<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Scan stuck on \\?\GLOBALROOT\Device\HardiskVolume3\System Volume Information\tracking.log in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-stuck-on-globalroot-device-hardiskvolume3-system-volume/m-p/484856#M1944</link>
    <description>&lt;P&gt;Hi Fred.L,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you using the CE (Critical Environment) version? Or just the standard 7.5? The reason I ask is if you are not using the CE version then I would recommend using version 7.6 or later. Prior to 7.6 there were similar issues reported that were fixed in the agent 7.6 release. If you are using the CE version then I recommend opening a support case so our support engineers can conduct advanced troubleshooting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
    <pubDate>Wed, 04 May 2022 13:24:09 GMT</pubDate>
    <dc:creator>bbucao</dc:creator>
    <dc:date>2022-05-04T13:24:09Z</dc:date>
    <item>
      <title>Scan stuck on \\?\GLOBALROOT\Device\HardiskVolume3\System Volume Information\tracking.log</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-stuck-on-globalroot-device-hardiskvolume3-system-volume/m-p/484143#M1933</link>
      <description>&lt;P&gt;Hello, we are using Cortex in a Citrix PVS environment.&lt;/P&gt;&lt;P&gt;We installed the agent with the VDI flag on the master vDisk. When we try to generate a scan on the new version of the vDisk, it always stuck on this file:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;\\?\GLOBALROOT\Device\HardiskVolume3\System Volume Information\tracking.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We know that tracking.log a file responsible of the ntfs changes and other things and that we can't have access to this folder because it's protected by the sytem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But is there any way to exclude this file from the scan via the&amp;nbsp;&lt;SPAN&gt;cytool imageprep scan command line ? We tried to change the timeout values or the upload value but nothing changes and we could not find any documentation using the /help flag.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Other thing we tried: scan with the malware module DISABLED =&amp;gt; nothing changed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The restore file features is disabled on our drives.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks you for your help,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Fred&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2022 13:23:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-stuck-on-globalroot-device-hardiskvolume3-system-volume/m-p/484143#M1933</guid>
      <dc:creator>fred.l</dc:creator>
      <dc:date>2022-05-02T13:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: Scan stuck on \\?\GLOBALROOT\Device\HardiskVolume3\System Volume Information\tracking.log</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-stuck-on-globalroot-device-hardiskvolume3-system-volume/m-p/484718#M1941</link>
      <description>&lt;P&gt;Hi Fred.L,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you share what agent version you are using?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 03:24:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-stuck-on-globalroot-device-hardiskvolume3-system-volume/m-p/484718#M1941</guid>
      <dc:creator>bbucao</dc:creator>
      <dc:date>2022-05-04T03:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: Scan stuck on \\?\GLOBALROOT\Device\HardiskVolume3\System Volume Information\tracking.log</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-stuck-on-globalroot-device-hardiskvolume3-system-volume/m-p/484771#M1943</link>
      <description>Hello Ben,&lt;BR /&gt;Thank you for your interest.&lt;BR /&gt;Here is the agent version we are running (OS 2019 Server):&lt;BR /&gt;Cortex XDR 7.5.1.40243&lt;BR /&gt;Fred&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 04 May 2022 09:33:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-stuck-on-globalroot-device-hardiskvolume3-system-volume/m-p/484771#M1943</guid>
      <dc:creator>fred.l</dc:creator>
      <dc:date>2022-05-04T09:33:33Z</dc:date>
    </item>
    <item>
      <title>Re: Scan stuck on \\?\GLOBALROOT\Device\HardiskVolume3\System Volume Information\tracking.log</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-stuck-on-globalroot-device-hardiskvolume3-system-volume/m-p/484856#M1944</link>
      <description>&lt;P&gt;Hi Fred.L,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you using the CE (Critical Environment) version? Or just the standard 7.5? The reason I ask is if you are not using the CE version then I would recommend using version 7.6 or later. Prior to 7.6 there were similar issues reported that were fixed in the agent 7.6 release. If you are using the CE version then I recommend opening a support case so our support engineers can conduct advanced troubleshooting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 13:24:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-stuck-on-globalroot-device-hardiskvolume3-system-volume/m-p/484856#M1944</guid>
      <dc:creator>bbucao</dc:creator>
      <dc:date>2022-05-04T13:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: Scan stuck on \\?\GLOBALROOT\Device\HardiskVolume3\System Volume Information\tracking.log</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-stuck-on-globalroot-device-hardiskvolume3-system-volume/m-p/484862#M1945</link>
      <description>Hi Ben,&lt;BR /&gt;I will ask for the security team and will answer you as soon as I can. Thank you for this precision.&lt;BR /&gt;Fred&lt;BR /&gt;</description>
      <pubDate>Wed, 04 May 2022 13:26:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-stuck-on-globalroot-device-hardiskvolume3-system-volume/m-p/484862#M1945</guid>
      <dc:creator>fred.l</dc:creator>
      <dc:date>2022-05-04T13:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: Scan stuck on \\?\GLOBALROOT\Device\HardiskVolume3\System Volume Information\tracking.log</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-stuck-on-globalroot-device-hardiskvolume3-system-volume/m-p/488207#M2011</link>
      <description>Hello Ben,&lt;BR /&gt;I update the discussion: after following your recommendations, we upgrade the agent to the 7.7 version and the scan completed successfully.&lt;BR /&gt;Thank you for your help,&lt;BR /&gt;Fred&lt;BR /&gt;</description>
      <pubDate>Wed, 18 May 2022 13:37:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-stuck-on-globalroot-device-hardiskvolume3-system-volume/m-p/488207#M2011</guid>
      <dc:creator>fred.l</dc:creator>
      <dc:date>2022-05-18T13:37:33Z</dc:date>
    </item>
  </channel>
</rss>

