Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 1765 Views
  • 0 replies
  • 3 Likes

Resolved! Defender remains running on Windows 11

Hi Everony

 

We've noticed that under Windows 11 the MS Defender Antivirus remains running in passive mode even after Cortex XDR is installed. The Cortex integration in Windows security center works, but Defender services are still running.

 

Does an

...

Rocky-25 by L2 Linker
  • 3326 Views
  • 3 replies
  • 0 Likes

API BLOCK LIST

Hello,

By doing or achieving different automations I have managed to add hashes to the block list in the action center section via API, but as in this console I see that it is blocked with 15,000 entries, let me explain when adding 15,000 hashes I un

...

Unable to parse the time stamp

I have tried to create a new field with an existing string field (createdDate), which is already in an ISO 8601 format. unable to parse it

sample value of feild createdDate=2019-08-29T10:10:26.608Z

 

Here below the query I have used

| alter filedate

...

Unable to parse the time stamp

I have trying to create a new field with existing string field (cretedDate) which is already in a ISO 8601 format but. unable to parse it

sample value of feild createdDate=2019-08-29T10:10:26.608Z

 



here below the query i have used


| alter filedate

...

Veeam Server high CPU Cortex XDR

Hello,

We have a server with Veeam Backup, and we are noticing high CPU usage from Cortex.

 

We have seen that some exceptions might need to be applied:

 

https://www.veeam.com/kb1999

 

Would this apply to Cortex?

 

Best regards.

Resolved! Finding if a URL was visited using XQL in Cortex

We wanted to see if we could use XQL to query for if a URL was visited in our environment. Is there a way to structure a working query for this using XQL? We've tried unsuccessfully so far, so we are turning to you, the community.

 

Thank you for any

...

Resolved! Detect delete agent with XQL.

I kindly ask for your assistance with an XDR XQL query language script to identify devices in the network that do not have the XDR agent installed. Additionally, it would be helpful if the users could be identified from AD or through the DHCP on the

...

Resolved! XQL For Silent Log Source

below is the query so far but what we are trying to do is get a silent log source detection. For example, one of the log source names has not sent a log in x number of hours then alert. Any suggestions?


dataset = panw_ngfw_traffic_raw | fields log_sou

...

Resolved! Azure AD and InTune

Hi Palo Live Community, I'm hoping that someone has worked with Cortex XDR and Azure InTune.

 

I'm trying to find a dynamic way to apply an extension profile  (block USB), in Cortex XDR, targeting specific endpoints that reside in Azure InTune.

 

Bef

...

  • 2472 Posts
  • 88 Subscriptions
Top Liked Authors