<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TELAM SERVICES IS STOPPED - CORTEX XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/telam-services-is-stopped-cortex-xdr/m-p/1244790#M8944</link>
    <description>&lt;P data-path-to-node="12,0"&gt;Hi everyone,&lt;/P&gt;
&lt;P data-path-to-node="12,1"&gt;I am looking for in-depth technical details regarding the &lt;STRONG data-path-to-node="12,1" data-index-in-node="58"&gt;&lt;CODE data-path-to-node="12,1" data-index-in-node="58"&gt;telam&lt;/CODE&gt;&lt;/STRONG&gt; service within the Cortex XDR agent architecture.&lt;/P&gt;
&lt;P data-path-to-node="12,2"&gt;I've observed that this service handles the local machine learning analysis for executables, but I often see it in a "Stopped" state during runtime queries. Could anyone clarify:&lt;/P&gt;
&lt;UL data-path-to-node="12,3"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="12,3,0,0"&gt;&lt;STRONG data-path-to-node="12,3,0,0" data-index-in-node="0"&gt;Role &amp;amp; Impact:&lt;/STRONG&gt; What exactly happens at the kernel/user level when &lt;CODE data-path-to-node="12,3,0,0" data-index-in-node="66"&gt;telam&lt;/CODE&gt; is active versus stopped?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="12,3,1,0"&gt;&lt;STRONG data-path-to-node="12,3,1,0" data-index-in-node="0"&gt;Resource Usage:&lt;/STRONG&gt; How does it manage resources during the analysis of unknown files?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="12,3,2,0"&gt;&lt;STRONG data-path-to-node="12,3,2,0" data-index-in-node="0"&gt;Troubleshooting:&lt;/STRONG&gt; If the service is stopped unexpectedly, what are the standard logs or indicators we should look for (besides &lt;CODE data-path-to-node="12,3,2,0" data-index-in-node="126"&gt;cytool&lt;/CODE&gt;)?&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-path-to-node="12,4"&gt;I am trying to build a better troubleshooting guide for my team, so any "under the hood" details would be very helpful.&lt;/P&gt;</description>
    <pubDate>Fri, 02 Jan 2026 20:55:11 GMT</pubDate>
    <dc:creator>J.Gammara</dc:creator>
    <dc:date>2026-01-02T20:55:11Z</dc:date>
    <item>
      <title>TELAM SERVICES IS STOPPED - CORTEX XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/telam-services-is-stopped-cortex-xdr/m-p/1244790#M8944</link>
      <description>&lt;P data-path-to-node="12,0"&gt;Hi everyone,&lt;/P&gt;
&lt;P data-path-to-node="12,1"&gt;I am looking for in-depth technical details regarding the &lt;STRONG data-path-to-node="12,1" data-index-in-node="58"&gt;&lt;CODE data-path-to-node="12,1" data-index-in-node="58"&gt;telam&lt;/CODE&gt;&lt;/STRONG&gt; service within the Cortex XDR agent architecture.&lt;/P&gt;
&lt;P data-path-to-node="12,2"&gt;I've observed that this service handles the local machine learning analysis for executables, but I often see it in a "Stopped" state during runtime queries. Could anyone clarify:&lt;/P&gt;
&lt;UL data-path-to-node="12,3"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="12,3,0,0"&gt;&lt;STRONG data-path-to-node="12,3,0,0" data-index-in-node="0"&gt;Role &amp;amp; Impact:&lt;/STRONG&gt; What exactly happens at the kernel/user level when &lt;CODE data-path-to-node="12,3,0,0" data-index-in-node="66"&gt;telam&lt;/CODE&gt; is active versus stopped?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="12,3,1,0"&gt;&lt;STRONG data-path-to-node="12,3,1,0" data-index-in-node="0"&gt;Resource Usage:&lt;/STRONG&gt; How does it manage resources during the analysis of unknown files?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="12,3,2,0"&gt;&lt;STRONG data-path-to-node="12,3,2,0" data-index-in-node="0"&gt;Troubleshooting:&lt;/STRONG&gt; If the service is stopped unexpectedly, what are the standard logs or indicators we should look for (besides &lt;CODE data-path-to-node="12,3,2,0" data-index-in-node="126"&gt;cytool&lt;/CODE&gt;)?&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-path-to-node="12,4"&gt;I am trying to build a better troubleshooting guide for my team, so any "under the hood" details would be very helpful.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jan 2026 20:55:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/telam-services-is-stopped-cortex-xdr/m-p/1244790#M8944</guid>
      <dc:creator>J.Gammara</dc:creator>
      <dc:date>2026-01-02T20:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: TELAM SERVICES IS STOPPED - CORTEX XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/telam-services-is-stopped-cortex-xdr/m-p/1244955#M8948</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Telam service is boot time module which runs only during boot time.It protects against attack happening at boot level.As a result it is not meant to run during OS runtime.Hence It is showing stopped.&lt;/P&gt;
&lt;P class="p1"&gt;Please mark the solution as accepted ,if it helps.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jan 2026 11:49:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/telam-services-is-stopped-cortex-xdr/m-p/1244955#M8948</guid>
