Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4397 Views
  • 0 replies
  • 3 Likes

Resolved! Broker VM cli Admin password

Greetings everyone, How can we get the admin password of broker vm? i have connected via ssh to the broker vm's cli now i need to do some actions which require admin's password Cortex XDR

Jira integration errors

Good day please is there a way to pass headers during the cortex-jira integration. we get this error that this header is required, but there is no option to pass headers. any fix or solutions to that is welcomed. thanks

KMgbachi_0-1777543372045.png

Need help with XQL datetime interval

Hello I would need some help regarding XQL. I'm trying to list files created between 2026-04-01 11:00:00 Eastern Day Time and 2024-04-02 16:00:00 Eastern Day Time. I'm having difficulties handling the syntax. Thanks in advance! PA

P.Forand by L0 Member
  • 446 Views
  • 2 replies
  • 0 Likes

Get all parent processes of a given process with XQL

I am trying to obtain a linear process tree for a specific process using XQL. Example:In the Causality Chain view, the process tree for Process X looks as follows: explorer.exe → Process Z → Process Y → Process X I want to write a query that returns exactly those three process events (excluding explorer.exe) that spawned the next process up u...

MaaHaa by L0 Member
  • 751 Views
  • 3 replies
  • 0 Likes

Resolved! Threat ID #9999' generated by PAN NGFW

Hello, I have turned off alerts on NGFW for Private URL, but I still get threat ID #9999. Can somebody a little bit more explain what this threat ID means? I am trying to clean it up, but still get these alerts.And it is not any kind of malicious traffic.It is usually connected with some internal web-pages. I can provide more info, if needed.Lukas

LukasB by L2 Linker
  • 21429 Views
  • 8 replies
  • 0 Likes

Cortex XDR FIM

Hi Team I am configuring File Integrity Monitoring (FIM) in Cortex XDR for Windows endpoints. I have defined a monitoring rule for the directory:C:\Windows\* However, within this path, I need to exclude specific subfolders from being monitored (for example, system or application folders that generate excessive or irrelevant events).I am not seei...

M.Rather by L1 Bithead
  • 477 Views
  • 1 replies
  • 0 Likes

XDR Automation Rules not triggering Playbook execution

I am experiencing an issue with XDR Automation Rules when attempting to execute a script. I have configured an automation rule to trigger a Playbooks when a specific event occurs. The Playbook is designed to run the built-in Quick Action: “Run Endpoint Script”, which executes a script registered in Action Center > Scripts Library. However, th...

.522643 by L1 Bithead
  • 416 Views
  • 1 replies
  • 0 Likes

Cortex XDR Playbooks – Most returning errors, looking for working use cases

Hi Community, I wanted to check in with the community regarding Cortex XDR Playbooks. Has anyone successfully executed playbooks within Cortex XDR and actually received meaningful results? In our environment, the majority of playbook executions end up throwing errors, and we're struggling to identify the root cause. We've tried several built-in ...

Cortex XDR integration with IBM QRadar

Hi All, We have a requirement to get cortex XDR Data(Alerts, agent audit logs) into IBM Qradar. Following the documentation, we took the approach of configuring syslog server in external applications, new configuration in notifications, and adding Cortex DSM app extension in QRadar. Due to security concerns, our QRadar team does not wish to ma...

MithunKT by L2 Linker
  • 9552 Views
  • 4 replies
  • 0 Likes

Integrating Cortex wth QRadar

Hello Everyone,Does the installed Cortex XDR for QRadar Version1.2.0 and config it via syslog allow receive Alerts directly from Cortex XDR into QRadar? I found https://apps.xforce.ibmcloud.com/extension/d12c3794f142ee334b4bbdc83d10347f but not able to find newer version. Can someone know if there is other way to receive alerts directly from C...

  • 2610 Posts
  • 98 Subscriptions
Top Solution Authors