Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4398 Views
  • 0 replies
  • 3 Likes

Agent Settings - Network Location Configuration

Hello dear community, what use cases are there for the network Location Configuraiton and is there a simple documentation about this topic? If there is a connection to the host firewall topic, we have a use case, because our laptops get a public ip on sim card. So wee need to stay secure and block everything which comes from out to inbound. ...

RFeyertag_0-1689112764174.png
RFeyertag by L4 Transporter
  • 3745 Views
  • 1 replies
  • 0 Likes

Resolved! Upgrade XDR Agent

Hi, We are trying to uninstall and install XDR on a Windows server but getting a prompt during uninstallation that reboot is required. Will reboot be necessary after uninstallation? Regards, Shahwaz

Resolved! About XDR Cloud Compliance

Hello dear community, We noticed a feature called Cloud Compliance on Cortex XDR, but we don't see any details. What is this feature related to and from where to collect data? Is there any documentation available about this feature since I couldn't find any related instructions in the help center? Thanks.

Chilla by L1 Bithead
  • 2487 Views
  • 1 replies
  • 0 Likes

Mobile Phone Device Restriction on MacOS

Hello all, I am currently looking into creating a Device Restriction Policy in which I block a physical connection of a Mobile Phone to MacOS endpoint. Once blocked I would expect to receive an alert on the Device Policy Violation page. Is this possible? In regards to Windows endpoints, this works seamlessly as expected and the device is recog...

Resolved! Disappearing XDR Endpoints for iOS and Android

Hi There, We've got the XDR Agent for mobile devices deployed in our environment for both Android and iOS. I've noticed after some time these devices stop checking in with Cortex in the Endpoints dashboard. The devices will first say 'disconnected' then 'connection lost' etc. Funny thing is, they seem to stay upgraded in terms of versions. ...

Resolved! Cloud identity engine - Logs collection

Hi Community, Good day! We are unable to see the logs in the Cloud identity engine log viewers. if possible, Could you please suggest a way to get logs from the Directories? Thanks in advance. Cortex XDR Cloud Identity Engine Cloud Identity Engine

Resolved! Cloud Identity engine - Application

Hi Community, Good day! In the cloud identity engine for an Azure directory, we have the option of application. In that application option its showing as Not Consented. Could you please tell us why it shows like that and how to rectify the not Consented error? Thanks in advance Cloud Identity Engine Cortex XDR Cloud Identity Engine

no Cortex XDR integration in "security providers" in "security center" in Windows Server?

Palo Alto docs say this: The Cortex XDR agent registers with the Windows Security Center as an official Antivirus (AV) software product. As a result, Windows shuts down Microsoft Defender on the endpoint automatically, except for endpoints that are running Windows Server versions. To avoid performance issues, Palo Alto Networks recommends that...

kindzma by L2 Linker
  • 6508 Views
  • 5 replies
  • 0 Likes

Download the freshly created xdr-distribution-file

Hello I'm looking for an autmoatisation, where I'm able to download the freshly created xdr-distribution-file.In my Playbook I've created following steps: xdr-get-distribution-versionsxdr-create-distributionxdr-get-distribution-url Now, the last step tells me an URL to download the xdr-file.I would like to download that file to put it on out int...

Resolved! Need help with XQL query to report deleted files

Dear Sir, Please if anyone can help to advise the XQL query to create a custom report to capture the "File Delete" activities in one particular server? I know we can create the same from Query Builder, but from Query Builder it will only return 10,000 records. In addition, we not able to email the result as attachment (or if i am wrong with this...

  • 2611 Posts
  • 98 Subscriptions
Top Solution Authors