Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Deploy Cortex Agent via Intune

Has anyone managed to successfully deployed the Windows Cortex agent via Intune?

 

I have an app configured and deployed, but it's not working as expected. Likely because of the App protection policy in Cortex. I have version checking in the App turn

...

CORTEX XDR - Endpoint delete

Good morning dears,

I want your opinion, I have devices disconnected for a long time (3 months) so I am planning to delete from the console and recover the licenses.

My question is whether the device will have problems uninstalling when it is reconne

...

Masquerading - 4203898100

We're getting this alert whenever we're trying to install filezilla.exe or Opening Filezilla.exe. We're using the same installation file like before and also tried with the latest versions. But still it's getting blocked by XDR. Any idea why is that

...

Error code:307 on MAC, Cortex Agent 8.2.1

I get a "Cortex XDR Policy update failed!" message
Error code: 307

 

This happens on a MAC (updated).

 

I'm also unable to uninstall the agent.

I was able to do it once, then installed it again, and now my tennant's global uninstall password doesn't w

...

CFriacas by L0 Member
  • 1336 Views
  • 1 replies
  • 0 Likes

Data Lake Activation Button

Hello, 

 

I have Cortex Pro per GB license of 165 GB. I have also bought Cortex Data Lake. When I go to Support Palo Alto--> Products--> Assets tab, I can see Data Lake and its Auth Code. But when I go to https://apps.paloaltonetworks.com/apps , I se

...

JahidAliyev_0-1708693524066.png
JahidAliyev_1-1708693647357.jpeg

Resolved! Software Inventory query

Hi,

 

I'm using following query to get software inventory and it is working well. However to the results, as last column, I would like to add number of hosts which have particular software.  Could somebody advise how to do this please?

 

dataset = ho...

Cortex Visio Stencils

I am making customer diagrams for Cortex XDR, XSOAR, and the data lake. I can easily find hardware visio stencils, but nothing for Cortex. Does anyone know where I can find Visio stencils? This link has nothing: https://www.paloaltonetworks.com/compa

...

Resolved! Cortex XDR Data Lake

Hi, can you answer to this question? 

 

If a customer activates a TMS tenant and has not purchased a Cortex Data Lake instance. Palo Alto Networks will provide the customer with a free instance. What size is this free Cortex Data Lake instance? 

a. 1

...

XQL Query Assistance

Hi all,

I'm new to Cortex and creating XQL queries. I was looking for a way to detect a brute force attack (failed logins followed by a successful login). Are there any good resources available online or can someone help me get this query built?

 

Th

...

Resolved! Agent interface display language

Hey All, has anyone had to ever "set" a default language for the agent interface for a select group of users? 

 

Ideally, I would like to flip all endpoints from a specific location to French. 

 

If this is NOT possible, is there a way to set the lan

...

  • 2075 Posts
  • 81 Subscriptions
Top Solution Authors
Top Liked Authors