Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4320 Views
  • 0 replies
  • 3 Likes

Resolved! Cortex XDR Pro on Linux Mint

I am having an issue with an installation of XDR on Linux Mint 20. I found this post with no resolution and one of the comments from @MartinSauer suggests someone else was seeing the same issue.LIVEcommunity - ERROR:14090086:SSL routines: SSL3_GET_SERVER_CERTIFICATE: certificate verify failed - LIVEcommunity - 317055 (paloaltonetworks.com) In...

Resolved! What are the capabilities of Cortex XDR without endpoint agents which ingest Logs and data From third EDR like MDE ?

Hello, I'd like to hear from people who have worked with Cortex XDR without the Cortex XDR agent. The scenario is as follows:The machines (workstations and servers) are protected by a third-party EDR solution (e.g. Micrsoft Defender for Endpoint).we'd like to add the XDR layer for greater visibility. So what are the capabilities of Cortex ...

Resolved! Some Cortex XDR events are not displayed in the endpoint client's events tab

Hi, We recently onboarded Cortex XDR and some of the detections are not displayed in the Cortex client's Events tab. But I can see them in the Cortex XDR console. As an example I can see Prevented (Blocked) malware in both cloud console and the endpoint's events. But Detected (Scanned) type alerts can only be seen in the cloud console and the...

Isuru by L1 Bithead
  • 2890 Views
  • 3 replies
  • 0 Likes

Resolved! Clients/Server do not have assigned endpoint group ALERT / CORRELATION / XQL

Hello dear community, I want to share with you my little XQL script which can identify and alert connected Clients which have no assigned endpoint group. This can happen: - Cortex is installed, but the endpoint name does not match the defined criteria - Endpoint name is changed, does not match the defined criteria dataset = endpoints | f...

RFeyertag_1-1686849957699.png
RFeyertag_0-1686849683794.png
RFeyertag by L4 Transporter
  • 1979 Views
  • 2 replies
  • 1 Likes

After not using a broker, the endpoints are unable to connect to the server.

Dear community, I tried to make some agents connect directly to the server without using a broker. However, it's not able not connect to server. I referred to the practices of others, and tried executing "cytool reconnect force", but still couldn't establish a connection. Because some endpoints can be successfully connected, it can be ruled out...

Chilla by L1 Bithead
  • 2631 Views
  • 1 replies
  • 0 Likes

Resolved! How to automatically input the password when using the "cytool reconnect" command?

Hi everyone, I want to run Cytool reconnect on multiple computers, I tried the following echo <password>| cytool reconnect force it works, but still displays "Enter supervisor password:", so you still need to press enter to let it continue running. is there another way to pass the password to cytool via cmd? Or make it not di...

Chilla_0-1686708588184.png
Chilla by L1 Bithead
  • 6020 Views
  • 7 replies
  • 0 Likes

DNS resolution was wrong for Firewall alerts

Dear LIVEcommunity, Did anyone encounter problem such as hostname does not match with the IP address for alert ingested from NGFW? This is especially true when come to host that doesn't have Cortex XDR agent installed. Now, if the host cannot install with Cortex XDR agent for whatever reason, is there any way that I could improve the accuracy ...

myu06kkn_1-1685698402054.png
  • 2585 Posts
  • 95 Subscriptions
Top Solution Authors