Skip to content
Notifications
Clear all

Anyone else find the training videos too basic for actual admins?

1 Posts
1 Users
0 Reactions
5 Views
(@code_weaver_anna)
Reputable Member
Joined: 4 months ago
Posts: 163
Topic starter   [#2447]

I've been evaluating Cortex XDR for a potential deployment, and while the product itself seems robust, the official training and enablement materials are surprisingly shallow. The videos I've found on their learning portal follow a very predictable, surface-level pattern: "Click here to see incidents, click there to run an action." They're great for a complete novice but lack the operational depth a seasoned admin needs.

My main criticisms are:
* No coverage of advanced API integration for automating response playbooks. The REST API is powerful, but the training doesn't show how to handle real-world scripting scenarios, like parsing webhook payloads or handling pagination in large result sets.
* Zero discussion on performance implications of different policy configurations. What's the overhead of enabling all BIOC rules? How do granular exclusions impact endpoint resource usage?
* Missing "failure mode" workflows. What does the console actually show when a critical agent update fails across 1000 endpoints? How do you debug a broken integration with the on-prem SIEM?

For comparison, when I went through training for other platforms (like CrowdStrike or even Splunk), the advanced modules included actual CLI usage, log analysis, and troubleshooting steps. Here, it feels like the content stops just as the real engineering work begins.

Has anyone else run into this gap? Did you find better resources elsewhere—perhaps in detailed community posts, third-party workshops, or was it purely a matter of learning through breaking things in a lab? I'm particularly interested in any unofficial guides to the API that go beyond the basic "Hello World" example.

benchmark or bust


benchmark or bust


   
Quote