Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4322 Views
  • 0 replies
  • 3 Likes

Resolved! How do we set an incident title ?

Hello all, I feel this is a silly question but I don't know the answer and can't find it. We have a lots of incident comming from Splunk integration with the following title: ":". We can't find anywhere inside classifier or mapper how to set the title from a value of the input Splunk log. Can you help please ? Best regards,Alexandre

Using Windows environment variables in XDR Firewall

Hello, Configuring host firewall via XDR and I cannot seem to get the Windows environment variables running.Basically, there's an implicit deny for inbound/outbound connections, so there are applications that require some internal/localhost connections that are blocked. Due to this specific allow rule for such an application has to be made - bas...

nikoo by L3 Networker
  • 3619 Views
  • 1 replies
  • 1 Likes

Who/How to send feedback on "Cortex XDR Scheduled Maintenance on January 17" email notification?

Hello LivecommunityI believe there are Palo Alto representatives that do some level of monitoring and participation in this Forum, would they or someone know where you provide feedback to enhance notifications such as the one listed above, that describes a update that will occur on our Tenant but if your a member of more than one Tenant, there i...

KRisselada_0-1609960296061.png

Log storage and resources usage

Hi everyone! How much space do the cortex xdr agent records use? I understand that in the agent profile configurations you can set the quota for log storage, by decreasing the quota the logs are automatically purged ??, for the last one on my machine local that has the cortex agent in which folder are the logs stored to see the accumulated to da...

Resolved! Cortex & Wildfire - The WF detailed analyze reports arrives with a delay.

Dear PA community members, I've done the research but could not find any info bout the Wildfire limitations nor any issues which could explain why in some cases the WildFire Report arrives with delays. As per WildFire Analysis Concepts: https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/endpoint-securi...

Recent Change - creation of Threat ID #8002 Alerts in Cortex

Hello all, Beginning on or around 14/15 December, I began to notice we were commonly generating the following Alerts in Cortex:Alert name: Threat ID #8002Description: Scan DetectionAlert Source: PAN NGFWCategory: Scan Detected via Zone Protection ProfileThis is occurring on two different customers that have entirely different IT teams, but do bo...

KRisselada_0-1609434433229.png

Resolved! Feature Request: Ability to add a 'Comment' when Bulk Uploading IOC Rules in XDR

When adding IOC's to XDR, adding a comment is a useful way to keep track of where the IOC originated from. When an alert is triggered from that IOC, the analyst can review the IOC rule and read the comment for context. When 'bulk' uploading, using a file for example, there is no comment field. Is it possible to add the ability to make a comment...

AlCurran by L0 Member
  • 5808 Views
  • 2 replies
  • 0 Likes

The Cortex XDR version upgrade on my computer is not progressing from "In progress".

The Cortex XDR version upgrade on my computer is not progressing from "In progress".When grouping and upgrading some agent has stuck on "In Progress" situation, we cannot even cancel and stop it.Even rebooting the computer and then upgrading again does not work.Could you please advise how we can solve this issue?Thank You

mkakara by L0 Member
  • 5985 Views
  • 1 replies
  • 0 Likes

Cortex XDR Alert Dump File Analysis

Is there a way we can analysis the dump file when a behavior based alert is generated for an incident? We would like to analysis the process dump file with volatility for windows 10 machines.Thanks for the help in advance.

App-ID for endpoint-based BIOC rules

Currently, BIOC rules can be created for "NETWORK" (endpoint-based) or "NETWORK CONNECTIONS" (NGFW-based) but only the latter supports the usage of App-ID and VPN infrastructure isn't always in place or available. Are there any plans to add this?

2020 ∕ 09 ∕ 22 16꞉01꞉10 - Rule_Builder_-_Cortex_XDR_-_Google_Chrome.png
2020 ∕ 09 ∕ 22 16꞉01꞉38 - Rule_Builder_-_Cortex_XDR_-_Google_Chrome.png
2020 ∕ 09 ∕ 22 16꞉02꞉07 - Rule_Builder_-_Cortex_XDR_-_Google_Chrome.png

Feature Request – Add ability to capture memory dump

During a recent investigation our team came across a situation where we needed to take a forensic image of a device on our network. Prior to taking the image, we had hoped to utilize Live Terminal in order to remotely capture a memory dump to get a head start on our investigation. Unfortunately, we ran into several limitations including the fil...

GoToMeeting Whitelist

Does anyone know how to whitelist the GoToMeeting download? It is an EXE but the client agent blocks it. When I attempt to whitelist it, EVERY SINGLE download is a different hash value making it impossible to whitelist. Thanks for any suggestions.

  • 2589 Posts
  • 95 Subscriptions
Top Solution Authors