> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2023-xdr/october-2023/feature-enhancements.md).

# Feature Enhancements

The Cortex XDR 3.8 and Cortex XDR Agent 8.2 releases include the following enhancements:

## Investigation and Response

| Feature                        | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| ------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Incident page enhancements     | The Incident Overview tab was revised to provide an improved incident response and investigation experience, including fonts, sizing, and other UI improvements.                                                                                                                                                                                                                                                                                                                 |
| New incident lifecycle widgets | <p>New and improved widgets help you measure the operational efficiency of incident and alert handling, and identify issues in the incident response process. The widgets identify peaks in incident and alert creation, provide visibility into the incident lifecycle, and help balance workloads by identifying the incidents assigned to each analyst:</p><ul><li>Open Incidents</li><li>Incidents by Status Duration</li><li>Open Incidents by Assignee Over Time</li></ul> |

## Endpoint Security

| Feature                                 | Description                                                                                                                                                                                                                |
| --------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Risky prevention policies notifications | Cortex XDR introduces a new feature that identifies risky prevention policies based on Palo Alto Networks best-practice policy settings. Admins can review and update flagged policies to enhance global security posture. |

## XDR Collectors

Windows 1.4.1.1100 and Linux 1.4.1.1046

For more information on maintenance releases, see [Maintenance Releases](/cortex-xdr-3.x-rn/cortex-xdr-release-information/maintenance-releases.md)

| Feature                                                                                                              | Description                                                                                                                  |
| -------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- |
| <p>XDR collectors upgraded Filebeat and Winlogbeat versions</p><p>(Requires a Cortex XDR Pro per GB license)</p>     | Cortex XDR now supports using Filebeat and Winlogbeat version 8.8.1 when using XDR collectors on Windows and Linux machines. |
| <p>Updated XDR Collectors for Linux and Windows Python versions</p><p>(Requires a Cortex XDR Pro per GB license)</p> | Cortex XDR has upgraded the XDR Collectors to use Linux Python 3.9.17 and Windows Python 3.7.17 on 32-bit or 64-bit.         |

## Broker VM

Version 21.1.12

For more information on maintenance releases, see [Maintenance Releases](/cortex-xdr-3.x-rn/cortex-xdr-release-information/maintenance-releases.md)

| Feature           | Description                                                   |
| ----------------- | ------------------------------------------------------------- |
| Broker VM 21.1.12 | This release includes performance improvements and bug fixes. |

## External Data Ingestion and Management

| Feature                        | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Lookup management enhancements | <ul><li>The Files and Folders Collector was enhanced with an option to automatically collect reference data into a lookup dataset. Read more in <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Activate-the-Files-and-Folders-Collector">Activate the Files and Folders Collector</a>.</li><li>While importing data manually from a file into an existing dataset using the Add Lookup option in the Dataset Management screen, you can now select to replace the existing data in the dataset.</li><li>You can now manually edit existing lookup datasets to update reference data directly from the console.</li></ul> |

## Cortex Query Language (XQL)

| Feature                                                                                                   | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| --------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| <p>New XQL convert\_to\_base\_64 function</p><p>(Requires a Cortex XDR Pro license)</p>                   | Corex XDR now supports a new function called `convert_to_base_64`, which converts the base64-decoded input to the encoded string format. See more in [convert\_to\_base\_64](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-XQL-Language-Reference/convert_to_base_64).                                                                                                                                                                                            |
| <p>New XQL datasets subset of xdr\_data</p><p>(Requires a Cortex XDR Pro license)</p>                     | <p>To provide faster query results, instead of querying the entire <code>xdr\_data</code> dataset, Cortex XDR added the following three datasets:</p><ul><li><code>vpn\_logs</code>: VPN logs, such as GlobalProtect.</li><li><code>auth\_logs</code>: Authentication logs, such as Okta.</li><li><code>login\_logs</code>: Login logs, such as WEC.</li></ul><p>The fields contained in any of these datasets are a subset of the fields in the <code>xdr\_data</code> dataset.</p> |
| <p>New system field added to XDR Collectors datasets</p><p>(Requires a Cortex XDR Pro per GB license)</p> | A new system field called `_collector_internal_ip_address` was added to all XDR Collector datasets including Filebeat and Winlogbeat data. This system field provides the internal IP of the endpoint.                                                                                                                                                                                                                                                                               |

## General

| Feature                                 | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| --------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| New Cortex In-App documentation         | <p>Cortex XDR now includes in-product documentation that helps you find information about new and existing features, reference material, and common workflows. While you're working with Cortex products (XDR/XSIAM/XSOAR), the documentation will launch relative to your current location from within the product.</p><p>Stay tuned for the Help Chat (which will gradually be rolled out), as part of the Cortex XDR Help Center. With the AI driven Help Chat, you will be able to asks questions about features and tasks and immediately receive a response.</p> |
| Enabling automatic backup in Cortex XDR | To better secure your machines against ransomware attacks, a new solution based on native operating system backup mechanisms (Time Machine from MacOS and Shadow Copy from Windows) allows customers to turn on automatic backups from Cortex XDR.                                                                                                                                                                                                                                                                                                                     |
| Cortex SSO improvements                 | For SSO configuration of Cortex XDR, you now have the option to enter a metadata URL, rather than manually providing the IdP SSO URL, issuer ID and x.509 certificate.                                                                                                                                                                                                                                                                                                                                                                                                 |
| Refresh all dashboard widgets           | Dashboards now include a refresh icon that updates the data for all dashboard widgets with a single click.                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Analytics Detector Tags                 | A new tag type, Detector Tags, has been added to Alerts, Incidents, and Analytics BIOC Rules. This tag enables you to filter for specific detectors such as Identity Threat, Identity Analytics, Alert Analytics. The addition of Detector Tags enables more efficient data analysis and threat management.                                                                                                                                                                                                                                                            |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2023-xdr/october-2023/feature-enhancements.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
