Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4322 Views
  • 0 replies
  • 3 Likes

Resolved! XQL For Silent Log Source

below is the query so far but what we are trying to do is get a silent log source detection. For example, one of the log source names has not sent a log in x number of hours then alert. Any suggestions?dataset = panw_ngfw_traffic_raw | fields log_source_name | dedup log_source_name

Resolved! Azure AD and InTune

Hi Palo Live Community, I'm hoping that someone has worked with Cortex XDR and Azure InTune. I'm trying to find a dynamic way to apply an extension profile (block USB), in Cortex XDR, targeting specific endpoints that reside in Azure InTune. Before, I was using Active Directory OUs to target these endpoints but newer endpoints being added t...

Cortex XDR agent removal

Hi all, In one of our endpoints XDR agent triggerd an alert named ' Suspicious file modification detected ' cmd is 'C:\Windows\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09}' after this XDR service cyserver was stopped , now status is disconnected, we don't have data to analyze the issue. what can i do

Cortex XDR to google chronicle

Dear community, One of my client is using Google chronicle as their SIEM . They would like to know and understand what is required on Palo-Alto Cortex XDR side to send their logs to Google Chronicle . Is there a simple way to do this ? Do we need a Broker VM ? Thanks Da

davoxxxx by L0 Member
  • 982 Views
  • 1 replies
  • 0 Likes

XDR 8.5.0 print servers error

Hi, we are experiencing issues with Cortex XDR agent version 8.5 on our PrintServerWe had agents running version 8.4.0 without any errors, but after upgrading to version 8.5, we started encountering printing problems on the servers.The error is:Faulting application name: spoolsv.exe, version: 10.0.20348.2520, time stamp: 0xf42f642eFaulting modul...

tlmarques by L4 Transporter
  • 3121 Views
  • 5 replies
  • 1 Likes

Agent Configuration - Password strength

Hi, I'm struggelin' to set a new password. Have tried all kind of combinations. Allways get "Does not meet the requirements." Please see attached for an example.. I've seen earlier discussions on this. Something does not seem to be working as intended.. Regards Ivar

Cortex xdr with RedHat Quay with Clair

Hello PA community, For all images on customer s OpenShift clusters, they have a policy that all images have to be stored in their RedHat Quay with Clair. Customer has tried to setup a mirror with the "europe-west4-docker.pkg.dev/xdr-eu-2009645628112/agent-docker/cortex-agent" repo but unfortunately the only authentication possible in Quay is wi...

Resolved! Alarm on disconnected agents..

Hi, we're in the process of migrating our endpoint security on servers and PC clients to Cortex XDR. I'm new to Cortex XDR, but have started to walk thru all kinds of documentation/training.. Today's question 🙂 : If I, or someone else, disables the agent on a client (cytool, or whatever else), will the disconnected client show up in Cortex ...

Alerts and incidents

Hello Palo Live Community.Does anyone know what are the criteria that Cortex XDR takes into account to create an incident for a single alert? This is because I have seen that some alerts do not necessarily form an incident, but in other cases, yes. I insist, talking only about a single alert.I attach evidence.

R.Tuyub by L1 Bithead
  • 1172 Views
  • 1 replies
  • 0 Likes

XQL Query Help

I'm trying to write a few XQL queries in Cortex XDR, but I’m quite new to it and running into some difficulties. I’d really appreciate any guidance or examples you can provide for any of the following queries: To detect when the Cortex XDR Agent is uninstalled, To trigger an alert for Tamper Detection, To monitor if a live terminal session is i...

  • 2589 Posts
  • 95 Subscriptions
Top Solution Authors