Cortex XDR Configuration Overview
With Cortex XDR you can use a variety of sensors to integrate all your network, endpoint, and cloud data. For the most complete set of correlated data, you can collect network and cloud data from your Palo Alto Networks firewalls, mobile endpoint data from GlobalProtect and GlobalProtect cloud service, and use either Traps or Pathfinder to collect endpoint data. However you can also use Cortex XDR apps with either Palo Alto Networks firewalls, GlobalProtect, or Traps.
The following workflow highlights the tasks that you must perform (in order) to configure Cortex XDR apps. Each individual task focuses on setting up critical components (for example, the Cortex Data Lake, the Cortex XDR apps, and Traps).
- Confirm that you have Everything You Need to Configure Cortex XDR.
- Assign roles to
the users who will activate Cortex XDR apps. You must be assigned the four app and service roles when you activate the Cortex XDR or activation will fail.
- Set up Cortex Data Lake.
- Activate Cortex Data Lake on the Cortex hub.
- If you plan to use Traps, and want to use the same Cortex Data Lake instance for both firewall logs and Traps logs, you must associate Panorama with the Cortex Data Lake instance. See License and Install the Cloud Services Plugin.
- Manage Logging Storage for Cortex XDR.
- (Optional) Set Up Directory Sync Service.
- Use the Palo Alto Networks Cortex hub to Activate Cortex XDR Apps.
- Set up additional Cortex XDR app components:
Activate Cortex XDR Apps
Activate Cortex XDR Apps Use the Palo Alto Networks Cortex hub ( https://apps.paloaltonetworks.com ) to activate your Cortex XDR apps. This is a one-time task ...
Set Up Cortex XDR
Set Up Cortex XDR Cortex XDR Configuration Overview Everything You Need to Configure Cortex XDR Review the prerequisites for setting up Cortex XDR apps. Manage ...
Everything You Need to Configure Cortex XDR
Review the prerequisites for setting up Cortex XDR apps. ...
Manage Logging Storage for Cortex XDR
Cortex XDR – Analytics licenses are based on Cortex Data Lake capacity. To view your licensed capacity, use the Customer Support Portal. ...
View Logs in Cortex Data Lake
View Logs in Cortex Data Lake In most cases, you can view logs stored in Cortex Data Lake locally on the product that is sending ...
Cortex Data Lake Logging for Firewalls without Panorama
Cortex Data Lake Logging for Firewalls without Panorama Palo Alto Networks® Cortex Data Lake provides cloud-based, centralized log storage and aggregation for firewalls and certain ...
Cortex XDR™ Architecture
This section describes the app ecosystem and data sources for the Cortex XDR app. ...
Set Up Cortex XDR – Analytics
Set Up Cortex XDR – Analytics Cortex XDR – Analytics analyzes data from a variety of network, endpoint, and cloud detection sources. For the most ...
New Features: April 2019
New Features: April 2019 Feature Description Traps-Only Detection Cortex XDR – Analytics no longer requires you to deploy Palo Alto Networks firewalls to begin collecting ...