Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 431 Views
  • 0 replies
  • 2 Likes

Cortex XDR with Carbon Black

Hi All,

  I know it is a stupid question but I am encountering this situation that we need to install Cortex XDR working with Carbon Black (it's a long story). May I know if anyone experienced this before or any suggestions on exclusion? Thank you so

...

Resolved! Cortex XDR report

Hello Live community,

 

I have a question about the report on Cortex, i want to know if the “Infected Endpoints” comes as default in Cortex reports or if we need to configure something to show that option?

Do the widgets "incidents by source" or "Top in

...

Resolved! How do we set an incident title ?

Hello all,

 

I feel this is a silly question but I don't know the answer and can't find it.

 

We have a lots of incident comming from Splunk integration with the following title: ":".

 

We can't find anywhere inside classifier or mapper how to set the titl

...

Using Windows environment variables in XDR Firewall

Hello,

 

Configuring host firewall via XDR and I cannot seem to get the Windows environment variables running.

Basically, there's an implicit deny for inbound/outbound connections, so there are applications that require some internal/localhost connectio

...

nikoo by L3 Networker
  • 2972 Views
  • 1 replies
  • 1 Likes

Log storage and resources usage

Hi everyone!

 

How much space do the cortex xdr agent records use? I understand that in the agent profile configurations you can set the quota for log storage, by decreasing the quota the logs are automatically purged ??, for the last one on my machine

...

Cortex XDR Alert Dump File Analysis

Is there a way we can analysis the dump file when a behavior based alert is generated for an incident? We would like to analysis the process dump file with volatility for windows 10 machines.

Thanks for the help in advance.

App-ID for endpoint-based BIOC rules

Currently, BIOC rules can be created for "NETWORK" (endpoint-based) or "NETWORK CONNECTIONS" (NGFW-based) but only the latter supports the usage of App-ID and VPN infrastructure isn't always in place or available.

 

Are there any plans to add this?

 

2020 ∕ 09 ∕ 22 16꞉01꞉10 - Rule_Builder_-_Cortex_XDR_-_Google_Chrome.png
2020 ∕ 09 ∕ 22 16꞉01꞉38 - Rule_Builder_-_Cortex_XDR_-_Google_Chrome.png
2020 ∕ 09 ∕ 22 16꞉02꞉07 - Rule_Builder_-_Cortex_XDR_-_Google_Chrome.png
  • 2216 Posts
  • 86 Subscriptions
Top Solution Authors
Top Liked Authors