Resolved! Detail Description of Alert Log Fields XDR API
Hello Everyone,
We are pulling alerts from the XDR API using below endpoint:
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.
Hello Everyone,
We are pulling alerts from the XDR API using below endpoint:
Hello Everyone,
For one of the client, we need to fetch logs from XDR API using XQL. Currently, the ask is for windows event logs only, but later they want IIS logs as well.
Any help in below queries would be appreciated:
1. There are two queri
...
Hello Everyone ,
Do you know if there is an option to create an custom report in XDR only for wild fire information visibility ?
Thank you in advance.
Hi,
I'm trying to find a good query to pull not only the user login time but also a user logout in AD/AZ AD. I've been able to get the login data easy enough but I can't seem to pull a log OUT time/date or timeout.
Does anyone have any suggestions
...
Hello Everyone,
Do you know if XDR supports option for removing several profiles for the console at the same time.
There is an option for manual removal profile y profile, but i have to make a clean up on environment with several hundred and som
...
Is it still possible to check the status of Cortex agent in registry? I want to check the status on the client side periodically. I know it is possible via cytool but i need to do this periodically on a lot of computers.
I know there was a way on Tra
...
Hi all,
I'm running into this issue where some personnel do not want to add malicious hashes to the XDR block list as it will isolate the machine. As far as I can tell, adding a hash to the block list will only remove the file on execution or scan,
...
Hello dear community,
I am uploading some IOCs (about 300k). Where are the limitations? I can see PA is using nginx, but I can't find any information about the submitted filesizes etc. Now I am actually running "Transfer-Encoding" = "chunked" in
...
Hello dear community!
will there ever be a backwards scan functionality for API uploaded IOC's?
BR
Rob
Wir haben Probleme bei der Installation eines Cortex XDR Clients 8.0.1.33809 (Win, 64 Bit, msi) auf einem Rechner Microsoft Surface Pro 9 5G (Prozessor: Microsoft SQ3 (ARM64) / OS: Windows 11 22H2)
Installation des Cortex beginnt, Cortex-Installatio
...
Hey folks,
Recently we are getting high number of large data upload alerts in Cortex XDR.
The issue is data upload alerts are flagged with domain name stun.l.google.com on port 19302 ,UDP.
Why browsers are connecting to this stun server ?
when queried a
Hey Folks,
Just wanted to understand how can we verify on console and XDR agents console that agent are installed with EPP modules enabled?
Regards,
M.R.
Cortex XDR Cortex XSIAM
Is it possible to access the vulnerability assessments via XQL and/or API
I've been tasked with looking at the possiblity of taking the CVE lists from vulnerability assessment and matching them to MS KB. I don't want to be manually running reports
...
Hello Community,
I am trying to understand Palo Alto XDR logs fetched using API(XQL Query).
I am using dataset as xdr_data, want to know what all event_types can come under this dataset.
For ex: EVENT_LOG.
What are the possible values we can ge
...
I read the relevant documents, but I don't quite understand them. I hope someone can confirm them for me.
reference articale url :https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/cortex-xdr-overview/cortex-xdr-licenses/cortex-x
...Subject | Likes |
---|---|
3 Likes | |
2 Likes | |
2 Likes | |
1 Like | |
1 Like |