Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 589 Views
  • 0 replies
  • 2 Likes

Security Channel Subscription Errors

Team,

While trying to collect logs from windows, one channel that is consistently resulting in errors is security channel. Systems and Applications work just fine eliminating any possibility connectivity or authentication issues. It is the security c

...

Cortex XDR Query for USB/External Drive Usage

Hi Family 

Good morning.

I am trying to filter the timeframe when a user last connected a USB flash drive or external hard drive using a Cortex XDR query. However, the following query did not return the expected results:

 

 
dataset = xdr_data | f
...

Resolved! XQL chart editor

Hi. just i'm little stuck...

 

config timeframe = 1y
|dataset= incidents
|filter (status in (ENUM.RESOLVED_FALSE_POSITIVE,RESOLVED_AUTO_RESOLVE))
|fields creation_time ,status
|alter month = format_timestamp("%m",creation_time )
|sort asc month
|comp count

...

TNurmi_0-1740054064047.png
T.Nurmi by L1 Bithead
  • 461 Views
  • 1 replies
  • 0 Likes

Resolved! Post detected by Wildfire

Hello dear community, 

what means Detected (Post Detected)? 

In our case, we see pdfpower.exe incidents popping up, the user says he didn't download anything to the incident time.

I think, the agent is scanning the OS, when there is allready a quaran

...

RFeyertag_0-1687468667966.png
RFeyertag by L4 Transporter
  • 9041 Views
  • 9 replies
  • 0 Likes

XQL query time setting

Hi!

I want to make a report that generates every month and it contains the previous month's data. My problem is that i cannot make it to be created on the first day of the month. So I tried to make the XQL query to work with the previous month's data

...

Temporary Session installation type

We have a large Citrix farm with session hosts and non-persistent servers. We are using the TS_ENABLED=1 switch when installing the agent but the console is showing standard installation and not Temporary session. 

 

I am trying to figure out what th

...

File retrieval in user context

Hello,

Is it possible to retrieve a file which is only accessible in user's context? I have an incident which user opened a file from a network mapped drive. That drive might not be accessible by anyone except for the user.

 

Which user context is us

...

Resolved! XQL - Time alteration

Hello,

Here is the scenario:

I have a table lookup looking for a specific event.

dataset = xdr_data

| filter event_type = SOME EVENT   

| alter TimeOfIntereset = _time

Now I want to join this again with the dataset table to enrich it and perform furthe

...

XDR Collector DNS

Does anyone know if there is a native DNS collector, similar to the DHCP Collector Agent, for Cortex XDR ? My goal is to enrich XDR with more DNS-related information.

tlmarques by L4 Transporter
  • 330 Views
  • 2 replies
  • 0 Likes
  • 2255 Posts
  • 86 Subscriptions
Top Liked Authors