Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4320 Views
  • 0 replies
  • 3 Likes

Resolved! Command line to set a Proxy_List to an already installed Cortex XDR Agent

Hi. Does anyone know if there is a command line to set a proxy to an already installed version of Cortex XDR? I know the proxy can be set using the command line: Cortex_Installer.msi proxy_list=”<proxy>:<port>” That being said, I didn’t find any way to change the defined proxy, once the installation is complete, except completely un...

Cortex XDR unable to uninstall

In Win 10 Pro 22H2 19045.3930, Cortex XDR agent unable to uninstall or upgrade in one user pc. Agent setup unable to find in control panel installed applications. Present agent version 8.2.0.46438. Worked on uninstalling from action response, endpoint etc no output.

Resolved! Managed Digital Signers Block List

Hello All- I am hoping this is a quick question as I did not find this in XDR documentation. It is my understanding that Palo manages a "trusted signers" list. Is there a way to leverage a similar list to automatically block the use/execution of digital signers that are unwanted? I know that a custom BIOC rule can be created but am wonderin...

Resolved! Impact on licences expiration #Cortex XDR

Hello My Cortex XDR licences expire in a few weeks I can't find the exact impact, I suppose that the new malware signature won't be updated but : - Will I be able to handle to connect to the console, to handle the agent - Will the agent still work? Cortex XDR Thanks !

XDR Collectors

Hello, I have prepared XDR collector agent for Windows. I have installed it on two of my windows servers. But unfortunately, it does not show up on Administration tab where i am supposed to see all installed collectors. I do not see my two XDR collector I have already installed. What can I do about it? Thanks in advance

Resolved! Ingest DHCP logs using XDR collector

Hi, I am having issues with ingesting DHCP log from our DCs. We are using the XDR Collector app. I suspect that the issue is with the filebeat.yml file but cannot figure out what the problem is. I have tried and followed the guide below and copy-paste the example code but no logs are showing up. The yml has been checked and the syntax is corre...

Send alerts to Syslog server with TLS failing with Certificate Verification Failed

Hi, I'm trying to configure my TLS enabled Syslog server in Cortex but not successful. I'm always getting "Test failed : Certificate Verification Failed". When I tick the "Ignore certificate errors", the error disappears and one syslog message is received successfully but getting errors after that. Can you please help me figure this out? Sysl...

Isuru by L1 Bithead
  • 6558 Views
  • 4 replies
  • 0 Likes

Resolved! XQL Help - Count array values

Hello,XQL beginner here, after 1 hour of tryhard with the cheap xql palo alto documentation. Finally got what I want but I feel like I've done it the wrong wa Context I have a BIOC rule monitoring for read on multiple folders that can contains identical files. Target The list of the top file that have been read Example Monitored file pa...

Resolved! Not able to uninstall 7.3.0 version

Hello, I have a PC with Cortex XDR version 7.3.0 and I can't uninstall it. I've already tried the Cytool protect disable command but it doesn't work. I've also tried XDRAgentCleaner 7.6.0 but obviously it doesn't work, it doesn't accept the admin password in any case. Does anyone have a solution? Thanks

Resolved! Cortex XDR _USB Blocking Levels

Hello, Please let me understand the levels of usb blocking in the edr policy. If the access is blocked does it allow printers, Charging smartphones, Other utilities like Cameras etc. Thanks in advance.

XDR Endpoint Visibility Dashboard

Hello, Let's assume I have 5 departments inside my organization. Each contains 6-7 endpoints. I want to create 5 dashbaords for each. In these dashboards, I want to see only organization specific endpoints ( 6-7 endpoints would be in each dashboard). I want to see incidents only related to specific organization. PS: I can filter endpoints accor...

How to install Cortex XDR Agent as Golden image using Debian package for Linux

I'd like to install the Cortex XDR agent as a golden image using a Debian file on Ubuntu. I tried to execute the command "apt-get install ./cortex-8.2.1.120305.deb -- --vm-template" or "apt-get install cortex-8.2.1.120305 -- --vm-template", but it doesn't work. Can someone help or suggest to me how to install an agent as Golden Image for Ubuntu?

  • 2585 Posts
  • 95 Subscriptions
Top Solution Authors