Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 1331 Views
  • 0 replies
  • 3 Likes

Cortex Prevention Profiles

Hi Team,


Customers found a few of the security modules disabled by default and they wish to enable the modules.
- Below are the modules that the customer wishes to enable for the endpoints.
“Agent Certificates”, “Data Generation Providers”, “PowerShell

...

H.Patri by L1 Bithead
  • 192 Views
  • 1 replies
  • 0 Likes

Endpoint is isolated

Basically I have a laptop loan from a school for the fall term, I downloaded a game which was counter strike source which I owned to keep me busy during breaks. Cortex basically told me it was a “Virus” and then ended my internet connection, Now I ca

...

tacbig01 by L0 Member
  • 243 Views
  • 1 replies
  • 0 Likes

Resolved! XQL Help - Any AI tools, query library?

Wondering if there are plans to help build queries? Something as simple as looking for a file called "testfile" requires the query with the below code:


|preset = xdr_file
|filter action_file_name contains "testfile"

Another example that we are current

...

J.Suter by L2 Linker
  • 2084 Views
  • 4 replies
  • 1 Likes

Create custom widget to display data from Jamf

Hi Everyone,

I'm wondering if it's possible to fetch data from JamfPro MDM solution for example user_name, ip address and mac details and add it as a custom widget to the cortex dashboard. If this is possible kindly guide me on how to achieve this.


#ap

...

H.Patri by L1 Bithead
  • 204 Views
  • 2 replies
  • 0 Likes

Upgrade Tenant 3.x to 4.x question

Hi Expert ,

 

I would like to know or anyone have experience about upgrade tenant cortex xdr  from 3.x to 4.x if older we have just prevent lic and then have to upgrade lic to pro can upgrade existing 3.x to 4.x ?

 

Thank you

Resolved! Threat ID #9999' generated by PAN NGFW

Hello,

 

I have turned off alerts on NGFW for Private URL, but I still get threat ID #9999. 

 

Can somebody a little bit more explain what this threat ID means? I am trying to clean it up, but still get these alerts.

And it is not any kind of malicious tr

...

LukasB by L2 Linker
  • 16285 Views
  • 6 replies
  • 0 Likes

Cortex XDR Agent setup

Hi folks

do you have idea from where i can download Cortex XDR Agent 8.8.1 MSI file, we wanna to run a batch script for uninstall it

 

PS: our license its expired and we cannot get it from the XDR portal

A.Warid by L0 Member
  • 313 Views
  • 1 replies
  • 0 Likes

Cortex XQL "Let" replacement

Hi, 

 

I'm wondering if anybody knows a method, I can use to join multiple queries within the same XQL query. 

I have 3 separate queries which return a count of vulnerabilities for each region of logs. How do i merge these 3 queries to return a table

...

  • 2416 Posts
  • 89 Subscriptions
Top Solution Authors
Top Liked Authors