Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4361 Views
  • 0 replies
  • 3 Likes

Cortex XDR

Hello everybody We recently saw a Cortex XDR app ( Pro per endpoint 200, Pro per TB 1) for activation which was purchased in 5 august in our customer support portal (in Cortex XDR Gateway) . But we did not request any Cortex XDR app. Is it possible Palo Alto give it periodically this for test purpose or after selling to customer. Or any idea? ...

Syslog Splunk Parsing

Hey everyone, First time poster. We just rolled out XDR and having some issues getting data into Splunk. The Splunk TA App says it does not support Syslog, but there is loads of documentation for getting agent logs, alerts, management logs sent to Splunk. It seems there may be a disconnect between the DEV's for the APP and Product Management. H...

eumbach by L3 Networker
  • 5975 Views
  • 2 replies
  • 0 Likes

Resolved! Using the Command Line in Live Terminal on a Mac

Hi, all. I tried using Live Terminal for the first time today, and all was going well until I got the the Command Line section. While connected to a Mac, I got this error message: bash: no job control in this shell The default interactive shell is now zsh. To update your account to use zsh, please run `chsh -s /bin/zsh`. For more details, ple...

I have two queries for Cortex XDR for cloud identity engine and browser protection.

Hi, I have deployed Cortex XDR in my environment and I have two queries it features. 1. I have integrated the on-premises AD with the help of a DSS agent and cert. It is connected and is synced in the cloud identity engine. So what is the purpose of the AD in Cortex XDR why it is used and can we configured the user and group base policy. if yes ...

High Alert wininfo.exe

received alert from Traps regarding malware detection of the maximum system due to file “Wininfo.exe”.Please find a snapshot of one system and suggest how to fix this. Is there any impact? CORTEXXDR WildFire MalwareHighSource:XDR AgentCategory:MalwareAction:Detected (Post Detected)Host:SS-akhilUsername:N/AStarred:NoExcluded:NoAlert:1240Incident...

Wininfo.jpg

After Uninstall Trap 7.2.2 from the machine - Cisco AnyConnect VPN started to work

When logging into Cisco AnyConnect VPN, the prompt: Login denied. Your environment does not meet the access criteria defined by your administrator. After trying various methods, it cannot be solved: Then we have uninstalled the Traps - 7.2.2 from the machine, the SSL-VPN started to work. I mean the Traps Uninstall made the VPN works

Anyone using Palo Alto Cortex XDR and/or Critical Start?

We are looking to replace our current aging AV system (Trend Micro) next year as we are up for renewal. We're a relatively small shop. ~475 employees.We are looking at jumping on the Palo Alto Cortex XDR bandwagon (We currently utilize their firewalls as well) and we are curious if anyone here actually uses this system and has any feedback. We d...

Cortex XDR 7.4.1 in MAC having Malware Definition date as year 1970

Cortex XDR 7.4.1 in MAC having Malware Definition date as year 1970 in The Global Protect. Somehow, the AV definition date for Cortex in Global Protect is showing as 1970. User is not able to connect to Global Protect as its failing HIP match from the firewall that says the AV definition date should not be older than 7 days. Business is impact...

IOC Function

Hi Everyone, Until now, I cant understood a function from IOC in Cortex XDR.Could please share to me what's a main function IOC XDR?Because I have tried to create new rules, for block link m.facebook , like a picture. But, after that I have tried to access again, and the result I keep can access the URL.

MuhammadRusli_0-1629424930850.png
  • 2600 Posts
  • 98 Subscriptions
Top Solution Authors
Top Liked Authors