<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: check cortex xdr agent status in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/check-cortex-xdr-agent-status/m-p/476569#M1776</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/209717"&gt;@Seka&lt;/a&gt;&amp;nbsp;if your endpoint is not connected, run the following commands to identify if XDR is running.&lt;/P&gt;&lt;P&gt;cytool runtime query&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_0-1648542937051.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39875iEFD4018A2DE19899/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_0-1648542937051.png" alt="bbarmanroy_0-1648542937051.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;If this is a fresh installation, I'd recommend you to uninstall and reinstall the agent to see if it&amp;nbsp;works, assuming this endpoint has the same network access levels as others in your tenant.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Otherwise, try using the command "cytool&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;reconnect&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;force&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;lt;distribution ID&amp;gt;", where the ID can be obtained from the Agent Installations page (you can also create a new one).&lt;/LI&gt;&lt;LI&gt;Does a reboot help?&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;If the aforementioned steps fail, please raise a support ticket at&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://support.paloaltonetworks.com/" target="_blank" rel="noopener"&gt;support.paloaltonetworks.com&lt;/A&gt;. Please retrieve the TSF logs from the endpoint itself and upload it to the portal.&lt;BR /&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BR /&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ensure your endpoint agent has access to internet (host firewalls, perimeter firewalls, corporate proxies etc.). Check if this is an isolated incident with one endpoint/few endpoints or if it is happening with all endpoints in your estate.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ref:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-6/cortex-xdr-agent-admin/cortex-xdr-agent-for-windows/troubleshoot-cortex-xdr-for-windows/cytool.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-6/cortex-xdr-agent-admin/cortex-xdr-agent-for-windows/troubleshoot-cortex-xdr-for-windows/cytool.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Mar 2022 08:41:24 GMT</pubDate>
    <dc:creator>bbarmanroy</dc:creator>
    <dc:date>2022-03-29T08:41:24Z</dc:date>
    <item>
      <title>check cortex xdr agent status</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/check-cortex-xdr-agent-status/m-p/476289#M1769</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a doubt&lt;/P&gt;&lt;P&gt;how can I check the status of the cortex xdr service / agent in windows 10 ?&lt;/P&gt;&lt;P&gt;cause my client won't synchronize with server&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;greetings.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 12:17:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/check-cortex-xdr-agent-status/m-p/476289#M1769</guid>
      <dc:creator>Seka</dc:creator>
      <dc:date>2022-03-28T12:17:03Z</dc:date>
    </item>
    <item>
      <title>Re: check cortex xdr agent status</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/check-cortex-xdr-agent-status/m-p/476494#M1775</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/209717"&gt;@Seka&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i guess your agents are not able to check-in to cloud console,&amp;nbsp;I think you will have to use a 3rd party tool here. We use 3rd party tool to check on services of Cortex XDR if it is running or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or probably you can use the below command and loop over your endpoint list:&lt;/P&gt;&lt;P&gt;wmic /node:"you-pc" service list brief | findstr cyserver&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The above command wont be useful if the endpoints are not on domain and also where IP connectivity is limited.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 23:58:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/check-cortex-xdr-agent-status/m-p/476494#M1775</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2022-03-28T23:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: check cortex xdr agent status</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/check-cortex-xdr-agent-status/m-p/476569#M1776</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/209717"&gt;@Seka&lt;/a&gt;&amp;nbsp;if your endpoint is not connected, run the following commands to identify if XDR is running.&lt;/P&gt;&lt;P&gt;cytool runtime query&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_0-1648542937051.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39875iEFD4018A2DE19899/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_0-1648542937051.png" alt="bbarmanroy_0-1648542937051.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;If this is a fresh installation, I'd recommend you to uninstall and reinstall the agent to see if it&amp;nbsp;works, assuming this endpoint has the same network access levels as others in your tenant.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Otherwise, try using the command "cytool&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;reconnect&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;force&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;lt;distribution ID&amp;gt;", where the ID can be obtained from the Agent Installations page (you can also create a new one).&lt;/LI&gt;&lt;LI&gt;Does a reboot help?&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;If the aforementioned steps fail, please raise a support ticket at&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://support.paloaltonetworks.com/" target="_blank" rel="noopener"&gt;support.paloaltonetworks.com&lt;/A&gt;. Please retrieve the TSF logs from the endpoint itself and upload it to the portal.&lt;BR /&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BR /&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ensure your endpoint agent has access to internet (host firewalls, perimeter firewalls, corporate proxies etc.). Check if this is an isolated incident with one endpoint/few endpoints or if it is happening with all endpoints in your estate.