Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 276 Views
  • 0 replies
  • 2 Likes

Resolved! Cortex XDR/Data Lake

Hello.

 

I can not see any logs in my Cortex Data Lake. Also when i go to Explorer app in Hub it is empty. Firewall Logs is also seem empty( I forward logs to Data Lake with Broker VM from Fortigate). Can anybody explain me this situation?

 

NOTE: I

...

Resolved! Cortex XDR whitelisting

Hi,

 

We have been asked to whitelist a specified folder in order to disable any kind of real-time checks and analysis made by Cortex XDR.

 

So, we added the aforementioned folder in the allow lists of "Portable Executable and DLL Examination" and "Behav

...

MCereda by L0 Member
  • 10664 Views
  • 3 replies
  • 0 Likes

Resolved! wf_vericts json file verdict values?

Exported wf_verdicts.db from an endpoint to validate local verdicts. Is there any reference for return codes and their meanings?

 

example:

"value": {
"verdict": 3,
"lruData": {
"lastUsed": "1613061210",
"index": "65945"

JoeDay by L0 Member
  • 2949 Views
  • 3 replies
  • 0 Likes

Resolved! Default Landing Page & Incidents Filter

Is there a way to set the system (with cookies enabled, or not) to default to the Incidents Page when first loading? IOW instead of going to the default dashboard have it load the Investigations/Incidents section as default.

 

Also, when going to to th

...

Resolved! XDR agent is showing high memory consumption

Hello,

 

We installed the agent on different devices. But we have noted that there are high levels of memory. In some devices, we see 180 MB. But in other, the memory is above 300 MB (especially VDI). Is this a normal situation? Or are there specific c

...

iscott by L2 Linker
  • 11708 Views
  • 2 replies
  • 0 Likes

Pro Per TB License Not Used for 14+ days

Hello LIVEcommunity received the following email from Cortex Customer Success <noreply@paloaltonetworks.com>, but I am a contact on several different customers/tenants of Cortex.  How does one know which customer this is for?  
May I suggest that a Te

...

Filtering by Endpoint groups

I am trying to write an XQL query that will only focus on the endpoints that I have defined in my endpoint groups and not all endpoints in the xdr_data dataset.  

 

How can I filter the xdr_data dataset by endpoint groups?

tfoley by L0 Member
  • 2242 Views
  • 1 replies
  • 0 Likes

admin applied agent tags

I have a few XDR deployments I manage and one this I miss is the ability to tag objects like I can on firewalls.

 

This would be useful for a number of tasks from:

- filtering views/dashboards/reports

- adding agents to dynamic agent groups

- assigning po

...

  • 2154 Posts
  • 83 Subscriptions
Top Liked Authors