Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4319 Views
  • 0 replies
  • 3 Likes

Endpoint shown as 'Connection Lost' - cannot reach

I have a user (my boss) who is one of several endpoints with a status of 'Connection Lost'. I'm not actually able to ping him from the DNS server when he is plugged in to the network at work; the XDR portal reports two IP addresses which are probably from his domestic wifi.Running the msi to install isn't possible because tamper protection is en...

TimGowen by L1 Bithead
  • 25579 Views
  • 8 replies
  • 0 Likes

Windows Defender Firewall blocking applications

Hello all,We are moving from Symantec Endpoint Protection (SEP) to Cortex XDR. If you are not familiar with SEP, it has its own firewall built in. When active, Windows Defender only manages a few aspects of the firewall. Since moving to having Cortex manage the firewall, we keep getting pop ups that Windows Defender is blocking some applications...

Integrating multiple Cortex XDR with QRadar

Hi, Thought I would give livecommunity a shot on this. We have been looking into integrating several Cortex XDR instances into a single QRadar instance but have come across an issue where it does not seem to let us change the syslog identifier name on any of them. This leads to a problem distinguishing the different XDR tenants from each other a...

Edmund66 by L0 Member
  • 3527 Views
  • 1 replies
  • 0 Likes

Device Control

Can Cortex XDR prevent the use of other USB devices other than Disk Drives, CD-Rom Drives, and Floppy Disk Drives? If one of my users plugs in a printer, can that be denied? Can the same be done with SD cards?

XDR Network location configuration & VPN

Hello! On all our endpoints we are using XDR with firewall(Uses built in Windows firewall) and Palo Alto GlobalProtect VPN connecting to PanOS devices at our office. We use split tunneling for the VPN, that means that only specified traffic goes through VPN tunnel to access internal resources and Active Directory services, the rest stays out of ...

mdsgn1 by L1 Bithead
  • 4668 Views
  • 2 replies
  • 0 Likes

XDR policy targeting using AD

Hi there, When we are trying to target a policy using AD group some of the listed endpoints is not a member of selected group.To get more clarity we selected a group which only contains users and even then the result listing some random endpoints.Is it normal behavior or am I missing something herehow can we target policies using AD groups and c...

HafisM by L0 Member
  • 3613 Views
  • 2 replies
  • 0 Likes

Cortex XDR with Carbon Black

Hi All, I know it is a stupid question but I am encountering this situation that we need to install Cortex XDR working with Carbon Black (it's a long story). May I know if anyone experienced this before or any suggestions on exclusion? Thank you so much Best Regards,Elroy

Resolved! Cortex XDR report

Hello Live community, I have a question about the report on Cortex, i want to know if the “Infected Endpoints” comes as default in Cortex reports or if we need to configure something to show that option?Do the widgets "incidents by source" or "Top incidents (Top 10) " display the infected Host? I suppose that incidents by source will be the clos...

Resolved! How do we set an incident title ?

Hello all, I feel this is a silly question but I don't know the answer and can't find it. We have a lots of incident comming from Splunk integration with the following title: ":". We can't find anywhere inside classifier or mapper how to set the title from a value of the input Splunk log. Can you help please ? Best regards,Alexandre

Using Windows environment variables in XDR Firewall

Hello, Configuring host firewall via XDR and I cannot seem to get the Windows environment variables running.Basically, there's an implicit deny for inbound/outbound connections, so there are applications that require some internal/localhost connections that are blocked. Due to this specific allow rule for such an application has to be made - bas...

nikoo by L3 Networker
  • 3612 Views
  • 1 replies
  • 1 Likes

Who/How to send feedback on "Cortex XDR Scheduled Maintenance on January 17" email notification?

Hello LivecommunityI believe there are Palo Alto representatives that do some level of monitoring and participation in this Forum, would they or someone know where you provide feedback to enhance notifications such as the one listed above, that describes a update that will occur on our Tenant but if your a member of more than one Tenant, there i...

KRisselada_0-1609960296061.png

Log storage and resources usage

Hi everyone! How much space do the cortex xdr agent records use? I understand that in the agent profile configurations you can set the quota for log storage, by decreasing the quota the logs are automatically purged ??, for the last one on my machine local that has the cortex agent in which folder are the logs stored to see the accumulated to da...

Resolved! Cortex & Wildfire - The WF detailed analyze reports arrives with a delay.

Dear PA community members, I've done the research but could not find any info bout the Wildfire limitations nor any issues which could explain why in some cases the WildFire Report arrives with delays. As per WildFire Analysis Concepts: https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/endpoint-securi...

  • 2583 Posts
  • 95 Subscriptions
Top Solution Authors