Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Resolved! Threat ID #9999' generated by PAN NGFW

Hello,

 

I have turned off alerts on NGFW for Private URL, but I still get threat ID #9999. 

 

Can somebody a little bit more explain what this threat ID means? I am trying to clean it up, but still get these alerts.

And it is not any kind of malicious tr

...

LukasB by L2 Linker
  • 11871 Views
  • 5 replies
  • 0 Likes

Searching for multiple hashes on cortex XDR

Does anyone know a way to search for multiple hashes on Cortex XDR?

file_search = existing_files does not allow any operators other than "=" for the sha values and you can't string multiple in a query. 

I feel like I'm missing something and there sho

...

rufat87 by L1 Bithead
  • 2835 Views
  • 3 replies
  • 0 Likes

Sorting out generic website fw rules

Hey everyone,

We are trying to sort out generic firewall alerts that we get as the incidents.

Currently, when there's site blocked that someone browsed through, we get the incident to check for it.

I would like to implement some correlation rule that w

...

Resolved! Cortex XDR Licenses

Hello,

 

Could you please share the required detail and if possible share documentation related it.?

 

  1. How are licenses utilized in Cortex XDR? (user based or device based) - How are new agent IDs created? (Parameters for agent Id creation)
  2. Deployment
...

What is /opt/traps/analyzerd/clad?

Hello

 

We run several Linux Servers with XDR on it.

11 out of those Linux Zoo, we get an Insident of our Monitoring, claiming, that there are double processes running:

 

3587 /opt/traps/analyzerd/clad -n clad -c 197:requests -- --log-level 7 --max-w

...

Access to live terminal with dual control

For legal reasons in our organization we have servers that can only be accessed in administrator mode if another authorized person authorizes access. That is, under no circumstances can a single person get administrator permissions.

Following this po

...

  • 2078 Posts
  • 82 Subscriptions
Top Solution Authors
Top Liked Authors