Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.
About Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.

Discussions

Welcome to the Cortex XSIAM Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 2390 Views
  • 0 replies
  • 0 Likes

Vulnerability Assessment in XSIAM 3.3

Does anyone know what happened to the Vulnerability Assessment in XSIAM after upgrading to 3.3?

 

I used to be able to do Inventory → Endpoints+Host Inventory → Vulnerability Assessment, select Endpoints on the upper-right bar and then search by Endp

...

Resolved! Use case BIOC Creation

Hi Live Community, Please I want to create BIOC with GUI for this use case Process name = svchost.exe and (Path not   C:\Windows\WinSxS\* OR C:\windows\system32\* )

 

 

 

BR.

Bouzeghoub_0-1767003982011.png

XSIAM - Vulnerability field (Issues)

Hi All.

 

Please, using "JSON Sample Incident Generator (Community Contribution)" app, is there any way to set "CATEGORY" field a value on Issues?.

 

Using "Classification & Mapping" and setting "Category" field to a specific value did not work.

 

Th

...

XSIAM V3.3 upgrade - anyone having issues?

Hi All, 

We have a XSIAM tenant running v3.2 and PAN upgraded to V3.3 yesterday (Nov 16th 2025) and since then we have a number of issues ie

- content pack updates (base/scripts etc) updates failing

- transformers missing as such custom playbook runs

...

PA_nts by L4 Transporter
  • 2449 Views
  • 1 replies
  • 0 Likes

Timeout issue - Health Issue/Alerts in XSIAM

Hello,

 

We are seeing multiple health issues under collection type.

 

For example: 

Issue name: Collection error in the instance AWS_***  collector

Description: timeout while waiting for server to answer: request ********-****-****-****-**********.

...

Vinay_AS by L0 Member
  • 724 Views
  • 0 replies
  • 0 Likes

XQL question

Hello,

I'm trying to get all the outgoing firewall traffic, except port 80, 443 using the query below but no sucess. Any ideias?

 

dataset = panw_ngfw_traffic_raw
| filter source_ip in ("x.x.x.x/24")
| filter dest_port != 443 and 80
| fields _time, sour

...

SouzaBr by L0 Member
  • 1925 Views
  • 1 replies
  • 0 Likes

xSIAM to xSOAR integration

Hey,


We’re currently looking at a potential xSIAM customer but haven’t been able to find any documentation confirming whether xSIAM can integrate with xSOAR. Does anyone have any insight?

Context:
I work for an MSSP that leverages xSOAR to ingest detec

...

sending NGFW logs to XSIAM without broker-vm

Hi,

I have a xsiam tenant running and a palo vm-100 (11.2.x) in our lab (xsiam / ngfw exists in the same csp account)

trying to find docs on this process.. the xsiam admin guide is pretty vague, it says yes and explains the steps on the xsiam side mo

...

PA_nts by L4 Transporter
  • 2509 Views
  • 8 replies
  • 0 Likes

Tagging all data from a broker-vm

Hi All,

has anyone done this to date yet?

I have a broker-vm deployed  in a specific region and want to tag any and all data from this broker-vm with a custom region tag.. 

anyone written a parsing rule for this as yet?

 

thanks in adv

PA_nts by L4 Transporter
  • 404 Views
  • 0 replies
  • 0 Likes

XSIAM NGFW Panorama logs onboarding

What is the recommended method to onboard NGFW logs. If the NGFWs are sending the logs to Panorama, how should i get the logs to XSIAM. I did see the "NGFW" integration and there is also syslog through Broker VM. which one is recommended? If I use th

...

  • 143 Posts
  • 41 Subscriptions
Top Liked Authors
Labels