Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.
About Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.

Discussions

Resolved! Using XQL queries in XSIAM playbooks

Hi Team,

 

I'd like to enquire whether Cortex XSIAM can search the logs of a dataset using XQL Query in a Playbook.
Cortex XSOAR can do that for Cortex XDR using the integration of "Cortex XDR - Search and Compare Process Executions - XQL Engine" .

Integrating Proofpoint TAP into XSIAM

Hi,

 

I would like some guidance on which data source I should use when integrating Proofpoint TAP into XSIAM.

 

In the content pack "Proofpoint TAP" on the marketplace,

 

There is a data source named "Proofpoint TAP".  This data source has the abili

...

Rule list

would like to see a list of rules regarding the types of incidents I receive in XSIAM.

I am not talking about IOC/BIOC 

 

Can anyone help with the path ?

Resolved! Coalescing of events in XSIAM?

Looking to migrate from QRadar/QRoC to XSIAM


In QRadar/QRoC, coalescing works in the following manner:

https://www.ibm.com/support/pages/qradar-how-does-coalescing-work-qradar

 

The goal of coalescing is to reduce the need for storage of events for c

...

Widget Library XQL Query

Hi All,

So in the xsiam portal under 'Dashboard and reports' there is a pre-defined list of Widgets in the library..

Within the 'system monitoring' library there is a widget called 'daily consumption' which is great to identify data sources ingestion

...

PA_nts by L3 Networker
  • 399 Views
  • 1 replies
  • 0 Likes

XSIAM Multi-Tenancy

How does multi-tenancy work for MSSPs in XSIAM? 
We are looking to use XSIAM as the core SecOps tooling to replace our current SIEM and we were wondering how does the multi-tenancy function work?  

Simple QXL Query help needed

Hi All,

withing query builder i have a very basic query as per below..

 

dataset = metrics_source
| fields _vendor , _product , total_size_bytes

 

which shows me the data sources and the amount of ingested data per source which is fine over a period

...

PA_nts by L3 Networker
  • 428 Views
  • 1 replies
  • 0 Likes

Resolved! Unified Inventory

Hello,

I have come across references to 'Unified Inventory' in the documentation for XSIAM, Xpanse, and Prisma Cloud. Could anyone please clarify if this is a single offering from Palo Alto Networks or specifically from Cortex? Alternatively, do thes

...

sh4unz0r by L0 Member
  • 1369 Views
  • 3 replies
  • 0 Likes

Unified/Assets Inventory and XQL

Do we have the ability to call Unified Inventory or Assets Inventory via XQL Query? I have many interesting examples and potential use cases for how this data can be used. Also, some custom reports like 'new assets detected in last 24h' can be useful

...

MDovirak by L0 Member
  • 737 Views
  • 1 replies
  • 0 Likes

XSIAM Cloud or Onprem?

Hi All,

 

I'd like to enquire whether Cortex XSIAM offers on-premises solutions exclusively, or if it provides a combination of both on-premises and cloud solutions? Additionally, how does the deployment model work? 

  • 26 Posts
  • 26 Subscriptions
Top Solution Authors
Top Liked Posts
Top Liked Authors
Labels