Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4322 Views
  • 0 replies
  • 3 Likes

I Wants to create new user account in Cortex xdr

Hi All, We have a new requirement where we need to integrate Cortex xdr with IBM Qradar and for this integration I have a IBM guide where it ask to download and install cortex xdr app, which we did, however from Cortex side (in Console) there are few steps which we need to follow like creating a syslog server etc, If anyone has performed this in...

AsifSid by L2 Linker
  • 2952 Views
  • 1 replies
  • 0 Likes

Cortex xdr notification for Licenses

Hi All, I have have received a notification in Cortex console (top right corner) where it says "Your license has expired or exceeded its capacity, Please contact support" We have a license capacity of 6000, I need to understand Is it really the capacity has exceeded? or do I need to do some kind of clean-up to release any unused licenses. Even ...

AsifSid by L2 Linker
  • 3723 Views
  • 1 replies
  • 0 Likes

I want to create a new user account in Cortex xdr

Hi Team, I need to create a new user account in Cortex console, Currently My role is app administrator of the Cortex xdr app (I never created any user account previously) This user account requirement is for the user who will be working on the Integration task (Cirtex xdr integration with Qradar).Can app administrator create new user account in...

AsifSid by L2 Linker
  • 15465 Views
  • 1 replies
  • 0 Likes

macOS Network Filter Causing Issues with shared VM connections

Hi Everyone, We are a new customer for Cortex XDR and the network filter seems to be killing our ability to share a connection to our Windows VM's from our macOS host while using our SonicWall VPN. If the VPN is disconnected connection works fine, when Cortex XDR is uninstalled it also works fine, as soon as Cortex is installed the shared conne...

KTaig by L1 Bithead
  • 6635 Views
  • 6 replies
  • 0 Likes

"Actions" in action centre are stuck at "In progress" only

Hi All, I have started facing an issue where whatever actions start via action centre, First it says "Pending" after that it turns to "In progress" status. and it stays there , It never shows status as "Completed successfully" Just to test, I initiated the scan on my own system and for more than 1hour status is "in progress" (Usually the scan fi...

AsifSid by L2 Linker
  • 4860 Views
  • 1 replies
  • 0 Likes

Resolved! cortexuser in Linux Agent

Hi Community, Anybody has any information on the user 'cortexuser' created while installing cortex in Redhat Linux ?, What this user used for and which folders are owned by this user Thanks in advance

File server, backup server and storage server profiles

Hi, we are about to activate Cortex XDR agent with Default Policy Rules (i.e. Default Exploit, Malware, Restrictions, Agent settings and Exceptions profiles) on some Windows servers which contain a huge amount of data (terabytes). Are there some recommended best practices to follow or some functionalities that should be disabled in order to avoi...

MCereda by L0 Member
  • 3659 Views
  • 2 replies
  • 0 Likes

Resolved! Cortex XDR - Detected (Scanned) alert for malware

Hello, Please excuse me if these are very basic questions. I have been trying to find a definitive, written answer and have been unable to, so far. If 1. Portable Executable and DLL Examination is set to the default of 'block' in an applied Cortex XDR policy, 2. a scan is run on an endpoint using that policy and 3. a malicious executable is ...

Resolved! Cortex XDR Windows Event Collector

Hello!I set up Windows Event Collector and data is coming to XDR. But i want to see data which come from Windows Event collector. In which category this data located? How can i search Windows Event collector data in XQL? THANKS!

  • 2587 Posts
  • 95 Subscriptions
Top Solution Authors