Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 1404 Views
  • 0 replies
  • 3 Likes

Problem uninstalling Cortex XDR Agent

I often have the problem that the host loses connection to Cortex console due to a failed agent update and I cannot uninstall the agent on it and reinstalling the agent results in a rollback. There is a file named "tdevflt.sys" left in the "C:\Progra

...

Scott103 by L0 Member
  • 5659 Views
  • 2 replies
  • 0 Likes

Query Builder to XQL

I have built queries within builder that I cannot replicate in a xql query

Is there a way to convert them quickly?

The example below was built with the builder, a search for files within removable media for the previous 24 hours

I need it in xql syntax

...

Resolved! Cortex XDR Agent and system logs

Hello All,

 

I am trying to get logs for cortex XDR agent of more than 1 month old, from system and tech support file however not getting any success. Does anyone knows any method by which we can retieve agent logs/tech support logs for more than 1 mon

...

tejasp04 by L1 Bithead
  • 18247 Views
  • 1 replies
  • 0 Likes

XDR agent quota exceeded

We're running 7.4.x currently and we've been seeing a ton of these alerts lately, and it seems to be for the same four or so machines out of several thousand. It is just alert after alert. I checked the log folders on the machines and they aren't any

...

enewman by L1 Bithead
  • 4320 Views
  • 2 replies
  • 0 Likes

Trying to setup Cortex Data Lake

Hi all,  I am new to this forum and new to the job where I am having this issue so please forgive me if this is an easy question that has been answered, I could not find the info I was looking for. I am trying to setup a Cortex Data Lake for my Corte

...

All Cygwin apps see the decoy files

Hi. My organization forced the installation of Cortex XDR 7.4.2.35695 on my workstation and When I use Cygwin it lists the anti-ransomware decoy files. It's especially troublesome when I copy directories because real files are created then.

ncdu 1.10 ...

Resolved! Cortex XDR Forensics Addon

Hello everybody.

I have a question about Cortex XDR Forensic addon. When we enable Forensic addon from Agent Settings profile we see "Interval Hours" for each section. But we can not understand what it is. Also we can not find anything about it in any

...

Move an Endpoint agent to another tenant

How to move an Endpoint agent to another tenant? I just tried to transfer a Cortex XDR agent from one tenant to another tenant. But unfortunately, the said agent is keeping listed at the current tenant rather than the new tenant.

High memory consumption on newer agent versions

Hello everyone,

 

 I have sporadic servers in our environment producing high memory consumption with the XDR agent. Cyserver.exe will climb to 350-400mb in some instances until the service is rebooted and it brings it down to an acceptable level. Has a

...

CraigV123 by L3 Networker
  • 20099 Views
  • 5 replies
  • 0 Likes

Advanced Training For Cortex XDR

Hi all,

 

Does any of you support members, or experienced Cortex XDR users know if there's reasonably priced advanced training for the platform (on-demand or instructor-led).  Please I'm not talking about the on-demand training available at this link a

...

How do you manage agent upgrades?

I am trying to manage agent upgrades without allowing the agent to upgrade to new and unstable releases.  For example, I do NOT want 7.5.0 upgraded on any system, but I do want the most recent 7.4 release upgraded on all systems.  I have run into iss

...

  • 2423 Posts
  • 88 Subscriptions
Top Solution Authors