Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

API Syntax Issue

Hi everyone,

 

I'm trying to use the 'run_script' API to start the built-in 'Execute_Commands' script on a target machine. I've worked through a few error messages already regarding the command string having black slashes, timeout not being set as in

...

Resolved! Email_data dataset empty

Hi all, have been digging into our Cortex tenant and noticed that the email_data dataset has no data. Our emails come from Microsoft Exchange online. To get data to this dataset is it just having a compliance mailbox set up in exchange? We already ha

...

Alert to Incident

Hey dear community, 

 

do I have the chance to elevate a alert to an incident? I tried allready to set the severity of an alert to critical, but nothing happened. This alert doesn't get an Incident ID. 

 

I thought this was possible in the past, but

...

RFeyertag by L4 Transporter
  • 2100 Views
  • 5 replies
  • 0 Likes

Resolved! Notification when alerts/Incident is resolved

Hi Community

I am trying to get notifications when alerts or incidents are resolved but it doesnt seem that there is a direct way to do so.
So is there a way to send a notification (Syslog or Email) when an alert or an incident is resolved?
Thanks in ad

...

Belhaj_a by L1 Bithead
  • 1055 Views
  • 2 replies
  • 0 Likes

Multiple Paths in Disable Prevention Rules

Hello
Is it possible to specify multiple values while creating prevention rules exception for one "application" ? If so what is the schematics of adding those ?
Especially in path section. As if application has multiple location paths for its different

...

how frequently XDR will push logs to Cortex?

Hi, 

how frequently XDR will push logs to Cortex? We have application it will write logs 400k per sec and log rotation setup like if file size is 50 MB it will compress the file and zips it. due to this we are missing logs in cortex xdr.

can you plea

...

Application WhiteListing

I have an application that needs whitelisting.

 

Actions Done:

Add to Allow List

Add to Malware Profile, under specific module that triggered alert/incident.

 

It is still showing up in incidents when executed. Any idea what could be going on?

 

jia_xuan by L0 Member
  • 958 Views
  • 3 replies
  • 0 Likes

Resolved! Installing Cortex XDR on a template

Hello,

 

We want to prepare a template with all the installed applications including cortex, to use it in the new installations. How would it be done with cortex, would it be necessary to introduce some parameter in the installation, or with the usua

...

  • 2004 Posts
  • 79 Subscriptions
Top Solution Authors
Top Liked Authors