<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR Pro - 8.2.0.46438 - Agents Disconnected - service state &amp;quot;stopping&amp;quot; how to monitor that? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-pro-8-2-0-46438-agents-disconnected-service-state/m-p/569691#M5722</link>
    <description>&lt;P&gt;Hi.Same version, e&lt;SPAN&gt;xactly same problems.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Dec 2023 12:45:42 GMT</pubDate>
    <dc:creator>Antanas_Kopas</dc:creator>
    <dc:date>2023-12-13T12:45:42Z</dc:date>
    <item>
      <title>Cortex XDR Pro - 8.2.0.46438 - Agents Disconnected - service state "stopping" how to monitor that?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-pro-8-2-0-46438-agents-disconnected-service-state/m-p/569331#M5698</link>
      <description>&lt;P&gt;Hello dear community,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;today I ran into some issues with the version mentioned above. I know it got hotfixed, but when you cannot install an upgrade and cannot uninstall the agent, I get challanged &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;You need to uninstall it directly after restart, when the service works. The service gives up some minutes after restart.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my scenario the agent&amp;nbsp; 8.2.0.46438 had to be restarted, because the cortex service stuck with status "stopping". A shutdown didn't work. Only a restart fixed the other agents which were "disconnected". However, I need a practical solution for monitoring this, when the cortex service is in a state where the agent is deactivated.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my agent log I can find 26.000 XDR service cyserver was stopped on entries. I think they are also written, when the computer is shut down.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What kind of monitoring (there are also agents which are not inhouse) would you use in my case?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 19:59:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-pro-8-2-0-46438-agents-disconnected-service-state/m-p/569331#M5698</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-12-11T19:59:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Pro - 8.2.0.46438 - Agents Disconnected - service state "stopping" how to monitor that?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-pro-8-2-0-46438-agents-disconnected-service-state/m-p/569347#M5699</link>
      <description>&lt;P&gt;So one step closer to the edge.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On some servers I am not able to uninstall the agent. It fails, because the cortex xdr agent service wants to be stopped, but it hangs in the stopping status.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone facing this problems too?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 22:34:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-pro-8-2-0-46438-agents-disconnected-service-state/m-p/569347#M5699</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-12-11T22:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Pro - 8.2.0.46438 - Agents Disconnected - service state "stopping" how to monitor that?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-pro-8-2-0-46438-agents-disconnected-service-state/m-p/569691#M5722</link>
      <description>&lt;P&gt;Hi.Same version, e&lt;SPAN&gt;xactly same problems.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 12:45:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-pro-8-2-0-46438-agents-disconnected-service-state/m-p/569691#M5722</guid>
      <dc:creator>Antanas_Kopas</dc:creator>
      <dc:date>2023-12-13T12:45:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Pro - 8.2.0.46438 - Agents Disconnected - service state "stopping" how to monitor that?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-pro-8-2-0-46438-agents-disconnected-service-state/m-p/569931#M5740</link>
      <description>&lt;P&gt;If you don't control the connected or disconnected status, you maybe get troubles.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This little guys helped us:&lt;/P&gt;
&lt;P&gt;XQL for checking the disconnected status in list format:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;config case_sensitive = false&lt;BR /&gt;|dataset = endpoints&lt;BR /&gt;| filter endpoint_type = ENUM.TYPE_SERVER and endpoint_status = ENUM.DISCONNECTED &lt;BR /&gt;| filter last_seen != null&lt;BR /&gt;| alter ct = current_time()&lt;BR /&gt;| alter diff_in_hours = timestamp_diff(ct, last_seen, "HOUR") &lt;BR /&gt;| alter diff_in_days = timestamp_diff(ct, last_seen, "DAY") &lt;BR /&gt;| filter diff_in_hours &amp;gt;0 &lt;BR /&gt;| fields endpoint_name, domain , ip_address , mac_address ,last_seen, diff_in_hours, diff_in_days &lt;BR /&gt;| sort desc diff_in_hours&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ping with exported list from the result (Hostnames) above.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;$complist = Get-Content "C:\temp\ip.txt"&lt;/P&gt;
&lt;P&gt;foreach($comp in $complist){&lt;BR /&gt;&lt;BR /&gt;$pingtest = Test-Connection -ComputerName $comp -Quiet -Count 1 -ErrorAction SilentlyContinue&lt;/P&gt;
&lt;P&gt;if($pingtest){&lt;/P&gt;
&lt;P&gt;Write-Host($comp + " is online")&lt;BR /&gt;}&lt;BR /&gt;else{&lt;BR /&gt;Write-Host($comp + " is not reachable")&lt;BR /&gt;}&lt;BR /&gt;&lt;BR /&gt;}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I bet there is a possibility to do this automaticly through api etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2023 17:14:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-pro-8-2-0-46438-agents-disconnected-service-state/m-p/569931#M5740</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-12-14T17:14:28Z</dc:date>
    </item>
  </channel>
</rss>

