Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 4100 Views
  • 0 replies
  • 3 Likes

Inquiry regarding Tenant Backu & Recovery

I am looking for detailed information regarding the backup and recovery lifecycle for a Cortex XDR tenant. Specifically, I have the following questions:

  1. Automated Backups: Does Palo Alto Networks perform regular backups of tenant-specific configurat

...

R.Abdeen by L0 Member
  • 217 Views
  • 1 replies
  • 0 Likes

Cortex Management Report

I want to know if I can generate a report of Cortex's actions over the last year or 3 months, such as what he blocked, quarantined, isolated, etc., but in a graph format. I tried using a widget library, but I can't find a way to represent that action

...

XDR 5.0 - opinion

Cortex Cortex XDR 5.0 tenant. What's your opinion

https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-5.x-Release-Notes/Release-Information

 

 

tlmarques_0-1770656806817.png
tlmarques by L4 Transporter
  • 568 Views
  • 8 replies
  • 0 Likes

Resolved! Sending USB Alerts via syslog (Cortex XDR)

Hello,

We have received a request asking whether it is possible for administrators to receive alert emails whenever a USB device is connected to any endpoints.
(*Currently, the USB policy in Exploit – Device Configuration is set to Read Only.)

(* I th

...

YSONG464633_0-1770612974843.png

Resolved! Cortex XDR Tenant Auto-Upgrade 3.17 → 5.0: UI mixed theme, AI pages stuck loading, Marketplace/Playbook Catalog empty + ingestion quota warning

I tried to open a Support case, but none of the available issue categories allowed me to create a case and I was redirected to Live Community for assistance. I’m posting here to get guidance on the likely root cause and recommended next steps.

 

Afte

...

Resolved! Microsoft Photos.exe

Hi,

Does anyone experience receiving alerts from photos.exe due to "Suspicious File Modification" and the Module is "Anti-Ransomware Protection" even the program is legitimate?
Other factors I'm seeing is due to possibly outdated version of the said p

...

J.Indoc by L0 Member
  • 1353 Views
  • 2 replies
  • 0 Likes

Cortex XDR Device Control Violation Alerts

Hi All,

 

We enabled device configurations to block external devices connecting to endpoints in the organization and its work fine. In the Cortex XDR console, I can see the device control violations.

 

We want to create alerts to detect the Device Co

...

Brew package manager for MacOS

We utilise Brew for package manager for our Mac in our organisation and we have over 100+ engineers using it to manage their operating environment. Cortex doesnt pick up any of the applications installed via brew or any of the vulnerabilities associa

...

Vulnerability assessment report

Hello,

In viewing this report I've noticed its still flagging servers that have been patched already and wondering how often that checks against all endpoints? I can go on a server and its not showing any updates needed and then look in the report an

...

  • 2540 Posts
  • 96 Subscriptions