Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 276 Views
  • 0 replies
  • 2 Likes

Resolved! Cortex XDR Prevent to Pro

Hi,

 

ill soon have to migrate a customer from prevent to pro. My question is i heard, that Palo just has to change the license in the background and that would be all i just have to enable the pro feature in the policy. My only concern is, that the

...

Resolved! The query is w.r.t API operation

Hello,

Is the API function available to run the "File Search" operation? --> (“Incident Response --> Action Centre --> File Search- Sha256”). Did not find this option in the Cortex XDR API documentation, however, wanted to confirm and check if this c

...

Resolved! Exception Exploit Module

Hello Community,

 

I would like to create an exception rule for an IIS worker process w3wp.exe, which module would be the appropriate one where the exception would reside.

 

Based on the documentation here EXPLOIT SECURITY POLICY offers protection ag

...

brownchris_0-1692392318707.png

Resolved! Server in the DMZ- unable to Live Terminal Into

All,

 

When looking through the log file of the agent, I ran across this. Can anyone tell me what its for and why is it missing? This was a fresh install of the latest Cortex agent. Thanks.

 

Payload archive file \"C:\\ProgramData\\Cyvera\\LocalSyste

...

How to use XQL parse_timestamp

I am trying to convert a string to a timestamp object and cannot understand how the parse_timestamp function works.

My string is as follow : 

"2023-08-17T17:40:38.000246+0300"
 
My XQL query is as follow :
alter
timestamp = parse_timestamp("%Y-%m-%d
...

unlucky by L0 Member
  • 2409 Views
  • 2 replies
  • 0 Likes
  • 2154 Posts
  • 83 Subscriptions
Top Liked Authors