<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Malware Scan on XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-on-xdr/m-p/528384#M3459</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206335"&gt;@RamyashreeMada&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;1. In the instance the connection is lost between the Endpoint and XDR cloud, but the scan had already started the scan should be completed and report the status back online if it happens within 24 hours.&lt;BR /&gt;2. In the instance the machine was shut down halfway through the scan the scan should indeed be cancelled/failed. This information should arrive to the XDR console in around 5-7 seven minutes, as the t&lt;SPAN&gt;he Cortex XDR agent initiates communication with&amp;nbsp;&lt;SPAN class=""&gt;Cortex XDR&lt;SPAN&gt;&amp;nbsp;every five minutes by sending a heartbeat to the server.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can read more about Agent and Server initiated communication&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Communication" target="_self"&gt;here.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If this helped, please click 'Accept as Solution'.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jan 2023 17:40:43 GMT</pubDate>
    <dc:creator>mavraham</dc:creator>
    <dc:date>2023-01-24T17:40:43Z</dc:date>
    <item>
      <title>Malware Scan on XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-on-xdr/m-p/527704#M3423</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How long does it take for endpoints to go to failed/canceled state from in progress state when malware scan ran on endpoints?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 13:06:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-on-xdr/m-p/527704#M3423</guid>
      <dc:creator>RamyashreeMada</dc:creator>
      <dc:date>2023-01-19T13:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: Malware Scan on XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-on-xdr/m-p/528104#M3437</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206335"&gt;@RamyashreeMada&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;Thank you for writing to Live Community. I'm not sure I fully understand your question.&lt;BR /&gt;&lt;BR /&gt;Do you mean how long it will take the endpoint to go failed/cancelled in case the endpoint was disconnected or something interrupted the scan?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 00:08:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-on-xdr/m-p/528104#M3437</guid>
      <dc:creator>mavraham</dc:creator>
      <dc:date>2023-01-23T00:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: Malware Scan on XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-on-xdr/m-p/528116#M3438</link>
      <description>&lt;P&gt;Yes, That's what I mean.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 04:46:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-on-xdr/m-p/528116#M3438</guid>
      <dc:creator>RamyashreeMada</dc:creator>
      <dc:date>2023-01-23T04:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: Malware Scan on XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-on-xdr/m-p/528384#M3459</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206335"&gt;@RamyashreeMada&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;1. In the instance the connection is lost between the Endpoint and XDR cloud, but the scan had already started the scan should be completed and report the status back online if it happens within 24 hours.&lt;BR /&gt;2. In the instance the machine was shut down halfway through the scan the scan should indeed be cancelled/failed. This information should arrive to the XDR console in around 5-7 seven minutes, as the t&lt;SPAN&gt;he Cortex XDR agent initiates communication with&amp;nbsp;&lt;SPAN class=""&gt;Cortex XDR&lt;SPAN&gt;&amp;nbsp;every five minutes by sending a heartbeat to the server.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can read more about Agent and Server initiated communication&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Communication" target="_self"&gt;here.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If this helped, please click 'Accept as Solution'.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 17:40:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-on-xdr/m-p/528384#M3459</guid>
      <dc:creator>mavraham</dc:creator>
      <dc:date>2023-01-24T17:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: Malware Scan on XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-on-xdr/m-p/536340#M3930</link>
      <description>&lt;P&gt;After how long it should get cancelled or failed if system scan is in progress and system is also connected to console.&lt;/P&gt;
&lt;P&gt;I mean what is the timeout period for Cortex XDR to cancel or fail the scan progress. I have seen few agents it keeps on scanning for more than 2-3 days .&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 15:06:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-on-xdr/m-p/536340#M3930</guid>
      <dc:creator>TejasPatil</dc:creator>
      <dc:date>2023-03-24T15:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: Malware Scan on XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-on-xdr/m-p/536346#M3933</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/274255"&gt;@TejasPatil&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are experiencing scanning that is taking 2-3 days to complete please submit this information in a case to our &lt;A href="https://support.paloaltonetworks.com/Support/Index" target="_self"&gt;support center&lt;/A&gt;.&amp;nbsp; The amount of time it takes to perform a scan is dependant on several factors not limited to endpoint hardware.&amp;nbsp; In any case 2-3 days seems extremely excessive and support will be able to look into the issue deeper to ensure there are no underlying issues we're unaware of.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In reference to the question of timeout period, I don't' believe there is a timeout period for the scan.&amp;nbsp; Once the command has been sent, unless a disconnection is made the scan will commence and run until complete.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope you find this information helpful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a great day!&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 17:01:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-on-xdr/m-p/536346#M3933</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2023-03-24T17:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: Malware Scan on XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-on-xdr/m-p/536364#M3934</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206335"&gt;@RamyashreeMada&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I just wanted to a supply a quick information update.&amp;nbsp; You asked earlier about how long it would take a scan to time out.&amp;nbsp; I was unaware of the time out, but can now confirm that the scan command should timeout after 24 hours.&amp;nbsp; This amount of time can be changed with a Support Exception, but would require having a ticket in with our &lt;A href="https://support.paloaltonetworks.com/Support/Index" target="_self"&gt;support team&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 17:33:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-on-xdr/m-p/536364#M3934</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2023-03-24T17:33:40Z</dc:date>
    </item>
  </channel>
</rss>

