Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4397 Views
  • 0 replies
  • 3 Likes

Cannot remove/install xdr agent

Hi everybody !I would like to find out how to download the XdrAgentCleaner.exe to remove cleanely old xdr cortex agent ? We have several computers on which we cannot uninstall the old agent, you will find the message attached. I have already follow these steps without success :https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-4/cortex-xdr-ag...

systemsi by L0 Member
  • 6482 Views
  • 2 replies
  • 0 Likes

Resolved! Broker VM connection issue

Hi Community We're facing an connection issue with Endpoints using Broker VMs (agent proxy). We opened a TAC case, but it's stuck. There is no useful help yet. - Endpoints are isolated from the internet (no direct or webproxy access)- Endpoints are registered in Cortex, but doesn't get content updates- Live terminal to endpoints is not possibl...

Rocky-25 by L2 Linker
  • 5803 Views
  • 2 replies
  • 0 Likes

Cortex XDR 8.1 not installing on Windows Server 2008 R2/2012 windows 10_v1607

Hi,We've a problem with installation cortex xdr 8.1 on Windows Server 2008/2012 and Windows10_v1607....All machine need the AZURE update https://support.microsoft.com/en-us/topic/kb5022661-windows-support-for-the-azure-code-signing-program-4b505a31-fa1e-4ea6-85dd-6630229e8ef4 We read the documentation, try install updates but errors every time...

tlmarques by L4 Transporter
  • 6100 Views
  • 3 replies
  • 0 Likes

Resolved! Cortex XDR Prevent to Pro

Hi, ill soon have to migrate a customer from prevent to pro. My question is i heard, that Palo just has to change the license in the background and that would be all i just have to enable the pro feature in the policy. My only concern is, that the client wont work cuz its currently prevent and i dont want to have to reinstall the client on all...

Create Cortex XDR rule exclusion with specific time

Hi community I wonder if are there any of you who succeed/ever experienced creating Exclusion Rule in Cortex XDR but the rule will only be applied if the incident occurred at a specific time. As I read Palo's documentation and dig down into the community, I haven't met the case that matched mine. If there are any documentation links or solutio...

Resolved! The query is w.r.t API operation

Hello, Is the API function available to run the "File Search" operation? --> (“Incident Response --> Action Centre --> File Search- Sha256”). Did not find this option in the Cortex XDR API documentation, however, wanted to confirm and check if this can be achieved through API or not?

Resolved! Exception Exploit Module

Hello Community, I would like to create an exception rule for an IIS worker process w3wp.exe, which module would be the appropriate one where the exception would reside. Based on the documentation here EXPLOIT SECURITY POLICY offers protection against this process, but in the exception configuration which module do I select when adding in th...

brownchris_0-1692392318707.png

Resolved! Server in the DMZ- unable to Live Terminal Into

All, When looking through the log file of the agent, I ran across this. Can anyone tell me what its for and why is it missing? This was a fresh install of the latest Cortex agent. Thanks. Payload archive file \"C:\\ProgramData\\Cyvera\\LocalSystem\\Download\\content\\cortex-xdr-payload.zip\" does not exist"

  • 2610 Posts
  • 98 Subscriptions
Top Solution Authors