Cortex XDR Error Pop-Up in Mac
Hi Team,
We have already granted full disk permissions in macOS for Cortex XDR. However, we are still encountering the following popup:
The popup continues to reappear on the machine.
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.
Hi Team,
We have already granted full disk permissions in macOS for Cortex XDR. However, we are still encountering the following popup:
The popup continues to reappear on the machine.
Hi All,
We are planning to do the following for the migration, can you pls validate if this is gonna work or not-
- We will import the configuration to new broker
- This will shutdown the old broker
- Since we have 2 BVM , we should not have any conn
Hello.
I am looking for configuration best practices for agent config, exclusions/exceptions for MS SQL. I am new to XDR but I know in similar products it's normal to exclude the database files from live scanning, etc and I can't seem to find any doc
...
I'm trying to create a dashboard with all temporary exceptions, but I can't find the database where the "Device Temporary Exceptions" is located.
Can someone help me
Hi Expert ,
I would like to know how to combine or join dataset between XDR-data and PANNGFW I make xql of PANNGFW when found, alert wildfire or antivirus will show file-sha256 by the way I want to combine dataset of xdr-agent to find file-path t
...
We have a mac that we suspect may be compromised. We would like to run a scan with the device offline and not connected to our network.
How would we go about doing this?
When i try to update the cortex version 8.1.1.43337 version, I got the attached error. I try to update from 7.9.1 version.
Hey!
I was just wondering if anyone knows of a way to get the total download/upload to show in MB or GB rather than bytes through an XQL queries' output?
XQL Query
dataset = xdr_data // Using the xdr dataset
| filter event_type = ENUM.NETWORK // Filt
Hello,
I am a bit confused by the information in logs when an XDR enpoint is connected to a BrokerVM.
It appears that for some connexions issues, endpoints are not communicating anymore with the BrokerVM:
XDR agent on ... failed to communicate to
...
How to change the default password for Password Protection for Download Files in server settings configuration Cortex XDR?
Hi Everyone.
I want to integrate Broker VM server with the QRadar using syslog service (we are open to discussion about syslog).
We have some servers that can't see the internet, so we set up Broker VM and installed agents on the servers. Now we
...
Hi team
Is it possible to configure XDR to display extra attributes on a few places - namely:
* User information under "Key Assets & Artifacts" in each incident
* Displayed name on the user card
XDR chose to display the SAM account name (i.e. the
...
Need help for getting Device Permanent Exceptions allowed endpoints and device details
Hello Everyone,
I'm new to Cortex XDR and looking to enhance our IOC hunting process. I want to run a scan with IOCs from our subscribed external threat feed.
I have uploaded multiple IOCs to XDR via add IOC option but only able to run the query for
...User | Likes Count |
---|---|
6 | |
4 | |
2 | |
2 | |
2 |