Audit Admin Activity
From ResponseAuditing, you can track the status of all administrative and investigative actions. Cortex XDR – Investigation and Response stores audit logs within the app for one year. Use the page filters to narrow the results or Manage Columns and Rows to add or remove fields as needed.
The following table describes the default and optional additional fields that you can add in alphabetical order.
|Email address of the administrative user|
|Description||Descriptive summary of the administrative action|
|Host Name||Name of any relevant affected hosts|
|ID||Unique ID for the action|
|Result||Result of the administrative action: Success, Partial, or Fail.|
|Subtype||Sub category of action|
|Timestamp||Time the action took place|
Type of activity logged, one of the following:
|User Name||User who performed the action|
Features Introduced in 2019
Introducing new features in the Cortex XDR – Investigation and Response by month during 2019. ...
Use the Cortex XDR – Investigation and Response Interface
Use the Cortex XDR – Investigation and Response Interface Before you can get started with Cortex XDR, you must Set Up Cortex XDR Apps and Related ...
Remediation Activity Logs
Remediation Activity Logs You can proactively monitor incident remediation logs to track activity. These logs are useful for auditing the progress of automatic remediation and ...
View Administrator Activity Logs
Monitor the activity and changes made by administrators in the Aperture service by viewing activity logs. ...
Administration You can view analyst actions within Cortex XDR™ – Investigation and Response. Audit reports can help in future threat hunting and remediation. Audit Administrator ...
Investigate Incidents An attack event can affect several users or hosts and raise different types of alerts caused by a single event. You can track ...
Log Events API
Log Events API An API client that you have registered to the Aperture service and is authorized to access the service, can long poll the ...
Cortex XDR – Investigation and Response Alerts
Cortex XDR – Investigation and Response Alerts The Alerts page shows a table of all alerts in Cortex XDR – Investigation and Response. The Alerts page consolidates ...
Panorama 5.1 Administrator's Guide
Palo Alto Networks® Panorama Administrator’s Guide Panorama 5.1 Contact Information Corporate Headquarters: Palo Alto Networks 3300 Olcott Street Santa Clara, CA 95054 http://www.paloaltonetworks.com/contact/contact/ About ...