Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4496 Views
  • 0 replies
  • 3 Likes

Resolved! Submissions to VirusTotal? VT Licence ?

Hello! As I know, samples which are provided to VT, are "lost" in the endless VT world. VT can do with the files what they want. (Sharing, etc.). When we connect Cortex XDR with VT, what will be transfered to VT? What are the limitiations with Cortex XDR and VT, if we only have a free VT license? BR Rob

Cyber1985 by L3 Networker
  • 2688 Views
  • 1 replies
  • 0 Likes

Palp alto TRAP XDR cortex

Is it safe to install paloalto cortex XDR solution?If we install in our premises then our client machine data may get compromised if cortex scan for malware on cloud. Then what is the use of proxy broker server. I want my data must be safe and it should on premises only. If my data my ip will be save on cloud then how i will be secured. What is...

Whitelist IP from XDR anlysis

Hello, We would ike to know if it is possible to create a list of IP's that will not be analysed by any of the XDR protection modules.We have a vulnerability scanning tool that uses all sorts of scripts to perform its tasks, At the moment, most of these scripts are blocked by Cortex because they look suspicious, which is true but not wanted in t...

Resolved! Ingest Logs from Cisco ISE to Cortex XDR

Hi Anyone successfully ingest logs from Cisco ISE to Cortex XDR via syslog? I've activated the syslog collector of broker VM for TCP514 and format set to auto detect, following this documentation, and configured the Cisco ISE to forward the logs to broker VM accordingly. However, when I hover over the Syslog Collector link in the Apps field of ...

weejh_0-1647926849547.png
weejh by L2 Linker
  • 7572 Views
  • 4 replies
  • 0 Likes

The data ingestion dashboard and datasets do not correspond

Recently, by purchasing a per TB licence, I integrated the logs of the Fortinet firewall, but I found that the daily data volume in the data ingestion dashboard and the log volume in the Fortinet datasets do not match. The dataset of the Fortinet only shows 411G. According to the data ingestion dashboard, the total number should be 592G. I check...

datadashboard.png
datasets.png
Grady by L2 Linker
  • 3118 Views
  • 2 replies
  • 0 Likes

Cortex XDR + CDL - Raw Log file integrity and tamper protection

Hello, I have been digging through various Cortex documentations to find explicit language around log integrity, tamper protection of logs from administrators. I am aware that RAW Logs are not accessible to tenant admins however, could you point me in the direction of any documents that explicitly state that all logs ingested by XDR and Data Lak...

'Hijacked DLL Injection' alerts

Greetings , The single most common and repeating alert which we are getting is like below :'' 173 'Hijacked DLL Injection' alerts detected by XDR Agent on 24 hosts ''Explanation is 'DLL attempted to load from blacklisted location' .So 2 questions hereWhat we are supposed to do here ? What is the investigation path we should follow ? What above a...

Balaraju by L2 Linker
  • 6604 Views
  • 5 replies
  • 0 Likes

XDR flags Chrome as malware on ubuntu endpoint

Hi folks, got a problem that i would like som input on.I have an ubuntu endpoint with a xdr agent installed. said agent has given me a high severity alert about several items on this ubuntu endpoint - Kite(which, seeing how kite can install itself autonomously, i understand why the XDR would flag it), systemd and chrome.Now here's what i dont un...

API Pagination

Hi community, I am new here. I am trying to integrate the Cortex XDR API for incidents into Azure Sentinel using the new Codeless Connector Platform (CCP). The challenge I have is that the Cortex API doesn't appear to have any indicator as to where you are up to in the response that is coming back. It gives the total number of records and the ...

Phil007 by L0 Member
  • 4583 Views
  • 3 replies
  • 0 Likes

upgrading endpoints from the Cortex Console, 50% success rate. spot checks show "Upgrade by SAM failed"

Hi Everyone, we have been trying to upgrade some endpoints from 7.2.2 to 7.5.1 but the success rate on the first push was 50%. on the second push again 50% on the left overs from the first push. the logs are showing ""Upgrade by SAM failed" 2022/03/10T09:22:33.132-05:00 <Notice> "endpoint name" [6104:6268 ] {trapsd:AgentAction:Startup:}...

  • 2633 Posts
  • 99 Subscriptions