Cortex XDR Host based firewalls visibility

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Cortex XDR Host based firewalls visibility

L0 Member

We have Cortex XDR Host Firewall enabled and can see rules are allowing and blocking traffic. What’s the best way to view detailed allow/deny logs? I’m not seeing all activity under host firewall events. Thanks!

1 REPLY 1

L5 Sessionator

Hi @Tyler_Wood 

 

I understand you want to see logs/events from your host Fw. 

  • Once you deploy the host firewall, use the Host Firewall Events table to track the enforcement events in your organization. This table provides an aggregated view of the host firewall enforcement events in your network. An enforcement event represents the number of rule hits per endpoint in 60 minutes.
  • If you have Cortex XDR Pro license, you can also query the host firewall events using the new host_firewall_events dataset in XQL Search for data and network analysis.
  • To collect the log file, right-click the event containing the endpoint you are interested in and select Collect Detailed Host Firewall Logs. Alternatively, you can perform this action for multiple endpoints from Endpoints Administration. So basically from the all Endpoints table, right click on the desired endpoint --> Endpoint Control ---> Collect Detailed Host Firewall Logs 

Please check the following doc for the former info and further info: 

https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Host-firewall

 

If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.

 

KR,

Luis

  • 201 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!