<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Scan status details of Cortex XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-status-details-of-cortex-xdr/m-p/578788#M6206</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/322192"&gt;@Aneesh&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;As per your requirements, scan status can be checked in multiple ways in Cortex XDR. Following are the methods&amp;nbsp; to do so:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Endpoints Administration:&amp;nbsp;&lt;/STRONG&gt;In the Endpoints Tab, go to&amp;nbsp;&lt;STRONG&gt;All Endpoints&lt;/STRONG&gt;.&amp;nbsp;We have two columns as "&lt;STRONG&gt;Scan status&lt;/STRONG&gt;" and "&lt;STRONG&gt;Last Successful Scan&lt;/STRONG&gt;". These can be used in parallel to map which endpoints had the scanning with result in the columns. Scan status can be described as below:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aspatil_0-1709189181609.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57939i5AB89819CBB86822/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="aspatil_0-1709189181609.png" alt="aspatil_0-1709189181609.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Agent audit logs:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;In the agent audit logs, under the "Sub-Type"&amp;nbsp;column, we can filter our "Scan" and find the status of the endpoints with malware scans with description. You can also set notifications forwarding as per your used cases to emails or syslog servers for this in form of agent logs.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;XQL Search&lt;/STRONG&gt;: You can write your own XQL queries to query the scan status of the endpoints. XQL query also gives you the leverage to create multiple items based on your used cases from generating reports to alerts(eg. generate an alert for endpoints with cancelled scan, or failed scans etc.). A sample XQL query below will list you the list of endpoints with their scan status and last successful scans&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="lia-code-sample  language-cpp"&gt;&lt;CODE&gt;dataset = endpoints 
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;PRE class="lia-code-sample  language-cpp"&gt;&lt;CODE&gt;| fields scan_status , last_successful_scan , endpoint_name , agent_version , last_seen , ip_address , platform , operating_system 
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also schedule the queries or choose to create reports or widgets in your dashboards to be used in XDR dashboards for your auditing and reporting purposes by sorting endpoints counts on basis of scan status etc. as a sample shown below:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aspatil_1-1709189181228.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57940i632C47233FA32D74/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="aspatil_1-1709189181228.png" alt="aspatil_1-1709189181228.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!Please mark this as "Accept as Solution" if it resolves your query&lt;/P&gt;</description>
    <pubDate>Thu, 29 Feb 2024 06:47:02 GMT</pubDate>
    <dc:creator>aspatil</dc:creator>
    <dc:date>2024-02-29T06:47:02Z</dc:date>
    <item>
      <title>Scan status details of Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-status-details-of-cortex-xdr/m-p/578613#M6185</link>
      <description>&lt;P&gt;Hi Team,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can I get more information on scan status for below scenarios.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;. If the scan initiated and before completion the endpoint got disconnected what will be the status?&lt;/P&gt;
&lt;P&gt;.. when the endpoint connects back, whether the scan automatically resume from where it stopped ?&lt;/P&gt;
&lt;P&gt;... Difference between 'Aborted', 'Error' and 'Cancelled' status?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 09:47:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-status-details-of-cortex-xdr/m-p/578613#M6185</guid>
      <dc:creator>Aneesh</dc:creator>
      <dc:date>2024-02-28T09:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: Scan status details of Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-status-details-of-cortex-xdr/m-p/578647#M6194</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/322192"&gt;@Aneesh&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;Below are the answers to your questions.&lt;/P&gt;
&lt;P&gt;1. Once the scan is initiated then it will be in progress status even if the endpoint got disconnected. Scan will be resumed if endpoint connects back within 24 hours.&lt;/P&gt;
&lt;P&gt;2. Scan will resume automatically from where it was interrupted.&lt;/P&gt;
&lt;P&gt;3. Below are the definitions for various action status.&lt;/P&gt;
&lt;UL class="itemizedlist"&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;&lt;SPAN class="guilabel"&gt;&lt;SPAN&gt;&lt;SPAN class="proto-highlight"&gt;Abort&lt;/SPAN&gt;ed&lt;/SPAN&gt;&lt;/SPAN&gt;—Scan was cancelled after it was started.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;&lt;SPAN class="guilabel"&gt;Error&lt;/SPAN&gt;—Scan failed to run. e.g. endpoint got disconnected for more than 24 hours.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;&lt;SPAN class="guilabel"&gt;Canceled&lt;/SPAN&gt;—Scan was canceled before it was started.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;Please click&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;to acknowledge that the answer to your question has been provided.&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL class="itemizedlist"&gt;
