# Palo Alto Cortex XDR Update

**URL:** <https://discuss.elastic.co/t/palo-alto-cortex-xdr-update/373968>\
**Category:** Elastic Agent\
**Tags:** integrations\
**Created:** [February 1, 2025, 11:38am UTC](https://discuss.elastic.co/t/palo-alto-cortex-xdr-update/373968 "2025-02-01T11:38:30Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![x\_deee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/x_deee/32/141091_2.png) [@x\_deee](https://discuss.elastic.co/u/x_deee)\
**Post date:** [February 1, 2025, 11:38am UTC](https://discuss.elastic.co/t/palo-alto-cortex-xdr-update/373968/1 "2025-02-01T11:38:30Z")

</div>

Recently, Cortex XDR by Palo Alto updated their api endpoint URLs from v1 to v2. This small change prevents data from entering our Elasticstack. So far, I have attempted to change elastic-agent.yml and change the httpjson.yml.hbs file to reflect the new url, and I have even uninstall and reinstalled the package after the changes. The agent still reverts to the v1 version of the url.

The agents make a call to /public\_api/v1/alerts/get\_alerts\_multi\_events when they should make a call to /public\_api/v2/alerts/get\_alerts\_multi\_events.

We need either an update (1.33.0) on the Cortex XDR integration package or a walk through so that we can change the API endpoint URL to v2.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 1, 2025, 3:24pm UTC](https://discuss.elastic.co/t/palo-alto-cortex-xdr-update/373968/2 "2025-02-01T15:24:35Z")

</div>

Hi @x_deee Welcome to the community and thanks for reporting this  
I pinged internally to the correct folks. Let's see what they come back with.

---

<div class="post-metadata">

**Author:** ![x\_deee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/x_deee/32/141091_2.png) [@x\_deee](https://discuss.elastic.co/u/x_deee)\
**Post date:** [February 1, 2025, 3:41pm UTC](https://discuss.elastic.co/t/palo-alto-cortex-xdr-update/373968/3 "2025-02-01T15:41:34Z")

</div>

Thank you for the quick response. The v1 url came online again today, so I'll work with that until the update.

Also, the alerts pipeline/mappings seem to be missing for the current version. We are working around that as well. Thanks again.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 1, 2025, 3:45pm UTC](https://discuss.elastic.co/t/palo-alto-cortex-xdr-update/373968/4 "2025-02-01T15:45:00Z")

</div>

> [@x\_deee](#):
>
> Also, the alerts pipeline/mappings seem to be missing for the current version.

Hmmmm perhaps reload the assets you should have all these  
I just installed / reloaded and they are all there

 ![Screenshot 2025-02-01 at 7.44.22 AM](https://us1.discourse-cdn.com/elastic/original/3X/c/7/c75d1a8521d4c39ee36b85118c34ef6ba16c9391.png)

---

<div class="post-metadata">

**Author:** ![x\_deee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/x_deee/32/141091_2.png) [@x\_deee](https://discuss.elastic.co/u/x_deee)\
**Post date:** [February 1, 2025, 3:53pm UTC](https://discuss.elastic.co/t/palo-alto-cortex-xdr-update/373968/5 "2025-02-01T15:53:28Z")

</div>

Interesting. I'm going to double check things on my end. This was a massive help. Thank you.

---

<div class="post-metadata">

**Author:** ![cyberguy2024](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyberguy2024/32/140237_2.png) [@cyberguy2024](https://discuss.elastic.co/u/cyberguy2024)\
**Post date:** [February 1, 2025, 4:07pm UTC](https://discuss.elastic.co/t/palo-alto-cortex-xdr-update/373968/6 "2025-02-01T16:07:19Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/d/7/d7f04b918694a37e470d7f5e50ba4e79808ccc07.png)

I also have the same issue. I tired reinstalling the package through the settings tab but nothing shows up in the assets tab. Any suggestions?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 1, 2025, 4:11pm UTC](https://discuss.elastic.co/t/palo-alto-cortex-xdr-update/373968/7 "2025-02-01T16:11:32Z")

</div>

Try uninstall then reinstall?

You can also go check if the assets are actually there.. manually

There may be a glitch where they're just not showing up there in that list.

You can use my image from above

One note

`logs@custom` may not really be there. It's a placeholder

---

<div class="post-metadata">

**Author:** ![cyberguy2024](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyberguy2024/32/140237_2.png) [@cyberguy2024](https://discuss.elastic.co/u/cyberguy2024)\
**Post date:** [February 1, 2025, 4:23pm UTC](https://discuss.elastic.co/t/palo-alto-cortex-xdr-update/373968/8 "2025-02-01T16:23:54Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/0/0/0031edaf19e03644c1e3ec11fc622a7453c54450.png)  
I tried the uninstall and reinstall with no change in the asset tab view. I looked under ingest pipelines and I can still see the cortex pipelines however the data coming in isn't being parsed properly. I'm using an offline EPR for pulling in packages since my cluster is air gapped.

---

<div class="post-metadata">

**Author:** ![x\_deee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/x_deee/32/141091_2.png) [@x\_deee](https://discuss.elastic.co/u/x_deee)\
**Post date:** [February 3, 2025, 4:50am UTC](https://discuss.elastic.co/t/palo-alto-cortex-xdr-update/373968/9 "2025-02-03T04:50:30Z")

</div>

Hello again.

After careful testing, I have determined the issue to be with Security Onion's implementation of the ELK Stack. When installing a proper ELK stack, the assets/pipelines work fine. So, I'll start a discussion on their forum. Thanks again for the help.
