- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.
Hi all,
I am a beginner at XQL. Where can I learn how to use this to my advantage?
Hello,
I have turned off alerts on NGFW for Private URL, but I still get threat ID #9999.
Can somebody a little bit more explain what this threat ID means? I am trying to clean it up, but still get these alerts.
And it is not any kind of malicious tr
...
Does anyone know a way to search for multiple hashes on Cortex XDR?
file_search = existing_files does not allow any operators other than "=" for the sha values and you can't string multiple in a query.
I feel like I'm missing something and there sho
...
Hello everyone!
Recently, I have been learning about the Identity Analytics feature in Cortex XDR.
After enabling Identity Analytics, I found that not every tenant presents the same interface.
I found that the following UI features are not identica
...
Hi All,
Need some help!
We have a Linux instance where the opt/ folder size is 2 GB and the recommended disk quota by Cortex is 5 GB. We can not resize it.
Do anyone know if there is a way to change the installation directory of Cortex from /opt to
...
Hi everyone,
unfortunately we still have a bunch of W7/S2008R computers (without extended support) in our network. The majority of the pcs have Cortex XDR 7.9 installed. In terms of support we are now trying to uninstall 7.9 and install 7.5 CE instea
...
Hi All,
We want alerts to be triggered for various open-source applications like NodeJS, Nginx, Python, etc.
Kindly let me know how we can achieve this.
Thanks
Hey everyone,
We are trying to sort out generic firewall alerts that we get as the incidents.
Currently, when there's site blocked that someone browsed through, we get the incident to check for it.
I would like to implement some correlation rule that w
Hello,
Could you please share the required detail and if possible share documentation related it.?
Hello
We run several Linux Servers with XDR on it.
11 out of those Linux Zoo, we get an Insident of our Monitoring, claiming, that there are double processes running:
3587 /opt/traps/analyzerd/clad -n clad -c 197:requests -- --log-level 7 --max-w
...
hello,
i'm facing an issue with cortex xdr agent, it's not able not connect to server , protection mode is always disable.
but internet connexion is allowed to this server.
any help please.
BR.
Hello Everyone,
I have a following question: Since XDR agents are able to detect unmanaged assets in their network (without Broker VM), how can I get that information via XQL ?
Any information will be usefully.
Thank you
Is there a feature in Cortex that allows us to monitor which endpoints use USB to transfer data?
For legal reasons in our organization we have servers that can only be accessed in administrator mode if another authorized person authorizes access. That is, under no circumstances can a single person get administrator permissions.
Following this po
...Subject | Likes |
---|---|
3 Likes | |
2 Likes | |
2 Likes | |
1 Like | |
1 Like |