Cortex XDR Configuration Overview
With Cortex XDR you can use a variety of sensors to integrate all your network, endpoint, and cloud data. For the most complete set of correlated data, you can collect network and cloud data from your Palo Alto Networks firewalls and Panorama and use either Traps or Pathfinder to collect endpoint data. However you can also use Cortex XDR apps with either Palo Alto Networks firewalls and Panorama or Traps.
The following workflow highlights the tasks that you must perform (in order) to configure Cortex XDR apps. Each individual task focuses on setting up critical components (for example, the Cortex Data Lake, the Cortex XDR apps, and Traps).
- Confirm that you have Everything You Need to Configure Cortex XDR.
- Assign roles to
the users who will activate Cortex XDR apps. You must be assigned the four app and service roles when you activate the Cortex XDR or activation will fail.
- Set up Cortex Data Lake.
- Activate Cortex Data Lake on the Cortex Hub.
- If you plan to use Traps, and want to use the same Cortex Data Lake instance for both firewall logs and Traps logs, you must associate Panorama with the Cortex Data Lake instance. See License and Install the Cloud Services Plugin.
- Manage Logging Storage for Cortex XDR.
- (Optional) Set Up Directory Sync Service.
- Use the Palo Alto Networks Cortex Hub to Activate Cortex XDR Apps.
- Set up additional Cortex XDR app components:
Activate Cortex XDR Apps
Activate Cortex XDR Apps Use the Palo Alto Networks Cortex Hub ( https://apps.paloaltonetworks.com ) to activate your Cortex XDR apps. This is a one-time task ...
Set Up Cortex XDR
Set Up Cortex XDR Cortex XDR Configuration Overview Everything You Need to Configure Cortex XDR Review the prerequisites for setting up Cortex XDR apps. Manage ...
Everything You Need to Configure Cortex XDR
Review the prerequisites for setting up Cortex XDR apps. ...
Set Up Cortex XDR – Analytics
Set Up Cortex XDR – Analytics Cortex XDR – Analytics analyzes data from a variety of network, endpoint, and cloud detection sources. For the most ...
Manage Logging Storage for Cortex XDR
Cortex XDR – Analytics licenses are based on Cortex Data Lake capacity. To view your licensed capacity, use the Customer Support Portal. ...
Set Up Traps
Set Up Traps Also available with Cortex XDR are Traps agents and Traps management service. If you choose to use Traps to monitor and collect ...
Role Migration Notes
Users of the Cloud Services Portal prior to role management in the Customer Support Portal need to be aware of these changes. ...
Cortex XDR™ – Investigation and Response Architecture
Cortex XDR – Investigation and Response Architecture Cortex XDR – Investigation and Response consumes data from the Cortex Data Lake and can correlate and stitch together logs ...
Palo Alto Networks Cloud Services provides both applications and services. Use the Cloud Services Portal to access and activate the applications.,Palo Alto Networks Cloud Services ...