Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4322 Views
  • 0 replies
  • 3 Likes

Resolved! Cortex XDR Windows Event Collector

Hello!I set up Windows Event Collector and data is coming to XDR. But i want to see data which come from Windows Event collector. In which category this data located? How can i search Windows Event collector data in XQL? THANKS!

XDR Global BIOC rules

Hello.If Restrictions profile for Windows is default then they don`t directly affect windows endpoints. We must edit and and apply them for getting protection in endpoints. But in Linux it is not same. Even if Restriction profile is default, XDR can generate alert base on global BIOC. I want to know why there are such difference? Thanks!

Cortex XDR Broker VM (proxy server)

Hello.In XDR Broker VM i enable proxy server and configure as follows:Type:HTTPAddress: 192.168.6.167Port: 8080 But it is not work and in configuration status i see "in progress" even through 3-4 hours.I want to know if is there anybody who configured this proxy successfully and how? Thanks!

Resolved! Uninstall agent rom MacOS

Hello, We want to uninstall an agent from MacOS, but we do not have the admin password. And we can't reset the password because the tenant was deleted it. So the agent does not have administration from web console. I try with "Passowrd1", it doesn't work. Does someone know how to uninstall it? I know that for Windows, there is a "special cleaner...

iscott by L2 Linker
  • 7155 Views
  • 2 replies
  • 0 Likes

Resolved! Piloting XDR 7.3.1, policies seem more stringent- blocking previously allowed scripts and .exes

We are in the process of updating our endpoint XDR agents from 7.2 to 7.3.1. We are testing on a small pilot group and finding that scripts and executables that we previously ran are now being blocked. Granted some these scripts are stopping and starting services and removing files. We are concerned if we deploy it site-wide that we'll have m...

WORRELLR by L0 Member
  • 3740 Views
  • 3 replies
  • 0 Likes

Cortex XDR Windows Event Collector

Hello!My question is about Windows Event Collector.Why we need Windows Event Collector? Don't XDR Agents collects all needed information from Windows endpoints? Can Windows Event Collector give us useful information than Agents?

Cortex XDR files modified

We have some systems that are locked-down with software that prevents modifications to files/directories, and I'm wondering what are the paths that Cortex needs to be able to modify? For example, when it downloads the latest definitions, what does it need to modify? Is there any data stored in the registry as well?

Resolved! About Behavioral Threat Protection (BTP) rules

Hi Everyone:Does anyone know where I can find Behavioral Threat Protection (BTP) rules?For example, a behavioral threat is detected (rule: pp.epm_for_malware_behavior_j01)or Behavior threat detected (rule: bioc.pp.ransom_prevention_final)What do these two rules mean?Thank you Richard

Resolved! Cortex xdr 7.0 and 7.1 agent end of life

Hi All, We need to upgrade the cortex agent from version 7.1 to 7.3 via console. My concern is how can we exclude a certain range of endpoints (Suppose we have 5000 endpoints and we want to exclude 800 endpoints) from upgrading. I have created an endpoint group that we want to exclude. but not sure how to exclude. Can anyone please advise? Rega...

AsifSid by L2 Linker
  • 9023 Views
  • 7 replies
  • 0 Likes

Resolved! Duplicate endpoint

Hello, I regularly reinstall my endpoints. This creates duplicates for me and it's difficult to locate all the duplicates. Is there a query to see all endpoints as duplicates?

Besnard by L0 Member
  • 7447 Views
  • 4 replies
  • 1 Likes

Resolved! Cortex XDR/Data Lake

Hello. I can not see any logs in my Cortex Data Lake. Also when i go to Explorer app in Hub it is empty. Firewall Logs is also seem empty( I forward logs to Data Lake with Broker VM from Fortigate). Can anybody explain me this situation? NOTE: I have Cortex XDR Pro per Endpoint and Cortex XDR Pro per TB licenses. Thanks!

  • 2588 Posts
  • 95 Subscriptions
Top Solution Authors