Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 763 Views
  • 0 replies
  • 2 Likes

Resolved! Windows Event Collector

Hello, 

 

I want to activate Windows Event Collector on my system. I am looking my documentation. https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Activate-the-Windows-Event-Collector?tocId=JKwlSDeDaqpS9R1bOJda

...

Resolved! Cortex XDR flagged malicious macros


Hi team
Cortex XDR keeps generates hundreds of alerts due to suspicious macro detected in my network. 
Severity : High
Alert Source : XDR Agent
Action : Detected (Post Detected)

Category : Malware
Extensions : .xls .tmp .xlt  .xar

Seems Cortex deletes al

...

chawki by L0 Member
  • 3468 Views
  • 5 replies
  • 4 Likes

Resolved! XQL Query - Machine Custom Reports

Hello,

good afternoon.

I currently have a few machines and xDR installed on them.

I need to make a weekly report with the information of the machines and the scan previously configured.

Currently, what I have configured using XQL Query:

 

-> Checks i

...

Resolved! XDR Console Access

Hello, 

 

Sometimes, I cannot access to the XDR console. It is just loading but nothing showing, just a white page. I have internet access. It happens sometimes and after about 15 minutes, the problem disappears. 

 

What can be the reason for that?

Resolved! Cortex XDR

Hi Community ,

i Had Came Across Some of the Questions Regarding Cortex Xdr , Hope you'll help me with Narrow Down The Rabbit Hole 

1. Why the Cortex scanning the files on the Endpoints that has the benign Verdicts in the Scanning Phase .

2. There ar

...

Yayati by L0 Member
  • 2011 Views
  • 1 replies
  • 0 Likes

Resolved! Automatic updates from Cortex XDR in Intune

Hi Everone! Hope you can help me 

 

I have acustomer use both Cortex XDR on their endpoints for monitoring, and Intune for app deployment etc. When receiving a new PC, it is configured through Intune. However, currently, the customer has to manually

...

Resolved! Dataset name change

Hello, 

 

I have linux logs which comes as:
[INGEST:vendor="unknown", product="unknown", target_dataset="unknown_unknown_raw", no_hit = drop]

 

It is collected under the dataset name called "unknown_unknown_raw". But I want to change its dataset name

...

Resolved! Export/Import filters

Hi,

In the Host Inventory/Applications I can filter programs then save the filter and open it when needed. However it would be very helpful if I could export this filter, modify it in editor and import again. Is any way to do this? I'm just trying to

...

  • 2284 Posts
  • 86 Subscriptions
Top Solution Authors
Top Liked Authors