Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4332 Views
  • 0 replies
  • 3 Likes

XQL/BIOC - web

Hello, Can you tell me in which dataset I can find the following data? URL addresses User Agent With this information, can we create a rule that is based on defined values ​​and then generate an alert based on it or block it within the Restriction Profiles?Can someone share such a query or rule.

arekf by L1 Bithead
  • 803 Views
  • 2 replies
  • 0 Likes

Cannot update user role to another user

This is about user permssion settings, I'm already the account admin of the XDR tenant already.Currently, the user scope is set to all, i want to change the scope for specific user.But there is no update user permission when right click on user does anyone share the same experience? Cortex XDR

XQL Timeseries Chart

I'm trying to build a timeseries chart that counts alert volume per day and that fills in zero values for days with no data. I have the following XQL that populates days with data but I'm unable to fill in a zero for all other days between now and the last event. dataset = alerts | bin _time span = 1D timeshift = 1736879866 timezone = "America...

XDR Agent - retrieve more information events

Hi, I have a question. I'm seeing XDR events with "Memory Corruption Exploit" generated by the XDR Agent... Cortex XDR I know this typically happens when users open a DOCX file with macros. My question is: Is there a way to collect information related to the macro? I'm asking because, in the artifacts, I only see the initiator "WINWORD.EXE"...

tlmarques by L4 Transporter
  • 974 Views
  • 1 replies
  • 0 Likes

Broker VM - Local Agent Settings Applet Error

Hi Team,As observed, we're getting the below error in the local agent settings applet in our broker vm's. We have three broker vm's in place and all of them are showing the same error. We have not made any changes in the configurations. Could you please assist in fixing this at the earliest? All the XDR service URL's and ports are already whitel...

SKhurana_0-1739781898751.png

Resolved! Cortex XDR folder taking up space

Hello Cortex Team, On one of our server endpoint, the Dump folder located on the path : ProgramData\Cyvera\LocalSystem\Dump is taking a lot of space. We already tried to clear the database of said agent, no difference. (see screenshot before and after) The endpoint does not enough free space to generate the supportfile. Please Could you...

Resolved! Connect New XDR Tenant with Existing Broker VM

Hello We are migrating our existing XDR tenant due to region issue. We have got our new tenant and Basic configurations are done. I have a question regarding the BrokerVM. Do we need to create new broker VM for the new tenant or we can use our existing Broker VM ? and If possible to connect the new tenant with the existing Broker VM whats the pr...

Resolved! File Integrity Monitoring FIM using Auditbeat module

Hello, Looking to set up FIM using the Cortex XDR agent and from what I have found so far, it seems unsupported. Has anyone set up FIM using any method? The only possible option I have found so far is maybe using an auditbeat with the FIM module: https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-module-file_integrity.html#_ho...

Broker VM Log ingestion and forwarding

Hi, My query is can we forward one broker VM logs to another broker VM. Use case is I have BVM A and BVM 2, 1. I want to ingest logs into BVM A from Agents or other log sources. 2. Then forward logs from BVM A to BVM B. 3. BVM B will send logs to XDR or XSIAM tenant. I found one way which is by rsyslog or any other sys...

P.Ghule by L1 Bithead
  • 1577 Views
  • 3 replies
  • 0 Likes

Show results only with matching fields from two different queries

I am trying to combine the results from two queries, one using dataset=xdr_data and one from preset=xdr_file. But, I only want to see the results when the same "agent_hostname" appears in both queries. In other words IF agent_hostname from filtered xdr_data = agent_hostname from filtered preset, show me all the results with those agent_hostnames...

Policies without certificate enforcement enabled warning message

Hi Team, Recently I got a warning message in cortex saying that "Some of your endpoints have policies without Certificate Enforcement enabled". And by checking it further I could see that, this is to increase protection on the agent's communication by enforcing the use of root CA provided by Cortex (rather than on the local machine). It was...

Aneesh by L1 Bithead
  • 16189 Views
  • 24 replies
  • 0 Likes
  • 2593 Posts
  • 97 Subscriptions
Top Solution Authors