      <dc:creator>ssingh32</dc:creator>
      <dc:date>2026-01-06T11:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: TELAM SERVICES IS STOPPED - CORTEX XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/telam-services-is-stopped-cortex-xdr/m-p/1244974#M8954</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1561359921"&gt;@J.Gammara&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="141" data-end="531"&gt;&lt;STRONG data-start="141" data-end="327"&gt;Technical analysis of the telam service (specifically the &lt;CODE data-start="201" data-end="212"&gt;telam.sys&lt;/CODE&gt; driver) indicates that its behavior and role differ from observations regarding local machine learning analysis.&lt;/STRONG&gt; In the Cortex XDR architecture, local machine learning analysis is typically handled by other modules, such as the &lt;STRONG data-start="443" data-end="497"&gt;Local Analysis Worker (&lt;CODE data-start="468" data-end="483"&gt;tlaworker.exe&lt;/CODE&gt;) on Windows&lt;/STRONG&gt; or the &lt;STRONG data-start="505" data-end="530"&gt;CLAD service on Linux&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H4 data-start="533" data-end="550"&gt;Role &amp;amp; Impact&lt;/H4&gt;
&lt;P data-start="552" data-end="685"&gt;The &lt;STRONG data-start="556" data-end="573"&gt;telam service&lt;/STRONG&gt; is a core system driver designed to comply with &lt;STRONG data-start="622" data-end="670"&gt;Microsoft’s Early Launch Anti-Malware (ELAM)&lt;/STRONG&gt; specification.&lt;/P&gt;
&lt;P data-start="687" data-end="831"&gt;&lt;STRONG data-start="687" data-end="717"&gt;When Active (During Boot):&lt;/STRONG&gt;&lt;BR data-start="717" data-end="720" /&gt;The driver loads very early in the boot process, even before disk drivers. Its primary responsibilities are to:&lt;/P&gt;
&lt;UL data-start="832" data-end="1153"&gt;
&lt;LI data-start="832" data-end="938"&gt;
&lt;P data-start="834" data-end="938"&gt;Register the Cortex XDR agent as a trusted security product with the &lt;STRONG data-start="903" data-end="936"&gt;Windows Security Center (WSC)&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="939" data-end="1111"&gt;
&lt;P data-start="941" data-end="1111"&gt;Host the certificates and signatures required for the agent’s user-mode services (such as &lt;CODE data-start="1031" data-end="1045"&gt;CyServer.exe&lt;/CODE&gt;) to run as an &lt;STRONG data-start="1060" data-end="1109"&gt;Anti-Malware Protected Process Light (AM-PPL)&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1112" data-end="1153"&gt;
&lt;P data-start="1114" data-end="1153"&gt;Initialize agent tampering protection&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="1155" data-end="1429"&gt;&lt;STRONG data-start="1155" data-end="1182"&gt;When Stopped (Runtime):&lt;/STRONG&gt;&lt;BR data-start="1182" data-end="1185" /&gt;Once these boot-time registration and self-protection initialization tasks are complete, the &lt;STRONG data-start="1278" data-end="1310"&gt;telam driver stops by design&lt;/STRONG&gt;. Observing it in a &lt;EM data-start="1330" data-end="1339"&gt;Stopped&lt;/EM&gt; state during runtime checks is expected behavior and does &lt;STRONG data-start="1398" data-end="1405"&gt;not&lt;/STRONG&gt; indicate a malfunction.&lt;/P&gt;
&lt;H3 data-start="1431" data-end="1449"&gt;Resource Usage&lt;/H3&gt;
&lt;P data-start="1451" data-end="1617"&gt;The &lt;STRONG data-start="1455" data-end="1471"&gt;telam driver&lt;/STRONG&gt; itself is a minimal driver that primarily serves as a container for certificates and does not actively manage resources or perform file analysis.&lt;/P&gt;
&lt;P data-start="1619" data-end="1936"&gt;Resource consumption during the analysis of unknown files is handled by the &lt;STRONG data-start="1695" data-end="1724"&gt;Local Analysis components&lt;/STRONG&gt;. For example, while the telam driver is stopped, the &lt;STRONG data-start="1778" data-end="1803"&gt;Local Analysis Worker&lt;/STRONG&gt; may consume between &lt;STRONG data-start="1824" data-end="1853"&gt;500 MB and 1000 MB of RAM&lt;/STRONG&gt; during analysis operations, which is considered normal behavior on active servers.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;For in-depth analysis of "Unexpected Stops" of the&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;main&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;services (which might be what your team actually needs to troubleshoot), you should look for "Memory allocation failed" or "Out of memory" errors in&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;trapsd.log.&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Happy New year!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jan 2026 15:18:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/telam-services-is-stopped-cortex-xdr/m-p/1244974#M8954</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-01-06T15:18:11Z</dc:date>
    </item>
  </channel>
</rss>

