<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Endpoint Operational Status in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/endpoint-operational-status/m-p/517435#M3004</link>
    <description>&lt;P&gt;Currently, our devices are unprotected state and partially protected state due to disk consumption.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is the data in the cortex xdr incrementive or does it delete itself after sometime ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the possible solution for this issue ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How do we differentiate the disk consumption error is because of disk full in the user's system or is it because the space assigned for the cortex is filled?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Oct 2022 11:31:46 GMT</pubDate>
    <dc:creator>Shashanksinha</dc:creator>
    <dc:date>2022-10-11T11:31:46Z</dc:date>
    <item>
      <title>Endpoint Operational Status</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/endpoint-operational-status/m-p/517435#M3004</link>
      <description>&lt;P&gt;Currently, our devices are unprotected state and partially protected state due to disk consumption.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is the data in the cortex xdr incrementive or does it delete itself after sometime ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the possible solution for this issue ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How do we differentiate the disk consumption error is because of disk full in the user's system or is it because the space assigned for the cortex is filled?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 11:31:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/endpoint-operational-status/m-p/517435#M3004</guid>
      <dc:creator>Shashanksinha</dc:creator>
      <dc:date>2022-10-11T11:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Operational Status</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/endpoint-operational-status/m-p/517719#M3014</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203123"&gt;@Shashanksinha&lt;/a&gt;&amp;nbsp; the XDR data stored in the endpoint is limited to 5GB (default, and configurable in Agent Settings profiles). You can use standard IT Ops tools to monitor disk sizes, or leverage Live Terminal to do the same. When the quota for XDR agent is exhausted, the agent will automatically start removing older data. Enabling Forensics consumes significant storage, so be mindful of allocating more disk space accordingly (around 3-4GB additionally).&amp;nbsp;&lt;BR /&gt;What you should look for is why the space is being filled up, and it could be attributed to being "noisy", i.e., with lots of alerts and incidents being triggered from that endpoint.&amp;nbsp;&lt;BR /&gt;I'd first start off by allocating more disk space to the XDR agent on the affected endpoints to ensure operational stability, and then start investigating the root cause.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 02:25:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/endpoint-operational-status/m-p/517719#M3014</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-10-13T02:25:20Z</dc:date>
    </item>
  </channel>
</rss>

