Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4319 Views
  • 0 replies
  • 3 Likes

Cortex XDR Block List isolating machines

Hi all, I'm running into this issue where some personnel do not want to add malicious hashes to the XDR block list as it will isolate the machine. As far as I can tell, adding a hash to the block list will only remove the file on execution or scan, leaving the rest of the machine completely alone. Is anyone able to confirm or deny either argum...

Resolved! API IOC Upload - Invoke-WebRequest : 413 Request Entity Too Large nginx

Hello dear community, I am uploading some IOCs (about 300k). Where are the limitations? I can see PA is using nginx, but I can't find any information about the submitted filesizes etc. Now I am actually running "Transfer-Encoding" = "chunked" in test. Lets see, what will happen. Error 413: Invoke-WebRequest : 413 Request Entity Too Larg...

RFeyertag by L4 Transporter
  • 2236 Views
  • 1 replies
  • 0 Likes

Resolved! Problem bei Installation eines Cortex XDR Clients 8.0.1.33809 (Win, 64 Bit, msi) auf Microsoft Surface Pro 9 5G ,Prozessor: Microsoft SQ3 (ARM64)

Wir haben Probleme bei der Installation eines Cortex XDR Clients 8.0.1.33809 (Win, 64 Bit, msi) auf einem Rechner Microsoft Surface Pro 9 5G (Prozessor: Microsoft SQ3 (ARM64) / OS: Windows 11 22H2) Installation des Cortex beginnt, Cortex-Installation versucht dann die entsprechenden Dienste zu starten und bricht dann wie folgt ab:SetupWizard en...

Cortex XDR -Large upload Alerts

Hey folks,Recently we are getting high number of large data upload alerts in Cortex XDR.The issue is data upload alerts are flagged with domain name stun.l.google.com on port 19302 ,UDP. Why browsers are connecting to this stun server ?when queried about it ,known few things about WebRTC , NAT & how STUN is used in peer to peer communicating...

Verifying Installed Modules

Hey Folks, Just wanted to understand how can we verify on console and XDR agents console that agent are installed with EPP modules enabled? Regards, M.R. Cortex XDR Cortex XSIAM

Possible Values for event_types

Hello Community, I am trying to understand Palo Alto XDR logs fetched using API(XQL Query). I am using dataset as xdr_data, want to know what all event_types can come under this dataset. For ex: EVENT_LOG. What are the possible values we can get in the field event_type when using dataset=xdr_data. I want to use event_type in the filter o...

agent intall exceed license number of agents

I read the relevant documents, but I don't quite understand them. I hope someone can confirm them for me.reference articale url :https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/cortex-xdr-overview/cortex-xdr-licenses/cortex-xdr-license-allocation.html.:After utilizing all available Pro licenses, Cortex XDR falls back to ...

Felixcao by L3 Networker
  • 8055 Views
  • 5 replies
  • 0 Likes

Searching for multiple hashes on cortex XDR

Does anyone know a way to search for multiple hashes on Cortex XDR? file_search = existing_files does not allow any operators other than "=" for the sha values and you can't string multiple in a query. I feel like I'm missing something and there should be a way to do that that I'm not aware of. Any ideas?

rufat87 by L2 Linker
  • 4858 Views
  • 3 replies
  • 0 Likes

Confirmed issues with some identity threat modules and risk management dashboard

Hello everyone! Recently, I have been learning about the Identity Analytics feature in Cortex XDR. After enabling Identity Analytics, I found that not every tenant presents the same interface. I found that the following UI features are not identical: absence of a Risk Management Dashboard less information displayed in User Risk View (e.g. Reg...

Chilla by L1 Bithead
  • 2956 Views
  • 3 replies
  • 0 Likes

Changing cortex installation directory in Linux

Hi All, Need some help! We have a Linux instance where the opt/ folder size is 2 GB and the recommended disk quota by Cortex is 5 GB. We can not resize it. Do anyone know if there is a way to change the installation directory of Cortex from /opt to any other folder? Awaiting your response, thanks in advance!.... Biswajit.

Resolved! Error (0x800705b4) during installation of 7.5 CE on W7/S2008R2

Hi everyone, unfortunately we still have a bunch of W7/S2008R computers (without extended support) in our network. The majority of the pcs have Cortex XDR 7.9 installed. In terms of support we are now trying to uninstall 7.9 and install 7.5 CE instead. The problem is, the installation only works on about 10% of the mentioned clients, at the re...

  • 2582 Posts
  • 95 Subscriptions
Top Solution Authors