Endpoint (Traps) Discussions
Traps Advanced Endpoint Protection prevents cyber breaches by protecting and enabling users to conduct their daily activities, and automating prevention by autonomously reprogramming itself using threat intelligence gained from WildFire.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Endpoint (Traps) Discussions
Traps Advanced Endpoint Protection prevents cyber breaches by protecting and enabling users to conduct their daily activities, and automating prevention by autonomously reprogramming itself using threat intelligence gained from WildFire.
About Endpoint (Traps) Discussions

Welcome to the Endpoint discussion forum! We encourage you to ask questions, propose solutions, and collaborate on ideas to better secure your endpoints with Traps.

Discussions

Malware scan single file upon custom alert

I want to be able to malware scan one single file with Cortex XDR from the administrator perspective and using automation. Does anyone have any experience with this? Here is my example: I have an SFTP server where files are uploaded to. As each file is uploaded (created) to the server, I want a custom BIOC alert to trigger. This BIOC alert will ...

Difficulty Converting Dates to String Format in XQL Query

Hi Everyone, Greetings!, I'm facing challenges writing a date and time-based query. One specific issue is that dates aren't converting into a string format, especially when I try to convert the date '01' into 'Monday/Mon' and date '02' into 'Tuesday/Tue' . For example, I've set a time frame from Monday to Friday only, with other dates be...

M.Kannan by L0 Member
  • 839 Views
  • 0 replies
  • 0 Likes

【Cortex XDR】 The Cortex XDR question asked

Hi everyone, I have the following Cortex XDR question to ask , the information is as follows: 1. If I have not purchased HostInsight License, does it support to get the installedAppList of the endpoint through API? 2. Can I export the Cortex XDR raw log? Is it possible to export the raw log to other storage systems e.g. splunk? Thanks in ...

[Cortex XDR ] Does Broker VM support tandem log dumping? Can you dump to more than 2 external storage systems at the same time (3rd party SIEM...)

Hi Everyone, I have encountered two Broker VM log collection and dumping problems want to ask, and then please help you help, the problem is as follows: 1. Can Broker VM tandem dump logs? Description: As shown in the figure below, a customer wants to collect external syslogs through the syslog collector function of Broker VM A, but instead...

SLin576639_0-1718603034022.png
SLin576639_1-1718603270171.png

Cortex XDR Agent Services

In which situations do the services in the screenshot run? 1) Why is File Prevalence service disabled? What is Service used for?2) Why is File Scanning disabled?3)Why are the following services disabled and will there be problems when we enable them? What does Service do?Bpf is Disabled Kernel Module is Enabled Fallback is DisabledBpf is Not Run...

  • 26 Posts
  • 90 Subscriptions