Cortex XQL help
Hello Dear Community, I want to count events based on specified time periods. For example I want to query hosts that scanned more than 50 hosts in 10 seconds. How can I write XQL in that case?
Cortex XDR
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.
Hello Dear Community, I want to count events based on specified time periods. For example I want to query hosts that scanned more than 50 hosts in 10 seconds. How can I write XQL in that case?
Cortex XDR
Hello dear community,
are you using the above mentioned module on windows notebooks with public routable ip addresses?
Is this firewall module recommended for such public facing scenario?
BR
Rob
Hello,
I have a working XQL query that deals with Host Connectivity. Can I configure this to run as a scheduled report and only if there are results the report can be sent by email?
I do not want to receive empty reports. Can this be done in XQL or
...
I do not think this is in the correct Board, but I could not find a Cortex XDR channel.. First time posting so I am sure I missed it.
I have Cortex XDR and we are trying to see what firewall is sending the largest amount of data by GB Ingest. We a
...
Good afternoon,
Is there a way to see the logs that are generated in Device control Violations?
I know that using preset = device_control in XQL we can see devices but this preset does not give me all the data that appears in the Violations section..
...
I followed the instructions on the website,and there was a problem
Hello all experts,
From Agent Release below, v8.5 supposed to be released by 30Jun2024.
https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Agent-Releases/Cortex-XDR-Agent-Releases
However, 8.5 was not shown from the pull down menu wh
...
XDR agent was successfully installed on CentOS, but I saw it on endpoints all endpoints. I checked the installation logs to ensure that it was installed successfully.
The XDR agent communicates through the broker VM, and their communication is also
...
Hi community,
I have a query regarding Cortex XDR collectors. When installing collectors on the local DOM servers, what types of logs does the Cortex XDR console retrieve? How can these logs help with the investigation of incidents?
Hi team
2 questions but related here:
1) We need to downgrade from 8.4.x to 8.3 CE. Is this possible to just installer a CE over the existing 8.4.x? Or an uninstall is required...?
2) Is there any reason why I can't see a CE version listed (screensh
When we move an agent to a new management server, what would happen to the logs and telemetries we have on the old tenant? Would they be retained as per the usual policy or would they just get purged?
Also if we then move it back to the old tenant,
...
I have encountered the following issue of failed agent upgrade on a Windows laptop, showing the following message:
XDR Agent failed to upgrade from version 8.4.0.51691 to version 8.5.0.624 on LAPTOP-xxxxxxx with error: Windows Installer DB: Current
...
Hi,
How we can monitor the scenario like, when a cortex connected workstation's IP address change?
Whether it is possible to create a rule/bioc in cortex xdr for monitoring the above mentioned scenario ?
Cortex XDR Cortex Data Lake
Thanks
Chr
...
I am using Hyper-v VM's on windows 2019 server
After automatic deployment (not managed by me) of Cortex XDR agent version 8.4.0 on that server
Assigning GPU's from host to the VM's getting roll back automatically within seconds in front of my eye
...
Hello once again,
Does anyone know if it is possible to customize the message that is sent to the endpoint when it is isolated?
Currently XDR just displays a message for 5 seconds that says 'The Cortex XDR agent has stopped network access on your
Subject | Likes |
---|---|
3 Likes | |
2 Likes | |
2 Likes | |
1 Like | |
1 Like |