Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.
About Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.

Discussions

Welcome to the Cortex XSIAM Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 2758 Views
  • 0 replies
  • 0 Likes

XDR Agent Reconnecting

Agent Version: 8.6.0.3704Last Seen: 01 January 2025 We had to remove the protection since it is cutting off connection via SSH for Backup purposes. Moreover, with protection off, it is able to backup consistently. My question is, we have I already raised a ticket to TAC but they are unsure on what module that is cutting connection via SSH. W...

Welcome to the Cortex XSIAM Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 2758 Views
  • 0 replies
  • 0 Likes

Dynamic Parsing of JSON to fields in XQL

Hi everyone, I’m working with a dataset in Cortex XSIAM, where I have a field containing JSON data. I want to dynamically parse this JSON so that each key becomes a field and the corresponding value is populated as its value. Is there a way in XQL to dynamically create columns from JSON keys without explicitly defining each key using alter? Ho...

Broker VM rejects SSL certificate

Hello PAN community, I am trying to import a SSL certificate into our #BrokerVMI can upload the private key, but the Server Certificate gets rejected with the Error: "failed to set custom ssl certificate" I tried .cer and .pem files and none were accepted. The guide only mentions the cipher as an error source, but SHA256 was used. (Configure t...

XSIAM Assets / Network Mapper - How to identify unknown assets

We configured network mapper in the BrokerVM settings and using multiple ports for network identification. Of course, on the firewalls we allow all traffic from them to make a full visibility internally. However, the scan doesn't resolve the hostname or open ports on the machine that can support with OS identification, like 22/ssh - potential Li...

MDovirak by L2 Linker
  • 1256 Views
  • 1 replies
  • 0 Likes

XQL Query for a Correlation Rules

I am trying to write a xql query for a correlation rule in which alert or incident will trigger for below condition.Condition: Threshold: Only once on match 2 Detect on unique values of: hostnameSo, my question is. how to write "Detect on unique values of: hostname" in a xql query? Please help me with a sample XQL search or syntax in XSIAM.Best ...

What part of the network did an alert generate from?

Within XSIAM, an enterprises' network asset ranges are defined at Assets > Network Configuration. On adding a network, you are able to assign the network a range name and and IP address range. When an alert is generated within XSIAM, where is the range name found within the alert? We want easily be able to see from which part of the ente...

XSIAM and ITSM Integration question

Hi All, anyone successfully done this to date? my integration works in that I can communicate with ITSM ok. however, I have the following issue.. our ITSM Dev team have provided some fields that is required from XSIAM playbook to ingest the tickets successfully. These include fileds such as 'source' host' 'subject' details' etc.. however on the ...

PA_nts by L4 Transporter
  • 1073 Views
  • 0 replies
  • 0 Likes
  • 164 Posts
  • 43 Subscriptions
Top Solution Authors
Labels