<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: A question about Cortex 7.3.0 in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-about-cortex-7-3-0/m-p/430671#M1011</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Just wondering if anyone else is experiencing this... We have about 600 XDR agents deployed and keep running into scenarios where the agents just seemingly randomly stop checking in. Nothing meaningful in the logs. Doing a cytool checkin does nothing. The agents disappear from the dashboard entirely making it reeeeeeallly hard to even determine that the agent has stopped communicating. If we use the XDRAgentCleaner to manually remove the agent and re-install it magically starts working just fine. We've seen it on multiple agent versions from 7.0 to 7.3. The last_checkin dates are all over the map.. It's just super odd. Palo support has been completely unhelpful.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.rapidfs.us/" target="_self"&gt;&lt;SPAN&gt;official rapidfs&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Sep 2021 04:59:32 GMT</pubDate>
    <dc:creator>Breitenberg</dc:creator>
    <dc:date>2021-09-02T04:59:32Z</dc:date>
    <item>
      <title>A question about Cortex 7.3.0</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-about-cortex-7-3-0/m-p/429647#M1001</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What does it mean to see Cortex status DISABLED in the VDI?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking forward.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 08:23:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-about-cortex-7-3-0/m-p/429647#M1001</guid>
      <dc:creator>LuisEhate</dc:creator>
      <dc:date>2021-08-27T08:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: A question about Cortex 7.3.0</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-about-cortex-7-3-0/m-p/430612#M1009</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155629"&gt;@LuisEhate&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What does it mean to see Cortex status DISABLED in the VDI?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking forward.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Hello LuisEhate,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you share a screenshot of your issue?, If you are referring to Cortex XDR agent operational status.&lt;/P&gt;&lt;P&gt;You can find more information here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/monitoring/monitor-agent-operational-status.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/monitoring/monitor-agent-operational-status.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example the unprotected status could mean;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV&gt;Behavioral threat protection and Malware protection are not running&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Exploit protection and malware protection are not running&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;The content is unavailable.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cortex XDR agent on VDI's:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-2/cortex-xdr-agent-admin/cortex-xdr-agent-for-windows/cortex-agent-for-virtual-environments-and-desktops.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-2/cortex-xdr-agent-admin/cortex-xdr-agent-for-windows/cortex-agent-for-virtual-environments-and-desktops.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Endpoint details:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-endpoints/view-details-for-an-endpoint.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-endpoints/view-details-for-an-endpoint.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;P class="p1"&gt;The registration statuses of the Cortex XDR agent on endpoint are:&lt;/P&gt;&lt;P class="p1"&gt;&lt;STRONG&gt;• Connected&lt;/STRONG&gt;—The Cortex XDR agent has checked in within 10 minutes for standard endpoints, and within 3 hours for mobile endpoints.&lt;/P&gt;&lt;P class="p1"&gt;&lt;STRONG&gt;• Connection Lost&lt;/STRONG&gt;—The Cortex XDR agent has not checked in within 30 to 180 days for standard endpoints, and between 90 minutes and 6 hours for VDI and temporary sessions.&lt;/P&gt;&lt;P class="p1"&gt;&lt;STRONG&gt;• Disconnected&lt;/STRONG&gt;—The Cortex XDR agent has checked in within the defined inactivity window: between 10 minutes and 30 days for standard and mobile endpoints, and between 10 minutes and 90 minutes for VDI and temporary sessions.&lt;/P&gt;&lt;P class="p1"&gt;&lt;STRONG&gt;• VDI Pending Log-on&lt;/STRONG&gt;—(&lt;STRONG&gt;Windows only&lt;/STRONG&gt;) Indicates a non-persistent VDI endpoint is waiting for user logon, after which the Cortex XDR agent consumes a license and starts enforcing protection.&lt;/P&gt;&lt;P class="p1"&gt;&lt;STRONG&gt;• Uninstalled&lt;/STRONG&gt;—The Cortex XDR agent has been uninstalled from the endpoint.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 31 Aug 2021 22:48:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-about-cortex-7-3-0/m-p/430612#M1009</guid>
      <dc:creator>yalonso</dc:creator>
      <dc:date>2021-08-31T22:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: A question about Cortex 7.3.0</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-about-cortex-7-3-0/m-p/430671#M1011</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Just wondering if anyone else is experiencing this... We have about 600 XDR agents deployed and keep running into scenarios where the agents just seemingly randomly stop checking in. Nothing meaningful in the logs. Doing a cytool checkin does nothing. The agents disappear from the dashboard entirely making it reeeeeeallly hard to even determine that the agent has stopped communicating. If we use the XDRAgentCleaner to manually remove the agent and re-install it magically starts working just fine. We've seen it on multiple agent versions from 7.0 to 7.3. The last_checkin dates are all over the map.. It's just super odd. Palo support has been completely unhelpful.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.rapidfs.us/" target="_self"&gt;&lt;SPAN&gt;official rapidfs&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2021 04:59:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-about-cortex-7-3-0/m-p/430671#M1011</guid>
      <dc:creator>Breitenberg</dc:creator>
      <dc:date>2021-09-02T04:59:32Z</dc:date>
    </item>
  </channel>
</rss>

