resolved! Inquiry: URL IOC Capability in Cortex XDR

Dear Palo Alto Community, I hope this message finds you well. As an active member of the community, I would like to reach out and seek your expertise regarding the capabilities of Cortex XDR, specifically in relation to the integration of URL Indicators of Compromise (IOCs). Recently, our organization has been exploring ways to enhance our t...

Tracking Cortex XDR Corrupted Agents

Dear Community, When I first started the Cortex XDR Project and started installing the agents, I made a mistake and deleted the outdated installation packages from the portal. After that I started getting a lot of disconnected agents as if they try to connect to the portal and the ID is already deleted. Since it will be hard to know which asse...

AmmarJi by L1 Bithead
  • 2762 Views
  • 4 replies
  • 0 Likes

Resolved! Details Regarding XDR Query Fields: server_creation_time and creation_time

Hello Everyone, We use below endpoint to collect the alerts: /public_api/v1/alerts/get_alerts Currently, we use creation_time to query alerts. But recently with the help of community answers only we found that creation_time is the time when an alert was created on the endpoint and not the time when the alert was ingested in XDR. For real ti...

Allow users to change the Timezone

Hello, We have users from different places and different timezone. We noticed that it is not possible for a user to change their timezone if they don't have the General Configuration View/edit permission. Is there any other way to allow a user to change their timezone in XDR? Thank you all!

atayar by L0 Member
  • 2863 Views
  • 2 replies
  • 0 Likes

Resolved! Users may experience account lockouts due to XDR services.

Dear Community, After modifying the password for a Windows user, the user account is continually locked out.Using Process Monitor, it was discovered that the XDR service (cyserver.exe) read cached credentials(C:\ProgramData\Cyvera\LocalSystem\Python\payload\grpc\_cython\_credentials).At approximately the same time, the lsass.exe process began se...

Chilla by L1 Bithead
  • 3069 Views
  • 1 replies
  • 0 Likes

Resolved! Can't find logged in users from Endpoint Asset View

Hello all, I find it strange that I cannot easily check the connected or previously logged in users on an endpoint. For example on Asset View or from Endpoints view I cannot see that.There is the possibility to see it only on an incident I guess. But only then.Do I miss something? Thanks

Panagiss by L1 Bithead
  • 2215 Views
  • 1 replies
  • 0 Likes

Host Insights - Functionality limitation through license

Hello dear community, we had not enough host insights licenses. About 13 agents are not available in the module system information. Where is the trigger to say one or more of them should now gather or send the informations to Host Insights? This topic is about one week ago, since we have the new license. BR Rob

RFeyertag by L4 Transporter
  • 2587 Views
  • 4 replies
  • 0 Likes

Resolved! Detail Description of Alert Log Fields XDR API

Hello Everyone, We are pulling alerts from the XDR API using below endpoint: /public_api/v1/alerts/get_alerts We query based on creation time which is shown as detection_timestamp in the log. I am looking for clarity on below points: 1. what is local_insert_ts field? What is the significance of this field? How it is different from creat...

Resolved! Requesting Clarity on XDR XQL API Logging

Hello Everyone, For one of the client, we need to fetch logs from XDR API using XQL. Currently, the ask is for windows event logs only, but later they want IIS logs as well. Any help in below queries would be appreciated: 1. There are two queries by which I fetched logs successfully. One is using: dataset= xdr_data | filter event_type = EV...

  • 2599 Posts
  • 98 Subscriptions
Top Solution Authors