Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4392 Views
  • 0 replies
  • 3 Likes

Broker VM Log ingestion and forwarding

Hi, My query is can we forward one broker VM logs to another broker VM. Use case is I have BVM A and BVM 2, 1. I want to ingest logs into BVM A from Agents or other log sources. 2. Then forward logs from BVM A to BVM B. 3. BVM B will send logs to XDR or XSIAM tenant. I found one way which is by rsyslog or any other sys...

P.Ghule by L1 Bithead
  • 1753 Views
  • 3 replies
  • 0 Likes

Show results only with matching fields from two different queries

I am trying to combine the results from two queries, one using dataset=xdr_data and one from preset=xdr_file. But, I only want to see the results when the same "agent_hostname" appears in both queries. In other words IF agent_hostname from filtered xdr_data = agent_hostname from filtered preset, show me all the results with those agent_hostnames...

Policies without certificate enforcement enabled warning message

Hi Team, Recently I got a warning message in cortex saying that "Some of your endpoints have policies without Certificate Enforcement enabled". And by checking it further I could see that, this is to increase protection on the agent's communication by enforcing the use of root CA provided by Cortex (rather than on the local machine). It was...

Aneesh by L1 Bithead
  • 16858 Views
  • 24 replies
  • 0 Likes

Resolved! Need help - BIOC / Script / XQL?

Hey everyone. I need some assistance in looking at this logically. We have an identified PuP in our environment that is persistent. It creates a scheduled task and if you don't remove that, your PuP that you deleted will be back in no time. Is there a methodical and easy way to find that scheduled task (with the information we have, e.g., ke...

CraigV123 by L3 Networker
  • 1951 Views
  • 2 replies
  • 0 Likes

Interpreting alerts on XDR

Hi, The alerts on XDR and very much rigid and not readable even to the support personnel, whenever I raise a case they keep checking with other teams teams and higher support levels to get details, for example how to interpret the below, it says suspicious DLL detected, however many of these DLL's are part of known applications and are intact, h...

eXtended Threat Hunting (XTH) Module

Hi team, Got a renewal quotation with new XTH module. Heard eXtended Threat Hunting (XTH) Module is about query the raw data for threat hunting. Still not so sure what is the new module is used for? What is the use case to purchase this lic in addition to XDR Pro. Without the XTH, what is limited when comparing with XTH lic on? Regards, SDG

Query: All vulnerabilities under 29 days

I created this query to identify all vulnerabilities under 29 days: dataset = va_cves| alter days = timestamp_diff(current_time(),publication_date ,"DAY")| filter days > 0 and days < 30|arrayexpand affected_hostsIs there a way to tie in IP Addresses from a different dataset (e.g. dataset = endpoints) and match them to the computer names...

Arcon Onboarding of Broker VM's

Hi Team,We are planning to on-board the broker vm's to arcon for which we need the hostname and the user id of these broker vm's. Could you please assist how to get these details for the broker vm's to get it onboarded to arcon. These broker vm's are ubuntu Linux systems. Also, could you please confirm if "SSH Access" needs to be enabled under c...

UNKNOWN USB DEVICE tdevflt.sys

Hi, i´ve a USB port problem. I´ve already update all the lenovo drivers both automatically and manually and it didn't work. The PC keeps blocking me the USB ports. When i was looking for the solution, we tried to disable the cortex agent and after a restart the issue stops, the PC automatically detect the USB device and there´s no error in the d...

Broker Link

Hi, I need a method to identify endpoints in my environment that are not communicating or linked the broker but Cortex is installed, noting that those machines do not have internet access. Thanks,

URL & Application level blocking possibilities in Cortex XDR.

Hi All, Hope you all are doing good. Can anyone help me to understand the possibilities of url and application-level blocking in XDR? Following are my scenarios, 1. Blocking of URLs in XDR. 2. Blocking of execution/installation of specific applications in XDR. 3. Blocking of applications running without installation.(eg. anydesk applicati...

Aneesh by L1 Bithead
  • 6847 Views
  • 5 replies
  • 2 Likes

XDR Agent Auto Upgrade installer has timed out.

Hi everyone, I have a customer who has configured the automatic upgrade of XDR Agent, when the new version is released, only a small number of Agents have completed the upgrade, a large number of Linux hosts have failed to upgrade, and the Last Upgrade Failure Reason shows "The installer has timed out.", I tried to find the reason for this pro...

yuyangab by L1 Bithead
  • 4144 Views
  • 4 replies
  • 0 Likes
  • 2611 Posts
  • 98 Subscriptions
Top Solution Authors
Top Liked Authors