Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

XDR Collectors

Hello, 

I have prepared XDR collector agent for Windows. I have installed it on two of my windows servers. But unfortunately, it does not show up on Administration tab where i am supposed to see all installed collectors. I do not see my two XDR colle

...

Resolved! Ingest DHCP logs using XDR collector

Hi,

 

I am having issues with ingesting DHCP log from our DCs. We are using the XDR Collector app. I suspect that the issue is with the filebeat.yml file but cannot figure out what the problem is. I have tried and followed the guide below and copy-pa

...

Legacy Agent Exceptions or New menu??

Hi, what's your opinion?

Legacy Agent Exceptions or Global Exceptions Menu??

 

What's the difference? Which one is better?

 

Some support people suggest activating Legacy in Cortex XDR #, but I'm not sure if I should. Would I lose any of the settings

...

tlmarques by L4 Transporter
  • 867 Views
  • 2 replies
  • 0 Likes

Resolved! XQL Help - Count array values

Hello,

XQL beginner here, after 1 hour of tryhard with the cheap xql palo alto documentation. Finally got what I want but I feel like I've done it the wrong wa

 

Context 

  • I have a BIOC rule monitoring for read on multiple folders that can contains ide
...

Resolved! Not able to uninstall 7.3.0 version

Hello,

I have a PC with Cortex XDR version 7.3.0 and I can't uninstall it. I've already tried the Cytool protect disable command but it doesn't work. I've also tried XDRAgentCleaner 7.6.0 but obviously it doesn't work, it doesn't accept the admin pas

...

Resolved! Cortex XDR _USB Blocking Levels

Hello,

 

Please let me understand the levels of usb blocking in the edr policy.

If the access is blocked does it allow printers, Charging smartphones, Other utilities like Cameras etc. 

 

Thanks in advance.

XDR Endpoint Visibility Dashboard

Hello, 

Let's assume I have 5 departments inside my organization. Each contains 6-7 endpoints. I want to create 5 dashbaords for each. In these dashboards, I want to see only organization specific endpoints ( 6-7 endpoints would be in each dashboard)

...

DTRH: Finding New XQL Fields and Joining Data

 

 

DTRH: Finding New XQL Fields and Joining Data

 

I was trying to look at some user login information through XQL and I started poking around the different fields that were being returned. I began one of the user login sample queries available in the q

...

JEbrahimi_0-1618590705273.png
JEbrahimi_1-1618590705280.png
JEbrahimi_2-1618590705285.png
JEbrahimi_3-1618590705288.png

Host Firewall API

Has anyone had any luck adding IPs to the XDR host firewall via API?

It seems like this would be a great function to have. (Looking at you Palo Alto DEVs)

 

I've also looked at:

Adding IPs to an IOC - but IOCs cannot be added to custom blocking rules

...

CJNTS by L2 Linker
  • 1144 Views
  • 3 replies
  • 2 Likes
  • 2081 Posts
  • 82 Subscriptions
Top Solution Authors