Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Veeam Server high CPU Cortex XDR

Hello,

We have a server with Veeam Backup, and we are noticing high CPU usage from Cortex.

 

We have seen that some exceptions might need to be applied:

 

https://www.veeam.com/kb1999

 

Would this apply to Cortex?

 

Best regards.

Resolved! Finding if a URL was visited using XQL in Cortex

We wanted to see if we could use XQL to query for if a URL was visited in our environment. Is there a way to structure a working query for this using XQL? We've tried unsuccessfully so far, so we are turning to you, the community.

 

Thank you for any

...

Split nested JSON

I have a field named "ModifiedProperties" and it has values like this below, I cant for the life of me figure out how XQL splits these up, Splunk uses SPAN or MVexpand and it works like a champ but i cant figure out what function does the same thing

...

Resolved! Detect delete agent with XQL.

I kindly ask for your assistance with an XDR XQL query language script to identify devices in the network that do not have the XDR agent installed. Additionally, it would be helpful if the users could be identified from AD or through the DHCP on the

...

Resolved! XQL For Silent Log Source

below is the query so far but what we are trying to do is get a silent log source detection. For example, one of the log source names has not sent a log in x number of hours then alert. Any suggestions?


dataset = panw_ngfw_traffic_raw | fields log_sou

...

Resolved! Azure AD and InTune

Hi Palo Live Community, I'm hoping that someone has worked with Cortex XDR and Azure InTune.

 

I'm trying to find a dynamic way to apply an extension profile  (block USB), in Cortex XDR, targeting specific endpoints that reside in Azure InTune.

 

Bef

...

Cortex XDR agent removal

Hi all,

In one of our endpoints XDR agent triggerd an alert named '

Suspicious file modification detected '  cmd is 'C:\Windows\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09}'  after this XDR service cyserver was stopped , now
...

Cortex XDR to google chronicle

Dear community,

One of my client is using Google chronicle as their SIEM .

They would like to know and understand what is required on Palo-Alto Cortex XDR side to send their logs to Google Chronicle . 

 

Is there a simple way to do this ? 

Do we need

...

davoxxxx by L0 Member
  • 187 Views
  • 1 replies
  • 0 Likes

XDR 8.5.0 print servers error

Hi, we are experiencing issues with Cortex XDR agent version 8.5 on our PrintServer

We had agents running version 8.4.0 without any errors, but after upgrading to version 8.5, we started encountering printing problems on the servers.

The error is:
Fault

...

tlmarques by L3 Networker
  • 1253 Views
  • 5 replies
  • 1 Likes

Agent Configuration - Password strength

Hi, I'm struggelin' to set a new password. Have tried all kind of combinations. Allways get "Does not meet the requirements." 

 

Please see attached for an example..

 

I've seen earlier discussions on this. Something does not seem to be working as in

...

Cortex xdr with RedHat Quay with Clair

Hello PA community,


For all images on customer s OpenShift clusters, they have a policy that all images have to be stored in their RedHat Quay with Clair.

Customer has tried to setup a mirror with the "europe-west4-docker.pkg.dev/xdr-eu-2009645628112

...

  • 2019 Posts
  • 81 Subscriptions
Top Solution Authors