<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File server, backup server and storage server profiles in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-server-backup-server-and-storage-server-profiles/m-p/404808#M709</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/170102"&gt;@MCereda&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are about to activate Cortex XDR agent with Default Policy Rules (i.e. Default Exploit, Malware, Restrictions, Agent settings and Exceptions profiles) on some Windows servers which contain a huge amount of data (terabytes).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there some recommended best practices to follow or some functionalities that should be disabled in order to avoid any kind of impact on these kind of servers in terms of performances?&lt;/P&gt;&lt;P&gt;For example, we were told that "File Search and Destroy" feature could cause a huge overhead for some time after the agent has been activated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Furthermore, can anyone provide an estimate of how long a Cortex XDR malware scan on 1 TB of data might take?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/170102"&gt;@MCereda&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;As I understand it, you're planning to deploy the Cortex XDR to a Windows server that houses a considerable amount of data. There are some considerations to make:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Install the Cortex XDR agent during a maintenance window.&lt;/LI&gt;&lt;LI&gt;After the installation, prepare for an immediate malware scan to follow.&lt;/LI&gt;&lt;LI&gt;Schedule scans during off-periods when the server will not be in use &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-profiles/add-malware-security-profile.html#id17AHD0R70XX" target="_blank"&gt;as described here&lt;/A&gt;.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; Subsequent scans will be faster as the agent will not rescan unmodified files.&lt;BR /&gt;&lt;BR /&gt;As for the amount of time that a scan could take, this is variable depending upon the system resources available and the size of the file, so there's no way to provide an estimate at this time. Predicting an estimated amount to scan a target fully would be an excellent feature, which should be submitted as a feature request for future consideration.&lt;BR /&gt;&lt;BR /&gt;Finally, Search and Destroy performs a hash match in the cloud for all devices noted to have a file with that hash on the endpoint (Search). Then it sends a delete job to remove the target file from the filesystem on the target endpoint (Destroy). There's no major resource utilization expected on the endpoint during this process, as the endpoint will only be tasked with deleting the target file if it exists.&lt;/P&gt;</description>
    <pubDate>Tue, 04 May 2021 18:55:04 GMT</pubDate>
    <dc:creator>gjenkins</dc:creator>
    <dc:date>2021-05-04T18:55:04Z</dc:date>
    <item>
      <title>File server, backup server and storage server profiles</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-server-backup-server-and-storage-server-profiles/m-p/403045#M699</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are about to activate Cortex XDR agent with Default Policy Rules (i.e. Default Exploit, Malware, Restrictions, Agent settings and Exceptions profiles) on some Windows servers which contain a huge amount of data (terabytes).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there some recommended best practices to follow or some functionalities that should be disabled in order to avoid any kind of impact on these kind of servers in terms of performances?&lt;/P&gt;&lt;P&gt;For example, we were told that "File Search and Destroy" feature could cause a huge overhead for some time after the agent has been activated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Furthermore, can anyone provide an estimate of how long a Cortex XDR malware scan on 1 TB of data might take?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 14:53:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-server-backup-server-and-storage-server-profiles/m-p/403045#M699</guid>
      <dc:creator>MCereda</dc:creator>
      <dc:date>2021-04-28T14:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: File server, backup server and storage server profiles</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-server-backup-server-and-storage-server-profiles/m-p/404808#M709</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/170102"&gt;@MCereda&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are about to activate Cortex XDR agent with Default Policy Rules (i.e. Default Exploit, Malware, Restrictions, Agent settings and Exceptions profiles) on some Windows servers which contain a huge amount of data (terabytes).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there some recommended best practices to follow or some functionalities that should be disabled in order to avoid any kind of impact on these kind of servers in terms of performances?&lt;/P&gt;&lt;P&gt;For example, we were told that "File Search and Destroy" feature could cause a huge overhead for some time after the agent has been activated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Furthermore, can anyone provide an estimate of how long a Cortex XDR malware scan on 1 TB of data might take?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/170102"&gt;@MCereda&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;As I understand it, you're planning to deploy the Cortex XDR to a Windows server that houses a considerable amount of data. There are some considerations to make:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Install the Cortex XDR agent during a maintenance window.&lt;/LI&gt;&lt;LI&gt;After the installation, prepare for an immediate malware scan to follow.&lt;/LI&gt;&lt;LI&gt;Schedule scans during off-periods when the server will not be in use &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-profiles/add-malware-security-profile.html#id17AHD0R70XX" target="_blank"&gt;as described here&lt;/A&gt;.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; Subsequent scans will be faster as the agent will not rescan unmodified files.&lt;BR /&gt;&lt;BR /&gt;As for the amount of time that a scan could take, this is variable depending upon the system resources available and the size of the file, so there's no way to provide an estimate at this time. Predicting an estimated amount to scan a target fully would be an excellent feature, which should be submitted as a feature request for future consideration.&lt;BR /&gt;&lt;BR /&gt;Finally, Search and Destroy performs a hash match in the cloud for all devices noted to have a file with that hash on the endpoint (Search). Then it sends a delete job to remove the target file from the filesystem on the target endpoint (Destroy). There's no major resource utilization expected on the endpoint during this process, as the endpoint will only be tasked with deleting the target file if it exists.&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 18:55:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-server-backup-server-and-storage-server-profiles/m-p/404808#M709</guid>
      <dc:creator>gjenkins</dc:creator>
      <dc:date>2021-05-04T18:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: File server, backup server and storage server profiles</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-server-backup-server-and-storage-server-profiles/m-p/405997#M729</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/170102"&gt;@MCereda&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If those are production servers I will suggest deploying the agents with a profile configured to 'Report' instead of Block, give it a week to collect alerts and activities from those servers, and monitor the triggered alerts on the hosts. in case you are seeing FP's perform the appropriate exclusions and once you feel comfortable with moving to 'Block' mode please do so.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 09:57:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-server-backup-server-and-storage-server-profiles/m-p/405997#M729</guid>
      <dc:creator>mabutbul</dc:creator>
      <dc:date>2021-05-11T09:57:46Z</dc:date>
    </item>
  </channel>
</rss>

