<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to check endpoint has no agent  and intregate edl with NGFW in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-check-endpoint-has-no-agent-and-intregate-edl-with-ngfw/m-p/524438#M3270</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/261687"&gt;@Pattarachai-FTH&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Having no agent is one part of the problem and integrate EDL with NGFW is another set. These are not related. Can you help us with more specific used case on the same.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your asset management tools can be used for checking applications installed, however, you can also do so using Cortex XDR by using Broker VM network mapper as&amp;nbsp; a tool and aggregating DHCP logs for asset discovery. Cortex XDR Network mapper will scan the subnet to discover IPs and will populate entries for endpoints with agent installed as "YES". The DHCP logs ingestion will help you get appropriate MAC addresses for devices with IPs that do not have cortex agent installed on them. Some of them might be ICND devices where you cannot install agents, but remaining can be leveraged to check if those do not have agents and can be pushed for installation.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Waiting to hear from you on your EDL perspective. Please mark this "Accept as Solution" if it answers your question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Mon, 19 Dec 2022 01:45:30 GMT</pubDate>
    <dc:creator>neelrohit</dc:creator>
    <dc:date>2022-12-19T01:45:30Z</dc:date>
    <item>
      <title>How to check endpoint has no agent  and intregate edl with NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-check-endpoint-has-no-agent-and-intregate-edl-with-ngfw/m-p/524328#M3266</link>
      <description>&lt;P&gt;Hi Expert ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How to check endpoint has no agent and integrate edl with NGFW when found endpoint&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now , I have try to create&amp;nbsp; python script&amp;nbsp; to get all endpoint&amp;nbsp; but not have idea to check endpoint has no agent&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 04:01:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-check-endpoint-has-no-agent-and-intregate-edl-with-ngfw/m-p/524328#M3266</guid>
      <dc:creator>Pattarachai-FTH</dc:creator>
      <dc:date>2022-12-16T04:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to check endpoint has no agent  and intregate edl with NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-check-endpoint-has-no-agent-and-intregate-edl-with-ngfw/m-p/524438#M3270</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/261687"&gt;@Pattarachai-FTH&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Having no agent is one part of the problem and integrate EDL with NGFW is another set. These are not related. Can you help us with more specific used case on the same.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your asset management tools can be used for checking applications installed, however, you can also do so using Cortex XDR by using Broker VM network mapper as&amp;nbsp; a tool and aggregating DHCP logs for asset discovery. Cortex XDR Network mapper will scan the subnet to discover IPs and will populate entries for endpoints with agent installed as "YES". The DHCP logs ingestion will help you get appropriate MAC addresses for devices with IPs that do not have cortex agent installed on them. Some of them might be ICND devices where you cannot install agents, but remaining can be leveraged to check if those do not have agents and can be pushed for installation.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Waiting to hear from you on your EDL perspective. Please mark this "Accept as Solution" if it answers your question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 01:45:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-check-endpoint-has-no-agent-and-intregate-edl-with-ngfw/m-p/524438#M3270</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2022-12-19T01:45:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to check endpoint has no agent  and intregate edl with NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-check-endpoint-has-no-agent-and-intregate-edl-with-ngfw/m-p/524444#M3271</link>
      <description>&lt;P&gt;If you have an asset management tool like SCCM, I would recommend creating a Powershell script (or whatever scripting language you prefer) to run the command and parse the response to ensure it matches the current day. This will accomplish two checks, one being that the agent is installed (if the command fails due to cytool not existing the agent is not installed) and that it's healthy and connecting by validating its connected to the console that day. You'll sometimes run into agents where the service is running, but for one reason or another it's not communicating successful, so this will validate that.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 03:24:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-check-endpoint-has-no-agent-and-intregate-edl-with-ngfw/m-p/524444#M3271</guid>
      <dc:creator>ZachIvins</dc:creator>
      <dc:date>2022-12-19T03:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to check endpoint has no agent  and intregate edl with NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-check-endpoint-has-no-agent-and-intregate-edl-with-ngfw/m-p/524445#M3272</link>
      <description>&lt;P&gt;Sorry I forgot to include the actual command, it's "cytool last_checkin" - see&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide/Cytool-for-Windows" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide/Cytool-for-Windows&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 03:25:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-check-endpoint-has-no-agent-and-intregate-edl-with-ngfw/m-p/524445#M3272</guid>
      <dc:creator>ZachIvins</dc:creator>
      <dc:date>2022-12-19T03:25:48Z</dc:date>
    </item>
  </channel>
</rss>

