Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Filtering by Endpoint groups

I am trying to write an XQL query that will only focus on the endpoints that I have defined in my endpoint groups and not all endpoints in the xdr_data dataset.  

 

How can I filter the xdr_data dataset by endpoint groups?

tfoley by L0 Member
  • 1186 Views
  • 1 replies
  • 0 Likes

admin applied agent tags

I have a few XDR deployments I manage and one this I miss is the ability to tag objects like I can on firewalls.

 

This would be useful for a number of tasks from:

- filtering views/dashboards/reports

- adding agents to dynamic agent groups

- assigning po

...

Status Cortex XDR

Hello community

Do you know where can i see the percentaje uptime of CortexXDR service?

 

I know about this link: Palo Alto Networks Cloud Services Status but it did not help me.

Resolved! Windows Server 2003 unable to check in to TMS

Hello everybody,

 

  I'm trying to connect an old Windows Server 2003 (service pack 2, 32 bits) to the traps management service. I know that I have to use an old version of the agent (I've installed 5.0.10), but the agent fails to check into the TMS. T

...

grenzi by L3 Networker
  • 4091 Views
  • 9 replies
  • 0 Likes

Inconsistent XQL search results

When carrying out XQL search...."dataset = xdr_data | fields action_country | dedup action_country"

I receive a set of results with different action_country values as expected.

If I then take one of these values ie Switzerland and run "dataset = xdr_da

...

Resolved! Block especific Process and Folder/directory

Hello community,

In our company we have implemented Cortex XDR with Pro per endpoint and pro per terabyte licenses.

the incident response area asks me to verify the viability of applying the following preventive measures in cortex xdr

1st. Block the exe

...

Agent 7.2 dont comunicate with broker vm

I proceeded to install cortex XDR on a Kali, respecting the installation parameter chmod + x Kali.sh - --proxy-list "proxysrv: 8080,10.250.1.34: 8080" However, the client cannot contact the broker the error it is a timeout. my query is the following,

...

romansad by L1 Bithead
  • 3086 Views
  • 6 replies
  • 0 Likes

Investigating ABIOCS

I'm investigating the cause of ABIOC alerts. We've seen one particular alert that appears to be a false positive but I'd like to get some more information to be sure and to understand these alerts better:

 

Name: Suspicious process accessed a site masq

...

DanBrook by L0 Member
  • 1408 Views
  • 2 replies
  • 0 Likes
Top Liked Authors