This website uses cookies essential to its operation, for analytics, and for personalized content. By continuing to browse this site, you acknowledge the use of cookies. For details on cookie usage on our site, read our Privacy Policy
When running xql queries against host inventory i have 2 questions 1. Is there documentation that states what each field means in the array The example below " start mode" and "state" are numerica...
The Get Incidents API allows you to filter based on an incident_id_list, but not a list of endpoint_ids much less endpoint group. The Get Alerts API allows you to filter on an ale...
I am attempting to pull in endpoint/incident data using the appropriate API in PowerBI. However, there's a limit of 100 . I tried adding a separate custom column anticipated that my total number of i...
1. Does PA have a repository of IOC to import to XDR?
2. 2. Does PA have a repository of Alert Exclusions to import to XDR? For example well known windows process and BIOC.
Cortex...
Hi, I was looking for an answer in a scenario where only 1 broker VM is available. What happens when the VM goes down. How does the end point connect to XDR console and how can we get the v...
Cortex XDR I can't get the login code from the Palo alto network that verifies by email (before it's working but during these two days I can't get those codes anymore).
We know that Cortex has the ability to use AMSI but is any one able to achieve a BIOC rule which can trigger an alert for the content inside the script. Lets say if a Powershell script which...
We have the Prevent license and I am curious if anyone has been able to take their PA NGFW data and send it to the XDR console? I know this can be done with the Pro license for increased forensics an...
Hello dear Community, is Cortex XDR Pro able to fire a script on all or on some hosts with one klick? I know and worked with the live terminal, but how can we perform scripts for mult...
Hello i am trying to create XQL filter to filter out all known connections, so it only returns me connections that should not happen. So i create separate line for each of those knows connections, ...