Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Resolved! Ingesting Syslog to Private/Internal Syslog

Hello,

 

My organization utilizes graylog, and we host it on prem. Is there a way to route/tunnel the XDR tenant into our internal network? I am aware of the BrokerVM, but I do not know if that plays a role. I know the BrokerVM has a syslog app, but

...

Cortex Domain controllers exceptions

Hi Team,

 

We are having replication issues across the domain controllers and Microsoft is suspecting its an issue with Cortex and they want the the below files to be created as an exceptions across all our domain controllers.

 

To rule out Cortex is

...

Join two data sets XQL

Before I get into my failed script, please allow me to explain what Im attempting to do.

 

We are looking for windows and Macintosh devices with cortex xdr agent NOT installed.  To do this we installed the cortex DHCP log collector. It is reporting its

...

Modifying Policies and Profiles on XDR

Dear All,

 

I wanted to create an XQL Query to identify the modification of XDR policies or Profiles by anyone who have access to XDR, so that I wanted to get the list of users who tried to modify the policies or profiles.

 

I wanted to convert the X

...

VenuK by L2 Linker
  • 947 Views
  • 2 replies
  • 0 Likes

Auto Agent Upgrade in 3.6 version

Hello Team,

Since the new version of Cortex has come out 3.6 version. 

Wanted to get clarity on auto -the agent upgradation part.

 

Is it recommended to upgrade your agents(servers/workstation) to N-1 or latest version via auto agent upgrade policy?'

...

Resolved! Finding if a URL was visited using XQL in Cortex

We wanted to see if we could use XQL to query for if a URL was visited in our environment. Is there a way to structure a working query for this using XQL? We've tried unsuccessfully so far, so we are turning to you, the community.

 

Thank you for any

...

File search based on Host

Is there any option in Cortex XDR, where we can check which all hosts have a specific exe present? 

For eg We want to get a list of hosts which has google chrome installed in it.

 

Regards,

Shashank

Resolved! Agent script Library

Hello, 

 

I would like to know if a script to that invokes live terminal or other functions related to Cortex XDR can be done using agent script library.

NivedaR by L2 Linker
  • 1454 Views
  • 4 replies
  • 0 Likes

Resolved! Intense SSO failures

Hello everyone,

Recently after the update we started getting errors for SSO that say Intense SSO failures.
While investigating execution chain, I only ran into outcome reason as "Strong authentication is required or device authentication failed".
Is the

...

Linux operation mode (Pending)

Dear All,

I wanted to create a widget to display the details of Linux Operation Mode, can someone help me how I can start with, I am still a rookie in XQL Query.

 

TIA

 

VenuK by L2 Linker
  • 1033 Views
  • 3 replies
  • 0 Likes
  • 1657 Posts
  • 80 Subscriptions
Top Liked Authors