Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4489 Views
  • 0 replies
  • 3 Likes

Group events with xql bin stage

Hi everyone I try to count some events per day and used the bin stage to do this. It does work to group the events together but the time is wrong. For example an event at 00:30 will count for the day before (probably because of the timezone). I tried different configurations with the optional parameter timeshift and timezone but I'm not able t...

micomi by L3 Networker
  • 4090 Views
  • 5 replies
  • 0 Likes

Service Interruption and Telemetry Issues on Cortex Installation (RHEL 9.4)

I'm facing issues with my Cortex install on a RHEL 9.4 system.Agent version 8.4.0.123787 Kernel version 5.14.0-427.35.1.el9_4.x86_64 Some services are stopped and not restarting: Command Run: sudo /opt/traps/bin/cytool runtime query Stopped Services: clad, spmd, lted Attempt to Restart Services: sudo /opt/traps/bin/cytool runtime start...

Create link on the dashboard

Hi all, I have created a simple custom Dashboard using a custom Widget. I want to put a link to endpoint table filtered by the result (result is the agent name), like the links on the default "Agent Management" dashboard. Does anyone know how to? Thanks for the replies in advance.

Dashboard_01.JPG
AbdBgc by L2 Linker
  • 2119 Views
  • 4 replies
  • 0 Likes

Can't uninstall old cortex xdr version

i have install cortex xdr on linux (7.9 version) , the service can't start. i try to uninstall old version or upgrade the version to 8.1.1 , but it show below error. Pls help me to fix the error. [root@MOFVM068 bin]# ./cytool runtime start allRedirecting to /bin/systemctl start traps_pmd.serviceFailed to start traps_pmd.service: Unit not fou...

Resolved! Adding file and folder exclusions

We have a security camera server that's been throwing out low memory resource messages and the company that provides the software claims that Cortex XDR endpoint client is causing memory leaks. There are no incidents being triggered by this server and the memory usage of Cortex is always under 1GB of memory. They have provided documentation tha...

Disabled Capabilities of XDR on instaallation

Hi all, in one of our customers with the installation of XDR agent version 8.5 the Response Capabilities (File Retrieval, Live Terminal, Script Execution) were disabled from the very beginning on many of the endpoints. As there is no other way, the agents were uninstalled and reinstalled as a solution. But we could not identify the main reason...

AbdBgc by L2 Linker
  • 2664 Views
  • 2 replies
  • 0 Likes

I ingested the Checkpoint firewall logs into Cortex XDR, now what should I do?

Hi, Some time ago I connected the CheckPoint Firewalls with Cortex XDR and I can now see the alerts from the Cortex console. My question is, what should I do now with the alerts? Since the FW is generating more than 100 incidents a day.I had created an exclusion rule for the incidents that are registered as blocked, but this made me lose vis...

How IOCs are detected?

Hi, I've recently noticed that an IOC that we created a month ago is still somehow being triggered, therefore an incident is generated. The IOC is a domain that we've found in a phishing email. I haven't visited the domain or clicked on that quarantined email, but somehow an incident occurred this morning. What actions could trigger an added I...

Resolved! Select more than 100 endpoints in Prevention Policy Rule

Hi,I created new Prevention Policy Rule and can only select 100 endpoints. When I try to select more, I get the Note: Note: The current target will be based on 100 endpoints, you cannot choose more than 100 endpoints. To create a larger target use Dynamic target I tried to solve it with dynamic Groups, but it didn't help.How to create/select Dyn...

Elbedin by L0 Member
  • 4615 Views
  • 3 replies
  • 0 Likes
  • 2632 Posts
  • 99 Subscriptions