Cortex XSIAM Discussions

Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.
About Cortex XSIAM Discussions
Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.

Discussions

Welcome to the Cortex XSIAM Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 376 Views
  • 0 replies
  • 0 Likes

Creating a Custom Issue For a Case

Hello LiveComm,

I have created a custom case with a single Issue for a Use-Case.

I want to create more issues with a command or script in this custom case which will eventually be a playbook task.  How does one do such an action?

Many thanks,

MSysec

...

Uploading files to Open Cloud Applications

HI Team,

 

I'm running a test case in uploading test documents to open source Cloud applications.

I was successful, but in xdr_data and Zscaler dataset; the file uploads and file names are being shown as blank or none.

 

Please let me know

1. if this

...

Computers no longer showing in Console

Hi,

 

We have staff members who work in the mining area and do not connect for a very long time; in some cases we have seen they came back from the sites after four months. Additionally, their computers do not appear on the Cortex XSIAM console, or I

...

O.Faheem by L1 Bithead
  • 89 Views
  • 0 replies
  • 0 Likes

Resolved! Cortex XDR Agent

Hi,

We are using Cortex XSIAM. Currently, some Microsoft Windows 10 and 11 agents are not receiving updates, indicating that they will soon become outdated. I concur that the majority of the machines lack network connectivity. However, is it possible

...

O.Faheem by L1 Bithead
  • 329 Views
  • 3 replies
  • 0 Likes

Monitoring Bluetooth

Hi,

 

We are using Cortex XSIAM. Now we want to perform monitoring of Bluetooth in Microsoft Windows 10 and 11 computers. The reason we want to check whether our users are connecting their mobile phones, like iPhone and Androids, through their office

...

O.Faheem by L1 Bithead
  • 141 Views
  • 0 replies
  • 0 Likes

Cortex XDR Host Firewall Rule evaluation

Hi Team,

I have a doubt about Host Firewall rule evaluation. Let say i have a rule created to allow all internal application inbound traffic on specific port / Remote IP. In the same rule group if i create another outbound rule and action type : allo

...

Jira and Teams XSIAM Integration

This is in XSIAM. When I create an instance in "Automation and Feed integrations" I can see that it creates one in the "Data sources" section as well. I do not want the logs from Teams in XSIAM and hence to not want an instance in the "Data sources"

...

Extract Incident context data using 'set' script

Hi All

very simple task running the 'set' script in a very basic playbook in xsiam

i am trying to pull the 'xsiam url link to the incident' from the incident context data ${parentIncidentFields.xdr_url} into a set task.. but it keeps showing as empty

...

PA_nts by L3 Networker
  • 335 Views
  • 2 replies
  • 0 Likes

Agent Not updating

Hi,

We have Windows clients which are sometimes not on the network nor connected to the internet. Their agent does not get updated. Tell me what other solutions we have to get it updated

O.Faheem by L1 Bithead
  • 352 Views
  • 3 replies
  • 0 Likes

sending NGFW logs to XSIAM without broker-vm

Hi,

I have a xsiam tenant running and a palo vm-100 (11.2.x) in our lab (xsiam / ngfw exists in the same csp account)

trying to find docs on this process.. the xsiam admin guide is pretty vague, it says yes and explains the steps on the xsiam side mo

...

PA_nts by L3 Networker
  • 602 Views
  • 3 replies
  • 0 Likes

Forcepoint proxy integration with XSIAM

Hi Palo Team, I am trying to onboard Forcepoint proxy logs into XSIAM, but i couldn't found any marketplace app/supporting datamodel.

Could someone help/guide to onboard the forcepoint proxy logs.

additionally referring to Splunk where we have a option

...

T.Sode by L0 Member
  • 351 Views
  • 1 replies
  • 0 Likes
  • 73 Posts
  • 36 Subscriptions
Top Solution Authors
Labels