Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4529 Views
  • 0 replies
  • 3 Likes

Cortex XDR Delayed Global Protect Connection Timing.

We are transitioning from MDE to Cortex XDR and a number of users have stated that connection time takes from 2-10mins to take place after a full reboot / cold start.This is inconsistent.MDE is currently in EDR in BlockMode - which was the advice given to be the correct status during transition in that it is in Passive mode on those specific end...

RobKen by L0 Member
  • 158 Views
  • 1 replies
  • 0 Likes

Trial Access for Cortex XDR

We're working on integrating Cortex XDR login with our system and would like to test the access management/SSO integration before rolling it out further. Could you let us know: Whether a trial version of Cortex XDR is available that we could use for integration testing, and If not, what alternative options exist for testing the access managemen...

antons by L1 Bithead
  • 288 Views
  • 5 replies
  • 0 Likes

Data Ingestion License Violation

After our Cortex XDR tenant was upgraded to 3.9 we started receiving the following error: "License Violation warning Based on a 7 day average calculation from February 24th 2024 to March 1st 2024, your daily ingestion quota is exceeded." Looking at the Data Ingestion Dashboard it appears our NGFW data ingestion is reporting to has significantl...

jruck by L2 Linker
  • 4953 Views
  • 8 replies
  • 0 Likes

Inquiry regarding Tenant Backu & Recovery

I am looking for detailed information regarding the backup and recovery lifecycle for a Cortex XDR tenant. Specifically, I have the following questions: Automated Backups: Does Palo Alto Networks perform regular backups of tenant-specific configurations (Security Policies, Profiles, XQL queries, etc.)? If so, what is the standard frequency? ...

R.Abdeen by L0 Member
  • 945 Views
  • 2 replies
  • 0 Likes

Resolved! XQL Help - Any AI tools, query library?

Wondering if there are plans to help build queries? Something as simple as looking for a file called "testfile" requires the query with the below code: |preset = xdr_file|filter action_file_name contains "testfile" Another example that we are currently working on is a way to search for specific models of computers. As an example: "find all Latit...

J.Suter by L2 Linker
  • 3761 Views
  • 5 replies
  • 1 Likes

Resolved! no incidents generated since May 20?

Our Cortex XDR instance stopped generating incidents when detecting malware and other threats. (Somewhat similar to "Cortex XDR - Blocked Hashes on newer systems do not show in Incidents" - except in our case, this is across the board on all devices, for all threats and behaviors.) (If we initiate a malware scan on the affected device, an incide...

Resolved! Orphaned Cortex XDR Agent enforcing USB read-only on personal laptop

Hello, I have a personal Windows 11 Pro laptop with Cortex XDR Agent 9.2.0 installed. The agent is no longer connected to any management server and the GUI shows: Connection: No connection to server However, Device Control is still active. Every time I connect my Samsung T7 Shield external SSD, I receive the notification: "Cortex XDR | Device Co...

Cortex XDR greatly affects C++ build performance

I have a C++ project that I build using Visual Studio 2022. When I build it on a PC with Cortex XDR installed, the build takes more than 3 hours. It looks as if Cortex XDR is analyzing every .obj file generated during the build process. Without Cortex XDR, the same build takes slightly less than 1 hour. The Cortex XDR application and its configu...

Understanding Inline Cloud Analysis C2 Detections and False Positives in Cortex XDR

Hi everyone, I am currently investigating several Cortex XDR incidents that originate from Palo Alto Networks Firewall Security Profiles, specifically detections related to Inline Cloud Analysis, Anti-Spyware C2 classifications. What I am trying to better understand is why a relatively large amount of legitimate-looking web traffic is being clas...

T.Fink by L1 Bithead
  • 903 Views
  • 3 replies
  • 0 Likes

How to Query WildFire Malware Prevention Events Not Generated as Issues

Hello We are currently operating approximately 4,800 agents. During the initial deployment, a large number of false positives were generated by WildFire Malware events, so we applied an exception to prevent these events from being generated as Issues. However, we have recently received user reports of cases suspected to be blocked by this policy...

.522643 by L1 Bithead
  • 220 Views
  • 1 replies
  • 0 Likes

Resolved! Case resolution center - no recommendations

Hello. I have never seen any recommendations in the resolution center when reviewing cases. Respective playbooks are configured and enabled; however, there's nothing. Our Palo SME stated it might be an XSIAM thing and not and XDR Pro thing, but I feel like something should be there. Anyone have any insight to this or tips? Thank you.

XQL to get details of endpoint connection time

Hello Team, I need to create a report in Cortex XDR to identify endpoint connection activity within a specific time window. The requirement is not to know when the endpoint was first registered in Cortex, so `first_seen` does not apply here. What I need is to identify: 1. Endpoints that changed from DISCONNECTED to CONNECTED during the selected ...

  • 2641 Posts
  • 101 Subscriptions
Top Solution Authors