Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4390 Views
  • 0 replies
  • 3 Likes

Integrating Cortex wth QRadar

Hello Everyone,Does the installed Cortex XDR for QRadar Version1.2.0 and config it via syslog allow receive Alerts directly from Cortex XDR into QRadar? I found https://apps.xforce.ibmcloud.com/extension/d12c3794f142ee334b4bbdc83d10347f but not able to find newer version. Can someone know if there is other way to receive alerts directly from C...

Cortex XDR - Issues auto-grouping under same case due to shared IP - how to manage?

Hi everyone, We recently integrated Palo Alto Firewall with Cortex XDR and incidents are coming in successfully. However, we're facing an issue with how cases are being created. The problem is: when a case is opened, other issues with different names are automatically being grouped under the same case simply because they share the same affected ...

Resolved! createNewIndicator - IP is not an existing indicator type in Cortex XDR

Hi, We are using Cortex XDR native playbook editor and trying to use the default EDL playbook. When the playbook runs the createNewIndicator task, we receive this error: 'IP' is not an existing indicator type. Note that the type is case sensitive (52) We have tried all possible type values: IP, ip, IPv4, IP Address — all return the same error. A...

Resolved! CSP HUB roles / accesses

Greetings, How can we manage the hub roles while no user have relevant roles in the tenant. I need to assign a role to a user to activate the Cloud Identity Engine for Cortex XDR

Resolved! Make MTP logs using XQL

Hello, Everyone! 1. An Android device is connected to a computer where XDR is installed.2. After the connection (Android-Computer), the user accesses the Android device’s folder from the computer and copies file A from the computer to the Android device.3. On the computer, the copied file A on the Android device is renamed or copied to a diffe...

Local Analysis Malware and WildFire Malware Alerts

Can someone explain the Local Analysis Malware and WildFire Malware alerts. The WildFire alerts seem straightforward for a file that it deems malware. On the other hand, the local analysis malware alerts trigger for a bunch of files but in the alert it has a wildfire report and verdict that says benign. Moving into suppressing these alerts, the ...

Resolved! XDR Endpoint with Containers

Hello, I would like your help to understand what protections I have with Cortex XDR Endpoint Pro on a Linux server running containers/Docker. Will XDR also protect against malicious activity originating from the container to the network, or is it more of a black box?

tlmarques by L4 Transporter
  • 1490 Views
  • 5 replies
  • 0 Likes

Cortex XDR - Sharing IOC with Other Tenant

Hello Palo Alto Team, I just want to ask a question regarding sharing IOC with other tenant. Is it possible to share continuously IOC with other tenant? If it possible, please share with me, because I have case that need to share IOC to tenant in other region under Pertamina Hulu Energi that have also their Cortex XDR. Thanks

A.Faruq by L1 Bithead
  • 464 Views
  • 3 replies
  • 0 Likes

Ingest GlobalProtect logs to Cortex

Hi. We are ingest data from Paloalto Firewall which using GlobalProtect feature and now we need send logs through Broker Vm setup. We can't use native integrations so syslog is only option. We get data and i see that dataset is > dataset = palo_alto_networks_lf_raw and i notice that not work with example some detection rules, so that is not ...

T.Nurmi by L2 Linker
  • 921 Views
  • 1 replies
  • 0 Likes

SBAC limitations: Delegation of full control (profiles and exceptions) for a specific group of endpoints.

Hello community! I'm looking for the best way to delegate Cortex XDR administration to an IT team within a specific department. The goal is to give them full control over a particular group of endpoints, ensuring strict separation: they shouldn't have visibility into or the ability to manage the endpoints in the main network. The problem: I've b...

cyvrlpc.sys failure

Our IT department supports a OurDesktop virtual environment. I was notified of an error that has been coming up during multiple sessions. It acts somewhat like a BSOD in that it shows an error then reboots the computer for you. No configuration changes were made. Running v8.9 in this environment. Stop code: SYSTEM_SERVICE_EXCEPTION (0X3B) What...

Resolved! Configuration/Whitelistings accross mutliple Cortex Tenants

Hello everyoneI am working in an MSSP environment and managing several Cortex XDR tenants. While reviewing the official Palo Alto Networks documentation and online resources, I couldn’t find any information about whether it is possible to create configurations (such as exceptions, exclusions, custom detections likes BIOCs etc.) once and apply th...

MaaHaa by L0 Member
  • 1369 Views
  • 1 replies
  • 0 Likes

Issue with IOC not blocking MyPDFSwitch executable

Hello, I have been receiving alerts related to a file named MyPDFSwitch_8173674.exe, where the filename ends with random numbers. I created an IOC with the following pattern: MyPDFSwitch*.exe However, today I received another alert related to this file, so I suspect that the IOC is not working properly. Could you please advise what might be happ...

  • 2611 Posts
  • 98 Subscriptions
Top Solution Authors
Top Liked Authors