Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4327 Views
  • 0 replies
  • 3 Likes

Cortex XQL "Let" replacement

Hi, I'm wondering if anybody knows a method, I can use to join multiple queries within the same XQL query. I have 3 separate queries which return a count of vulnerabilities for each region of logs. How do i merge these 3 queries to return a table which shows UKI 1 CAN 1 AUS 1 I know this was possible with Sentinel KQL as you could nest ...

Resolved! Baseline Creation of Endpoints Without Registered Alerts in Cortex XDR

Good afternoon, it’s a pleasure. I’m currently working on building a baseline of endpoints that have not generated any alerts within the production timeframe. The idea is to use this baseline as the foundation for a future correlation rule. I’ve been trying different approaches for hours using XQL queries, but I haven’t been able to get the expe...

Resolved! Block Execution of Specific Applications Regardless of Location

I want to prevent the execution of anydesk.exe, choco.exe, and cloudflared.exe. However, I went to the Prevention Policy Rules and created restrictions for applications, but it only allows blocking in specific locations, so that doesn't meet my needs. I want these applications to be blocked whenever they are detected anywhere in the system. Co...

Cortex XDR Broker VM Connection

Hi, Does Cortex XDR service on cloud initiate connection to Broker VM? Or just broker VM will initiate connection to Cortex XDR service? I need this information to define whether I need 1 to 1 static NAT on firewall for broker VM or not. Thanks in advance

Cortex XDR Agent Failover

Hi, I use broker VM for bridging communication between XDR agent and XDR cloud. But the communication can happen only when the agent reside in internal network. Does cortex xdr have mechanism to detect whether inside or outside network? So it can decide to send data via broker VM (inside network) or direct to cloud (outside network)? Thanks ...

Cortex XDR Agent offline notification

Hello Team, I would like to be notified by email when an XDR Agent goes offline. However, I could not find a function to notify the agent status. Do you know of any documentation that explains how to configure the agent status notification function? Regards,Yusuke Narita

Cortex XDR Agent offline notification

Hello Team, I would like to be notified by email when an XDR Agent goes offline. However, I could not find a function to notify the agent status.Do you know of any documentation that explains how to configure the agent status notification function? Regards,Yusuke Narita

Cortex XDR email data integration

Hi, i have integrated email data from Microsoft Graph API to Cortex Collections Integration -> M365, but still there are no phishing emails or suspicious emails being reported as incidents in Cortex. Could you let me know what should be done inorder to trigger such alerts and incidents in Cortex?

Cortex XDR API to get a full CVE list

We are working on an automation task that would like to download the CVE full list under "Vulnerability Assessment" of "Assets" from Cortex XDR menu pane. We would like to try API to download the contents and put it to CSV file format so that we can further processing our automation task. Please kindly advise if this can be achieved and what A...

  • 2591 Posts
  • 97 Subscriptions
Top Solution Authors