Resolved! Retetion Time - cortex xdr
Hi, I want to know what is the retetion time for the incidents in the cortex xdr tenant.
After how long are the console incidents cleared?
thank you
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.
Hi, I want to know what is the retetion time for the incidents in the cortex xdr tenant.
After how long are the console incidents cleared?
thank you
Hi community,
I'd like to enquire whether Cortex XDR can create BIOC rules via Cortex XDR API.
I could not find any description about creating BIOC rules on the following Cortex-XDR-API-Reference.
Cortex XDR API Overview | Cortex XDR (stoplight.io)
Saben si el formato de OVA del broker es compatible con VCLOUD o en que formato lo tendria que generar para poder montarlo?
Hi community,
I am attempting with restricting the execution of vulnerable applications.
Is it possible to block a specific application version using BIOC associated with restriction profile?
(Or if there's another easy way to do this please let m
Hello everyone,
I am looking for a solution to handle a specific situation related to incident activation from an email, using the MSGRAPH integration.
Typically, to activate an incident, I classify it based on a static email subject. Then, I configu
...
Hi Team,
I'm trying to activate palo alto xdr tenant and unfortunately asking for Tenant Sub-domain. Any advice?
Hi all,
I am a bit confused with the new Agent version numbers. So to be sure:
Taking the naming convention into account, isn't the XDR Agent version 8.5.0.624. higher and newer then version 8.5.0.3639?
8.5.0.3639 is recently released to suppor
...
I was going to delete them all and start over with a new naming convention for my admins, so they are easier to find and use. But when I tried to delete them, I was warned it would disconnect anything that was installed using the generated files.
Ques
Hi Team,
I have enabled the Cortex XDR agent settings for certificate enforcement. However, endpoints are showing as only partially protected, and the Operational Status Details indicate that certificate enforcement is disabled against policy (Failed
...
Guys,
I need your help, I need to upload 500 IOCs to the block list.
Is there any option to upload IOCs in bulk or I have upload one by one?
Cortex XDR
Hi Community,
Would it be correct to register the IP addresses of the firewall's WAN interfaces in Cortex's network configuration -> Internal IP range?
I ask this question because I have a Fortigate sending the logs to Crotex and always the IP t
...
Hi everyone
I try to count some events per day and used the bin stage to do this. It does work to group the events together but the time is wrong. For example an event at 00:30 will count for the day before (probably because of the timezone). I tri
...
Hi,
Someone know how i can integrate the FW PaloAlto and FW Fortigate on Cortex XDR for module NTA see the logs/traffic and create alerts?
I'm facing issues with my Cortex install on a RHEL 9.4 system.
Agent version 8.4.0.123787
Kernel version 5.14.0-427.35.1.el9_4.x86_64
Some services are stopped and not restarting:
sudo /opt/traps/bin/cytool runtime query
Hi all,
I have created a simple custom Dashboard using a custom Widget. I want to put a link to endpoint table filtered by the result (result is the agent name), like the links on the default "Agent Management" dashboard. Does anyone know how to?
...