&lt;LI class="listitem"&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 13:45:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-status-details-of-cortex-xdr/m-p/578647#M6194</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2024-02-28T13:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: Scan status details of Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-status-details-of-cortex-xdr/m-p/578788#M6206</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/322192"&gt;@Aneesh&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;As per your requirements, scan status can be checked in multiple ways in Cortex XDR. Following are the methods&amp;nbsp; to do so:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Endpoints Administration:&amp;nbsp;&lt;/STRONG&gt;In the Endpoints Tab, go to&amp;nbsp;&lt;STRONG&gt;All Endpoints&lt;/STRONG&gt;.&amp;nbsp;We have two columns as "&lt;STRONG&gt;Scan status&lt;/STRONG&gt;" and "&lt;STRONG&gt;Last Successful Scan&lt;/STRONG&gt;". These can be used in parallel to map which endpoints had the scanning with result in the columns. Scan status can be described as below:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aspatil_0-1709189181609.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57939i5AB89819CBB86822/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="aspatil_0-1709189181609.png" alt="aspatil_0-1709189181609.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Agent audit logs:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;In the agent audit logs, under the "Sub-Type"&amp;nbsp;column, we can filter our "Scan" and find the status of the endpoints with malware scans with description. You can also set notifications forwarding as per your used cases to emails or syslog servers for this in form of agent logs.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;XQL Search&lt;/STRONG&gt;: You can write your own XQL queries to query the scan status of the endpoints. XQL query also gives you the leverage to create multiple items based on your used cases from generating reports to alerts(eg. generate an alert for endpoints with cancelled scan, or failed scans etc.). A sample XQL query below will list you the list of endpoints with their scan status and last successful scans&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="lia-code-sample  language-cpp"&gt;&lt;CODE&gt;dataset = endpoints 
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;PRE class="lia-code-sample  language-cpp"&gt;&lt;CODE&gt;| fields scan_status , last_successful_scan , endpoint_name , agent_version , last_seen , ip_address , platform , operating_system 
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also schedule the queries or choose to create reports or widgets in your dashboards to be used in XDR dashboards for your auditing and reporting purposes by sorting endpoints counts on basis of scan status etc. as a sample shown below:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aspatil_1-1709189181228.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57940i632C47233FA32D74/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="aspatil_1-1709189181228.png" alt="aspatil_1-1709189181228.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!Please mark this as "Accept as Solution" if it resolves your query&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 06:47:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-status-details-of-cortex-xdr/m-p/578788#M6206</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-02-29T06:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: Scan status details of Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-status-details-of-cortex-xdr/m-p/579400#M6261</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/256101"&gt;@nsinghvirk&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the explanation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you said, before completion of a scan if the endpoint got disconnected and failed to connect back within 24 hrs, then the scan status will be in 'error' state.&lt;/P&gt;
&lt;P&gt;In that case&lt;SPAN&gt;&lt;SPAN class="ui-provider ed bdd bde bdf bdg bdh bdi bdj bdk bdl bdm bdn bdo bdp bdq bdr bds bdt bdu bdv bdw bdx bdy bdz bea beb bec bed bee bef beg beh bei bej bek"&gt;&amp;nbsp;can we configure the waiting period for the endpoint to connect back ? if yes how ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, some of the connected endpoints shows aborted scan state in our environment. So, to get some clarity,&lt;/P&gt;
&lt;P&gt;aborted status shows when the scan is cancelled either from user or admin side?&lt;/P&gt;
&lt;P&gt;what if there is no option for the user to cancel it and admin did not cancelled the scan.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;Aneesh&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 06:04:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-status-details-of-cortex-xdr/m-p/579400#M6261</guid>
      <dc:creator>Aneesh</dc:creator>
      <dc:date>2024-03-06T06:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: Scan status details of Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-status-details-of-cortex-xdr/m-p/580765#M6346</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/256101" target="_blank"&gt;@nsinghvirk&lt;/A&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can you help me with the above query?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;Aneesh&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 10:58:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-status-details-of-cortex-xdr/m-p/580765#M6346</guid>
      <dc:creator>Aneesh</dc:creator>
      <dc:date>2024-03-18T10:58:19Z</dc:date>
    </item>
  </channel>
</rss>

