Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4319 Views
  • 0 replies
  • 3 Likes

Resolved! Ingest Logs from Cisco ISE to Cortex XDR

Hi Anyone successfully ingest logs from Cisco ISE to Cortex XDR via syslog? I've activated the syslog collector of broker VM for TCP514 and format set to auto detect, following this documentation, and configured the Cisco ISE to forward the logs to broker VM accordingly. However, when I hover over the Syslog Collector link in the Apps field of ...

weejh_0-1647926849547.png
weejh by L2 Linker
  • 7080 Views
  • 4 replies
  • 0 Likes

The data ingestion dashboard and datasets do not correspond

Recently, by purchasing a per TB licence, I integrated the logs of the Fortinet firewall, but I found that the daily data volume in the data ingestion dashboard and the log volume in the Fortinet datasets do not match. The dataset of the Fortinet only shows 411G. According to the data ingestion dashboard, the total number should be 592G. I check...

datadashboard.png
datasets.png
Grady by L2 Linker
  • 2999 Views
  • 2 replies
  • 0 Likes

Cortex XDR + CDL - Raw Log file integrity and tamper protection

Hello, I have been digging through various Cortex documentations to find explicit language around log integrity, tamper protection of logs from administrators. I am aware that RAW Logs are not accessible to tenant admins however, could you point me in the direction of any documents that explicitly state that all logs ingested by XDR and Data Lak...

'Hijacked DLL Injection' alerts

Greetings , The single most common and repeating alert which we are getting is like below :'' 173 'Hijacked DLL Injection' alerts detected by XDR Agent on 24 hosts ''Explanation is 'DLL attempted to load from blacklisted location' .So 2 questions hereWhat we are supposed to do here ? What is the investigation path we should follow ? What above a...

Balaraju by L2 Linker
  • 6129 Views
  • 5 replies
  • 0 Likes

XDR flags Chrome as malware on ubuntu endpoint

Hi folks, got a problem that i would like som input on.I have an ubuntu endpoint with a xdr agent installed. said agent has given me a high severity alert about several items on this ubuntu endpoint - Kite(which, seeing how kite can install itself autonomously, i understand why the XDR would flag it), systemd and chrome.Now here's what i dont un...

API Pagination

Hi community, I am new here. I am trying to integrate the Cortex XDR API for incidents into Azure Sentinel using the new Codeless Connector Platform (CCP). The challenge I have is that the Cortex API doesn't appear to have any indicator as to where you are up to in the response that is coming back. It gives the total number of records and the ...

Phil007 by L0 Member
  • 4205 Views
  • 3 replies
  • 0 Likes

upgrading endpoints from the Cortex Console, 50% success rate. spot checks show "Upgrade by SAM failed"

Hi Everyone, we have been trying to upgrade some endpoints from 7.2.2 to 7.5.1 but the success rate on the first push was 50%. on the second push again 50% on the left overs from the first push. the logs are showing ""Upgrade by SAM failed" 2022/03/10T09:22:33.132-05:00 <Notice> "endpoint name" [6104:6268 ] {trapsd:AgentAction:Startup:}...

Resolved! XDR integrates Fortigate but doesn't see data in dataset

First of all, I have a per TB license, so today I integrated the data of the fortigate firewall, forwarded it to the broker through the log, and opened the syslog applet on the broker. Configured according to the admin guide, the firewall is given to the broker in cef format. Now the xdr cloud data ingestion Dashboard can see the Fortinet log, b...

dashboard.png
dataset.png
Grady by L2 Linker
  • 6191 Views
  • 6 replies
  • 0 Likes

Resolved! What is the relationship between XDR and Datalake

I saw that there is datalake in the official admin guide structure, but I don't know what datalake does. I bought 200 XDR pro licence and found that my account has more datalake, which has 1TB of storage space. I am very confused. What data is it used to store? I didn't buy a per TB license. Actually my XDR has some data, but I don't see it in d...

Grady by L2 Linker
  • 8185 Views
  • 5 replies
  • 0 Likes

deploy broker vm proxy configuration

hello, i want to install cortexXDR throught SCCM on my servers but i'm facing an issue with setting the proxy parameters also to type the confirmation password. How it's possible to do it?any help please? BR.

NCherbib by L2 Linker
  • 4933 Views
  • 4 replies
  • 0 Likes

Cortex XdR

Is it possible to set a policy for the file size in cortex Xdr /Cortex Xdr pro? Requirement: The limited size(configured size if possible to set policy) of file can only be shared between the endpoint

  • 2582 Posts
  • 95 Subscriptions
Top Solution Authors