Cortex XDR Customer Success Webinar: Endpoint Administration

Поделиться
HTML-код
  • Опубликовано: 5 окт 2024
  • Watch this video to learn about best practices for admin tasks, tips and recommendations.

Комментарии • 11

  • @Kumar-ez2bs
    @Kumar-ez2bs Год назад +8

    Understanding audio itself a big challenge, along with cortex XDR learning

  • @SsnfyJj
    @SsnfyJj Месяц назад

    I wish I could understand via English properly, This is the most important demo. Palo Alto Should give such training with proper English. He did all things good but We could not understand anything except what we saw in the GUI.

  • @mehmettokmak963
    @mehmettokmak963 Год назад +1

    What is the difference between uninstall agent and delete endpoint?

  • @vineetharumulla9101
    @vineetharumulla9101 2 года назад

    What is LOLBIN executable process in incidents? Could you please explain me

  • @vineetharumulla9101
    @vineetharumulla9101 2 года назад

    What's mean by "failed DNS" incident?

  • @wischfulthinking
    @wischfulthinking 3 месяца назад +1

    Impossible to understand.

  • @mike-fh8hi
    @mike-fh8hi Год назад

    yes, almost impossible to understand. all the time trying to guess

  • @vineetharumulla9101
    @vineetharumulla9101 2 года назад

    Why the PRO tag given to some endpoints?

    • @michaelalalade7129
      @michaelalalade7129 2 года назад

      PRO Tag on an "Endpoint name - Endpoint Table" indicates "PRO capabilities enabled"
      To enabled the Pro capabilities, Go to the applicable "Agent Settings" > XDR Pro Endpoints > Enable.
      Cortex XDR Pro agents capabilities including enhanced data collection, advanced responses, and attached add-ons.
      Note: This only applies to organizations with Cortex XDR Pro Licenses.

    • @vineetharumulla9101
      @vineetharumulla9101 2 года назад

      @@michaelalalade7129 Really thanks for your support for solving my doubts & responding within short time. I'm working on CORTEX XDR tool from paloalto.

  • @guyashkenazi1462
    @guyashkenazi1462 2 года назад

    conifg case_sensitive = false timeframe=30d
    | dataset = endpoints
    | filter endpoint_status = ENUM.CONNECTED or endpoint_status + ENUM.DISCONNECTED
    | alter agent_version_formatted = regextract(agent_version ,"^\D*(\d+(?:\.\d+)?)")
    | arrayexpand agent_version_formatted
    | comp count (agent_version_formatted ) as no_of_agents by agent_version_formatted
    | fields agent_version_formatted , no_of_agents
    | sort asc agent_version_formatted
    | view graph type = column subtype = grouped,horizontal header = "Count of Endpoints by Minor Release" show_callouts = 'true' legend = 'false' xaxis = agent_version_formatted xaxistitle = "Agents by Minor Release" yaxis = no_of_agents
    dataset = endpoints
    | fields endpoint_id, endpoint_name, last_seen
    | comp count() as count by endpoint_name addrawdata = true as raw_data
    | filter count > 1
    | sort desc count
    | alter endpoint_name = arrayindex (raw_data, 0) -> endpoint_name
    | alter endpoint_id = arrayindex (raw_data, 0) -> endpoint_id
    | alter last_seen = arrayindex (raw_data' 0) -> last_seen