<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR Agent profile:  content auto-update delay in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-profile-content-auto-update-delay/m-p/502208#M2162</link>
    <description>&lt;P&gt;Are you 100% sure of that?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is what logically should happen, but I ran into the exact issue that the OP is referring to where a CU was pushed, broke things, the next day it got fixed by a new CU, but my machines that were set to a 3 days delay picked up the broken CU first.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This happened to my environment back in early March 2022.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe things have changed now, but I can confirm that OP's concern is a valid one as I've seen it happen. There is no way for us customers to exclude a content update. What I ended up doing was work my way around it by changing the delay to a very long delay and then once I was sure the latest wasn't causing issues, I switched my initial group that had the delay setup to immediate content so they would pick up the latest one and then changed it back to 3 days delay once they were all to the point I wanted them.&lt;/P&gt;</description>
    <pubDate>Thu, 09 Jun 2022 13:21:15 GMT</pubDate>
    <dc:creator>Luc_Desaulniers</dc:creator>
    <dc:date>2022-06-09T13:21:15Z</dc:date>
    <item>
      <title>Cortex XDR Agent profile:  content auto-update delay</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-profile-content-auto-update-delay/m-p/501653#M2144</link>
      <description>&lt;P&gt;Hi everyone, I was wondering how the content auto-update delay feature works when a CU borks a system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Last week we experienced a sudden spike in cpu and ram usage, and the affected machines crawled and stuttered, impacting production. Support told us to wait for a specific content update to be released, which would (as had been appened) correct the problem.&lt;BR /&gt;&lt;BR /&gt;So, in a scenario like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Agent profile grp_CriticalServers : cu delay: 3 days.&lt;BR /&gt;Agent profile grp_Workstations: cu delay: none&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;day 0: CU 500-00001 released, applied on grp_Workstations , grp_CriticalServers still on CU 500-00000&lt;BR /&gt;day 1: CU 500-00001 works as expected&lt;BR /&gt;day 2: CU 500-00002 wreak havoc on grp_Workstations, grp_CriticalServer still on 500-0000&lt;/P&gt;&lt;P&gt;day 3: CU 500-00003 and CU 500-00004 released , grp_Workstations now working normally.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question: at day 3, which content update will be served to the grp_CriticalServers? The last available 00004 ? 00001 and then after another 3 days, all the critical servers will be affected by the problematic CU 00002?&lt;BR /&gt;&lt;BR /&gt;In the first case, going straight to the last available come with some risks, the latter is not acceptable if there is no way to deprecate a CU. Or there is?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The end goal is to use the vast majority of machines as canary for the critical servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How did you manage a situation like that?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 08:17:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-profile-content-auto-update-delay/m-p/501653#M2144</guid>
      <dc:creator>RobertoPastorino</dc:creator>
      <dc:date>2022-06-08T08:17:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Agent profile:  content auto-update delay</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-profile-content-auto-update-delay/m-p/501808#M2150</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/110751"&gt;@RobertoPastorino&lt;/a&gt;&amp;nbsp;you can consider using rollout delay for Content Updates to meet your needs. You will need to create a separate Agent Settings Profile and assign them to targetted endpoints.&lt;/P&gt;&lt;P&gt;Refer to Step 12:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/customizable-agent-settings/add-agent-settings-profile" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/customizable-agent-settings/add-agent-settings-profile&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 14:39:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-profile-content-auto-update-delay/m-p/501808#M2150</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-06-08T14:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Agent profile:  content auto-update delay</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-profile-content-auto-update-delay/m-p/501813#M2151</link>
      <description>Hi, thank you for your reply, but this has already been considered.&lt;BR /&gt;&lt;BR /&gt;What I don't know is the way the content updates are managed in the scenario depicted.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;What happens when a CU is going rogue and start to create problems to the endpoints were is deployed? In a delayed deployment , there is a method to exclude a specific content update from the available ones? This should be the ratio behind the delay , test a CU before deployment in a critical environment. But how can I be certain that a delayed, problematic update, won't be pushed to the agent?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;BR&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 08 Jun 2022 15:46:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-profile-content-auto-update-delay/m-p/501813#M2151</guid>
      <dc:creator>RobertoPastorino</dc:creator>
      <dc:date>2022-06-08T15:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Agent profile:  content auto-update delay</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-profile-content-auto-update-delay/m-p/501815#M2152</link>
      <description>&lt;P&gt;Hi RobertoPastorino,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In a case like this where a CU is identified as causing issues by Palo Alto Networks, the CU gets rolled back and then replaced.&amp;nbsp; The endpoints that are delayed will never receive the "bad" CU, they will just get the next CU after the delay period ends.&amp;nbsp; For example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hour 0: New CU released, agents with out delay get updated&lt;/P&gt;&lt;P&gt;Hour 24: CU is identified by PANW as causing issues, CU is rolled back&lt;/P&gt;&lt;P&gt;Hour 48: New CU is released, agents without delay get updated&lt;/P&gt;&lt;P&gt;* 72 hours after new CU released, so hour 120 *&lt;/P&gt;&lt;P&gt;Hour 120: New CU is installed to agents with delay&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These are just hypothetical numbers, issue discovery, CU rollback and replacement are always dynamic and unique to a specific issue.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 16:08:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-profile-content-auto-update-delay/m-p/501815#M2152</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2022-06-08T16:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Agent profile:  content auto-update delay</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-profile-content-auto-update-delay/m-p/501822#M2153</link>
      <description>Fantastic, this is what I hoped to be the case &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;So, content updates are not cached locally and are revoked / Replaced by PAN .&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thank you!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 08 Jun 2022 16:22:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-profile-content-auto-update-delay/m-p/501822#M2153</guid>
      <dc:creator>RobertoPastorino</dc:creator>
      <dc:date>2022-06-08T16:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Agent profile:  content auto-update delay</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-profile-content-auto-update-delay/m-p/502208#M2162</link>
      <description>&lt;P&gt;Are you 100% sure of that?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is what logically should happen, but I ran into the exact issue that the OP is referring to where a CU was pushed, broke things, the next day it got fixed by a new CU, but my machines that were set to a 3 days delay picked up the broken CU first.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This happened to my environment back in early March 2022.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe things have changed now, but I can confirm that OP's concern is a valid one as I've seen it happen. There is no way for us customers to exclude a content update. What I ended up doing was work my way around it by changing the delay to a very long delay and then once I was sure the latest wasn't causing issues, I switched my initial group that had the delay setup to immediate content so they would pick up the latest one and then changed it back to 3 days delay once they were all to the point I wanted them.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2022 13:21:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-profile-content-auto-update-delay/m-p/502208#M2162</guid>
      <dc:creator>Luc_Desaulniers</dc:creator>
      <dc:date>2022-06-09T13:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Agent profile:  content auto-update delay</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-profile-content-auto-update-delay/m-p/502221#M2164</link>
      <description>&lt;P&gt;Hi Luc_Desauliniers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It does of course depend on Palo Alto support identifying a widespread issue and engineering deciding to rollback the CU, but in the case with this most recent CU issue, I can confirm it was indeed rolled back.&amp;nbsp; In your case it is possible it was not rolled back by engineering.&amp;nbsp; I recommend you speak with your account team to get a feature request submitted to identify a better solution for managing CUs if needed.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2022 13:49:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-profile-content-auto-update-delay/m-p/502221#M2164</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2022-06-09T13:49:26Z</dc:date>
    </item>
  </channel>
</rss>