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ref:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-6/cortex-xdr-agent-admin/cortex-xdr-agent-for-windows/troubleshoot-cortex-xdr-for-windows/cytool.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-6/cortex-xdr-agent-admin/cortex-xdr-agent-for-windows/troubleshoot-cortex-xdr-for-windows/cytool.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 08:41:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/check-cortex-xdr-agent-status/m-p/476569#M1776</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-03-29T08:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: check cortex xdr agent status</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/check-cortex-xdr-agent-status/m-p/476589#M1777</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/209717"&gt;@Seka&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if with the command that &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192661"&gt;@bbarmanroy&lt;/a&gt; provided you see that services are not running, please try the following in your non connected endpoint and as admin user:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\Program Files\Palo Alto Networks\Traps\cytool.exe runtime start&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That should start the services/xdr processes and if it doesn't, it will give you an error or some clue of what might be going on at your endpoint.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this command does not get your xdr services/processes up and running and/or if your agent is not able to do the checkin, please open a TAC support case and our TAC engineers will help you further.&lt;/P&gt;&lt;P&gt;You can also try to force the checkin (once your xdr processes are running) with cytool.exe checkin&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure that your endpoint is not network-isolated so it can reach the tenant. That might be another issue&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR,&lt;/P&gt;&lt;P&gt;Luis&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 10:06:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/check-cortex-xdr-agent-status/m-p/476589#M1777</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2022-03-29T10:06:22Z</dc:date>
    </item>
    <item>
      <title>Re: check cortex xdr agent status</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/check-cortex-xdr-agent-status/m-p/476925#M1801</link>
      <description>&lt;P&gt;thank you for your reply , i will try it and get you back&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 15:21:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/check-cortex-xdr-agent-status/m-p/476925#M1801</guid>
      <dc:creator>Seka</dc:creator>
      <dc:date>2022-03-30T15:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: check cortex xdr agent status</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/check-cortex-xdr-agent-status/m-p/476928#M1802</link>
      <description>&lt;P&gt;hi ,thank you for you reply , please see in attachment the screenshot on cytool runtime query command&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 15:26:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/check-cortex-xdr-agent-status/m-p/476928#M1802</guid>
      <dc:creator>Seka</dc:creator>
      <dc:date>2022-03-30T15:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: check cortex xdr agent status</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/check-cortex-xdr-agent-status/m-p/476958#M1805</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/209717"&gt;@Seka&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please check that the following exists&lt;SPAN&gt;C:\Windows\System32\drivers\telam.sys&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If it doesnt exist open a TAC support ticket&lt;/P&gt;&lt;P&gt;If it exists, type&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;C:\Program Files\Palo Alto Networks\Traps&amp;gt;sc config telam start= boot&lt;/P&gt;&lt;P&gt;C:\Program Files\Palo Alto Networks\Traps&amp;gt;cytool runtime start&lt;/P&gt;&lt;P&gt;check that everything is runing with cytool runtime query&amp;nbsp;&lt;/P&gt;&lt;P&gt;If not running reboot and check again with cytool if the telam is running (as well as the other processes). For the sc config command you will need the supervisor pass (the same as the uninstall pass)&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it doesnt work please open a TAC support ticket.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know if this happened after trying to upgrade and having it failed ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luis&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 16:02:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/check-cortex-xdr-agent-status/m-p/476958#M1805</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2022-03-30T16:02:39Z</dc:date>
    </item>
    <item>
      <title>Re: check cortex xdr agent status</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/check-cortex-xdr-agent-status/m-p/588864#M6790</link>
      <description>&lt;P&gt;To check service status:&amp;nbsp; sc query cyserver&lt;/P&gt;
&lt;P&gt;To start the service: sc start&amp;nbsp;&amp;nbsp;cyserver&lt;/P&gt;
&lt;P&gt;check the event viewer logs :&amp;nbsp; eventvwr.msc&lt;/P&gt;
&lt;P&gt;Check the XDR agent logs:&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;SPAN&gt;C:\Program Files\Palo Alto Networks\Traps\logs&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Find more detail for further troubleshooting:&amp;nbsp; &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/8.4/Cortex-XDR-Agent-Administrator-Guide/Use-Cortex-XDR-Agent-for-Windows" target="_blank"&gt;Use Cortex XDR Agent for Windows • Cortex XDR Agent Administrator Guide • Reader • Palo Alto Networks documentation portal&lt;/A&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 17:50:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/check-cortex-xdr-agent-status/m-p/588864#M6790</guid>
      <dc:creator>jgupta</dc:creator>
      <dc:date>2024-06-05T17:50:31Z</dc:date>
    </item>
  </channel>
</rss>

