Use the Cortex XDR Interface
Get started with the Cortex XDR interface.
Each SAML login session is valid for 8 hours.
Depending on your license and assigned role, you can explore and the following areas in the app.
From this menu, you can manage your dashboards and run reports.
From this menu you can investigate a lead or hunt for threats. You can access the
Query Builderto search logs from your Palo Alto Networks sensors, or the
Query Centerto view the status of all queries, and
Scheduled Queriesto view the status and modify the frequency of reoccurring queries.
You can also view all incidents, prioritize incidents, and set alert exceptions.
From this menu, you can respond to identified threats and take action. With a Cortex XDR Prevent or Cortex XDR Pro per Endpoint license, you can view the Action Center where you can initiate investigation and response actions such as isolating an endpoint or initiating a live terminal session to investigate processes and files locally.
From this menu, you can also add malicious domains and IP addresses to an external dynamic list (
EDL) enforceable on your Palo Alto Networks firewall. EDL management requires a Cortex XDR Pro per TB license.
With a Cortex XDR Prevent or Cortex XDR Pro per Endpoint license, you can manage your endpoints and endpoint security policy from this menu.
From this menu, you can configure additional add-on security services such as Device Control. Device Control requires a Cortex XDR Prevent or Cortex XDR Pro per Endpoint license.
With a Cortex XDR Pro per TB license, you can define indicators of known threats to enable Cortex XDR to raise alerts when detected. As you investigate and research threats and uncover specific indicators and behaviors associated with a threat, you can create rules to detect and alert you when the behavior occurs.
Settings and management
From the gear icon, you can view a log of actions initiated by Cortex XDR analysts, configure Cortex XDR settings to integrate with other apps and services, and manage settings for the analytics engine.
View Cortex XDR notifications such as when a query completes.
User who is logged into the Cortex XDR app and additional information about the app.
The following topics describe additional management actions you can perform on page results:
Recommended For You
Recommended videos not found.