<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Force policy check in Cortex XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/349039#M293</link>
    <description>&lt;P&gt;A ticket is open with PaloAlto support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Whenever I create a new set of policies, it does not apply to any endpoints.&amp;nbsp; NEVER!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seems to be a "bug" within PaloAlto.&lt;/P&gt;</description>
    <pubDate>Mon, 14 Sep 2020 11:46:52 GMT</pubDate>
    <dc:creator>MartinCimone</dc:creator>
    <dc:date>2020-09-14T11:46:52Z</dc:date>
    <item>
      <title>Force policy check in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/347886#M280</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any way to force a policy check on an endpoint?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have created a new Policy Rule and assigned a new set of Policy Profiles to it.&amp;nbsp; I then assigned specific endpoints to this Policy Rule and the rule is #1 in the policy order tab.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem I am facing is that the targeted computers do not seem to receive the new policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;YES, the rule is ENABLED&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your time.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 14:15:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/347886#M280</guid>
      <dc:creator>MartinCimone</dc:creator>
      <dc:date>2020-09-09T14:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: Force policy check in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/348810#M287</link>
      <description>&lt;P&gt;What do you mean with 'computers does not seem to receive policy' ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Whenever there is some file execution, Cortex XDR will initiate its soo called File Analysis and Protection Flow, which evaluates it's decision based on the defined profiles within the policies applied to the given endpoint.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best,&lt;/P&gt;&lt;P&gt;D&lt;/P&gt;</description>
      <pubDate>Sun, 13 Sep 2020 16:00:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/348810#M287</guid>
      <dc:creator>DKasabji</dc:creator>
      <dc:date>2020-09-13T16:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: Force policy check in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/349039#M293</link>
      <description>&lt;P&gt;A ticket is open with PaloAlto support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Whenever I create a new set of policies, it does not apply to any endpoints.&amp;nbsp; NEVER!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seems to be a "bug" within PaloAlto.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 11:46:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/349039#M293</guid>
      <dc:creator>MartinCimone</dc:creator>
      <dc:date>2020-09-14T11:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: Force policy check in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/349040#M294</link>
      <description>&lt;P&gt;Hmm. I am sure PA will be able to help you as they can see more details. I know that in our case it is working normally.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you checked that the policy is correctly applied to the endpoints?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best,&lt;/P&gt;&lt;P&gt;D&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 11:55:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/349040#M294</guid>
      <dc:creator>DKasabji</dc:creator>
      <dc:date>2020-09-14T11:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: Force policy check in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/349059#M295</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/154882"&gt;@MartinCimone&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You should be able to force a policy check-in using by leveraging the script execution abilities of the agent.&amp;nbsp; You can initiate a cytool checkin command.&amp;nbsp; More info can be found at:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/5-0/cortex-xdr-agent-admin/traps-agent-for-windows/troubleshoot-traps-for-windows/cytool.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/5-0/cortex-xdr-agent-admin/traps-agent-for-windows/troubleshoot-traps-for-windows/cytool.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On your underlying issue, have you verified that the affected endpoints fall into the collection/group where the policy rule is applied.&amp;nbsp; If you look at the agent details:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Do the endpoints show as online?&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Does it show the policy applied ?&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; If you initiate a check-in from the endpoint itself, do you see successful communication?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 13:04:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/349059#M295</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-09-14T13:04:11Z</dc:date>
    </item>
    <item>
      <title>Re: Force policy check in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/349060#M296</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/47142"&gt;@dfalcon&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Do the endpoints show as online?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;YES they are.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Does it show the policy applied ?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Nope.&amp;nbsp; That's my whole problem ...&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; If you initiate a check-in from the endpoint itself, do you see successful communication?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Absolutely.&amp;nbsp; Targetted endpoints are even receiving content update but are not updating the policy assigned to it.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A support case has been opened with PaloAlto and they are still investigating the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your time &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 13:08:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/349060#M296</guid>
      <dc:creator>MartinCimone</dc:creator>
      <dc:date>2020-09-14T13:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: Force policy check in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/349061#M297</link>
      <description>&lt;P&gt;Will be interesting to see what the root cause was.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Sounds like there is no transmission between Endpoints and Console for only just policies, which is weird.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you tried accessing the Endpoint via Console through Live Terminal? Or run any script from Action Center? Just to see if you are able to interact with them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 13:11:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/349061#M297</guid>
      <dc:creator>DKasabji</dc:creator>
      <dc:date>2020-09-14T13:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: Force policy check in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/349065#M299</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/154882"&gt;@MartinCimone&lt;/a&gt;&amp;nbsp;-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you go to one of the affected machines and make note of the time and click check-in now from the agent interface?&amp;nbsp; Once you have initiated the request, give it a few seconds.&amp;nbsp; Next, open the log file from the same agent interface.&amp;nbsp; Scroll to the bottom and work your way back up.&amp;nbsp; Look for the time you click check in now.&amp;nbsp; Do you see any errors or communication failure messages during that time?&amp;nbsp; This may give us a good starting point to isolate the issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 13:21:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/349065#M299</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-09-14T13:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: Force policy check in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/349131#M301</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155222"&gt;@DKasabji&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;YES, Live Action Terminal, and Script are working perfectly on the targetted endpoint.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem seems only related to Policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll keep you informed as soon as I got some news from the Palo Alto Support investigation.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 14:01:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/349131#M301</guid>
      <dc:creator>MartinCimone</dc:creator>
      <dc:date>2020-09-14T14:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: Force policy check in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/349378#M303</link>
      <description>&lt;P&gt;Isn't a "Perform Heartbeat " under right-click Endpoint Control the way to ask the endpoint to check-in before the 5 minute interval?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While I have not had this issue with 7.1.3 Prevent, the first thing I would check is to ensure there are no blocks on your firewall to ensure there is not some odd communication issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 14:33:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/349378#M303</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-09-15T14:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: Force policy check in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/349445#M309</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Quick feedback on the situation.&amp;nbsp; The issue has been resolved by PaloAlto Support on Sunday evening.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They applied a new Server version on our Tennant and that fixed the issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All good now!&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 17:53:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/force-policy-check-in-cortex-xdr/m-p/349445#M309</guid>
      <dc:creator>MartinCimone</dc:creator>
      <dc:date>2020-09-15T17:53:17Z</dc:date>
    </item>
  </channel>
</rss>

