Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4322 Views
  • 0 replies
  • 3 Likes

Resolved! Cortex XDR agent SAP HANA

Hello everyone, does anybody know if the Cortex XDR agent for Linux systems is officially certified for SAP HANA environments (Redhead) ? Are there any documentations about this? Haven´t found anything to this. Thanks and regards, Tobias

XDR grouping

Hi Guys, In palaalto endpoint grouping what is static groupingWhat is dynamic grouping Where this scenario works with example

Help with XDR Rest query

Hi,I'm trying to query the Cortex REST API using this doc - https://live.paloaltonetworks.com/t5/cortex-xdr-articles/cortex-xdr-and-xsiam-postman-api-collection/ta-p/443667, but I keep receiving a "Public API request unauthorized" message. I tried opening a ticket, but apparentlythat's not allowed for this level of question. Any suggestions? M...

S.Bossi by L0 Member
  • 840 Views
  • 1 replies
  • 0 Likes

Broker VM, local agent setting status indicator fluctuates between Green to Red

Hello, Greetings Can anyone confirm why does status indicator of Broker VM's Local agent setting keeps fluctuating. It keeps changing between "Connected to Connection Failed" also showing inaccessible URLS that are already whitelisted. Also the active connection does not exceed 1000 at any point of time. Configuration to consider: 1. Number ...

Cortex XDR - Solutions for log collection without an official integration

Has anyone found a good approach for collecting logs from an API when there isn't an official Cortex XDR integration? For example, Automox has released a Splunk and DataDog app, but the custom collection in Cortex XDR isn't a good fit. We use the Broker VM for syslog, but most SaaS apps don't support syslog of course.What are people using to g...

mgreer by L1 Bithead
  • 1126 Views
  • 1 replies
  • 0 Likes

Resolved! Cortex XDR Pro - Looking for Scheduled tasks by name in mass?

Hello dear community, here is a script for searching specific scheduled tasks by name in mass. The search is via LIKE and wildcards are used. import subprocess import sys def ScheduledTask(scheduler_name): # PowerShell-Befehl mit Where-Object und Filterung für den TaskScheduler pscommand = f"""Get-ScheduledTask | Where-Object {{$...

RFeyertag_0-1713736580513.png
RFeyertag by L4 Transporter
  • 4845 Views
  • 3 replies
  • 3 Likes

Resolved! Keeping alive a program after closing Live Terminal

Hi everyone, I'm using Live Terminal to upload/download Microfsoft's MSERT on potentially infected devices, which are isolated. But, when running msert.exe via Live Terminal, it seems that the process is attached to my Live Terminal instance, meaning that if I want the MSERT scan to complete, I have to keep the Live Terminal session open. Is th...

G.Louhou by L1 Bithead
  • 1415 Views
  • 1 replies
  • 0 Likes

Resolved! Cortex XDR Installation issue for Windows 7 SP1 and Windows 2008 R2 SP1

Hi Community, I’m facing an issue while trying to install Cortex XDR Agent (7.9-CE) on Windows 7 SP1 and Windows 2008 R2 SP1 systems. According to the compatibility documentation, these platforms are supported, but I’m encountering the following error during installation: "Cortex XDR requires Azure Code Signing support. See Microsoft KB5022661 f...

53cd5e0d-b675-4282-8c6d-a9aba17cd4fe.jpg

Resolved! how remove softwares with XDR

Hello,I've two questions.First, I would like to know about your experience. How do you handle uninstalling software on specific devices that are not allowed and need to be removed via Cortex XDR without the user noticing?The second question is: Is it possible to block apps? For example, I don’t want users to install Wireshark. Can it be blocked

tlmarques by L4 Transporter
  • 2574 Views
  • 4 replies
  • 0 Likes
  • 2587 Posts
  • 95 Subscriptions
Top Solution Authors