Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Resolved! Cortex XDR Data Lake

Hi, can you answer to this question? 

 

If a customer activates a TMS tenant and has not purchased a Cortex Data Lake instance. Palo Alto Networks will provide the customer with a free instance. What size is this free Cortex Data Lake instance? 

a. 1

...

XQL Query Assistance

Hi all,

I'm new to Cortex and creating XQL queries. I was looking for a way to detect a brute force attack (failed logins followed by a successful login). Are there any good resources available online or can someone help me get this query built?

 

Th

...

Resolved! Agent interface display language

Hey All, has anyone had to ever "set" a default language for the agent interface for a select group of users? 

 

Ideally, I would like to flip all endpoints from a specific location to French. 

 

If this is NOT possible, is there a way to set the lan

...

Parsing rules

Hello, 

 

I am sending Cisco Asa logs to Cortex XDR and XDR automatically creates parsing rule of "Ingest". When I am searching for "cisco_asa_rules" in query, I got a field named "raw" which contains detailed format of log: 

 

That is a detailed for

...

Resolved! XQL query between 2 dates

Hi,

 

I want to query a specific number of events between 2 dates.

 

I have this query below, but it is missing the "between current_date and last 5 minutes"

dataset = fortinet_fortiauthenticator_vm_raw | filter deviceSeverity != "information" | filt...

Resolved! Agent not communicating

Hello, If I ask, can you please answer to this question? 

The certificate used for decryption was installed as a trusted root CA certificate to ensure communication between the Cortex XDR Agent and Cortex XDR Management Console. What action needs to

...

Cortex XDR agent error 307

Hi all, I have an issue that started popping up with an agent installation - newly installed agents throw out a 307 error. the package is present on the xdr management console, and we are beneath the license limit. 

What can be the issue here?

Scan endpoint error

Hi, I need help, I have Cortex XDR policy to allow scans on the endpoint, however users are unable to start the scans, the option does not appear

I can only scan, with cmd as administrator (cytool scan start) , in the GUI I can't even do it as admini

...

tlmarques_0-1706887670317.png
tlmarques_1-1706887790216.png
tlmarques by L4 Transporter
  • 854 Views
  • 2 replies
  • 0 Likes
  • 2080 Posts
  • 82 Subscriptions
Top Solution Authors
Top Liked Authors