Configure Cortex XDR network parameters
Define your internal IP address ranges and domain names to enable Cortex XDR to identify, track, and analyze network assets.
Define internal IP address ranges
The IP Address Ranges page displays the address ranges that Cortex XDR - Analytics monitors. Addresses are pre-populated with the default IPv4 and IPv6 address spaces. The names you define will appear when investigating the network-related events in Cortex XDR.
You can add a new IP address range manually or upload IP address ranges from a CSV file.
How to define internal IP address ranges
Select Assets → Network Configuration → Internal IP Address Ranges.
Do one of the following:
ToDo thisAdd a new IP address manually
1. Click Add New Range → Create New, and then enter the IP address name and IP address range or CIDR values.
By default, Cortex XDR creates Private Network ranges that specify reserved industry-approved ranges. Private Network ranges are marked with a
icon and you can only edit the name.2. Click Save.
Upload IP address ranges from a CSV file
1. Select Assets → Network Configuration → Internal IP Address Ranges.
2. Click Add New Range → Upload from File.
3. Locate the CSV file you want to upload, and then click Add.
Define internal domain names
Select Assets → Network Configuration → Internal Domain Suffixes.
Type the domain suffix you want to include as part of your internal network, for example,
acme.com.Select
to add the suffix to the Domains List.
Last updated
Was this helpful?
