Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4322 Views
  • 0 replies
  • 3 Likes

Managing Updates (Content & Agent Upgrades)

Hello dear community, I have a few questions how did you implemented your staging in Cortex XDR? Or did you say, no we trust PA and do not delay the content updates? It is all about these two categories in the agent settings: Content Auto-Update: 1. How long do you delay the content update with the setting "Setting Contenton"=enabled yo...

RFeyertag_0-1734720697054.png
RFeyertag_1-1734721039341.png
RFeyertag by L4 Transporter
  • 1118 Views
  • 1 replies
  • 1 Likes

Resolved! Cortex XDR agent SAP HANA

Hello everyone, does anybody know if the Cortex XDR agent for Linux systems is officially certified for SAP HANA environments (Redhead) ? Are there any documentations about this? Haven´t found anything to this. Thanks and regards, Tobias

XDR grouping

Hi Guys, In palaalto endpoint grouping what is static groupingWhat is dynamic grouping Where this scenario works with example

Help with XDR Rest query

Hi,I'm trying to query the Cortex REST API using this doc - https://live.paloaltonetworks.com/t5/cortex-xdr-articles/cortex-xdr-and-xsiam-postman-api-collection/ta-p/443667, but I keep receiving a "Public API request unauthorized" message. I tried opening a ticket, but apparentlythat's not allowed for this level of question. Any suggestions? M...

S.Bossi by L0 Member
  • 841 Views
  • 1 replies
  • 0 Likes

Broker VM, local agent setting status indicator fluctuates between Green to Red

Hello, Greetings Can anyone confirm why does status indicator of Broker VM's Local agent setting keeps fluctuating. It keeps changing between "Connected to Connection Failed" also showing inaccessible URLS that are already whitelisted. Also the active connection does not exceed 1000 at any point of time. Configuration to consider: 1. Number ...

Cortex XDR - Solutions for log collection without an official integration

Has anyone found a good approach for collecting logs from an API when there isn't an official Cortex XDR integration? For example, Automox has released a Splunk and DataDog app, but the custom collection in Cortex XDR isn't a good fit. We use the Broker VM for syslog, but most SaaS apps don't support syslog of course.What are people using to g...

mgreer by L1 Bithead
  • 1128 Views
  • 1 replies
  • 0 Likes

Resolved! Cortex XDR Pro - Looking for Scheduled tasks by name in mass?

Hello dear community, here is a script for searching specific scheduled tasks by name in mass. The search is via LIKE and wildcards are used. import subprocess import sys def ScheduledTask(scheduler_name): # PowerShell-Befehl mit Where-Object und Filterung für den TaskScheduler pscommand = f"""Get-ScheduledTask | Where-Object {{$...

RFeyertag_0-1713736580513.png
RFeyertag by L4 Transporter
  • 4852 Views
  • 3 replies
  • 3 Likes

Resolved! Keeping alive a program after closing Live Terminal

Hi everyone, I'm using Live Terminal to upload/download Microfsoft's MSERT on potentially infected devices, which are isolated. But, when running msert.exe via Live Terminal, it seems that the process is attached to my Live Terminal instance, meaning that if I want the MSERT scan to complete, I have to keep the Live Terminal session open. Is th...

G.Louhou by L1 Bithead
  • 1418 Views
  • 1 replies
  • 0 Likes
  • 2589 Posts
  • 95 Subscriptions
Top Solution Authors