<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Devices that are down cortex XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/devices-that-are-down-cortex-xdr/m-p/423132#M930</link>
    <description>&lt;P&gt;This is a little bit tricky, since the agent is disconnected for a long time probably more than 180 or either some issue with agent itself that cause it to be disconnected to the tenant. Once its past 180 days, the endpoint is gone on from the table.&lt;/P&gt;&lt;P&gt;I believe your issue might be that most of these endpoints have older-older &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; version possibly 7.1&lt;/P&gt;&lt;P&gt;A possible workaround is looking at agent audit logs then filter Sub-Type = Stop, then from there you can filter XDR Agent Version Contains contains 7.1 . That will give you the list of the agents to start with. Then you can compare the list with connected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other option is to use a tool like sccm to check the protection status of the agent. You can submit a support case on this and ask for the registry that you can use.&lt;/P&gt;</description>
    <pubDate>Thu, 29 Jul 2021 16:57:42 GMT</pubDate>
    <dc:creator>jcandelaria</dc:creator>
    <dc:date>2021-07-29T16:57:42Z</dc:date>
    <item>
      <title>Devices that are down cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/devices-that-are-down-cortex-xdr/m-p/423015#M924</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="m2"&gt;&lt;DIV class="mrg"&gt;&lt;DIV class="client"&gt;&lt;DIV class="targetTxt"&gt;&lt;DIV class="txtDiv border3d"&gt;Hi,&lt;DIV class="m2"&gt;&lt;DIV class="mrg"&gt;&lt;DIV class="client"&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV class="targetTxt"&gt;&lt;DIV class="txtDiv border3d"&gt;&lt;DIV class="m2"&gt;&lt;DIV class="mrg"&gt;&lt;DIV class="client"&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV class="targetTxt"&gt;&lt;DIV class="txtDiv border3d"&gt;I have devices that are down, how can I find them? In the interface, I only see the devices in status connected or disconnected&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="txtDiv border3d"&gt;&lt;DIV class="m2"&gt;&lt;DIV class="mrg"&gt;&lt;DIV class="client"&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV class="targetTxt"&gt;&lt;DIV class="txtDiv border3d"&gt;Thanks.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 29 Jul 2021 13:48:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/devices-that-are-down-cortex-xdr/m-p/423015#M924</guid>
      <dc:creator>Shmuel</dc:creator>
      <dc:date>2021-07-29T13:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: Devices that are down cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/devices-that-are-down-cortex-xdr/m-p/423065#M928</link>
      <description>&lt;P&gt;Hi Shmuel,&lt;/P&gt;&lt;P&gt;Not sure what you mean by down?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We will show the xdr agent status as below.&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;&lt;DIV&gt;Connected&lt;/DIV&gt;—The Cortex XDR agent has checked in within 10 minutes for standard endpoints, and within 3 hours for mobile endpoints.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;&lt;DIV&gt;Connection Lost&lt;/DIV&gt;—The Cortex XDR agent has not checked in within 30 to 180 days for standard endpoints, and between 90 minutes and 6 hours for VDI and temporary sessions.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;&lt;DIV&gt;Disconnected&lt;/DIV&gt;—The Cortex XDR agent has checked in within the defined inactivity window: between 10 minutes and 30 days for standard and mobile endpoints, and between 10 minutes and 90 minutes for VDI and temporary sessions.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-response/investigate-endpoints/view-details-for-an-endpoint" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-response/investigate-endpoints/view-details-for-an-endpoint&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can also create a filter from endpoint administration using Last Seen. ex. screenshot below with endpoint status disconnected and last seen 7 Days&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jcandelaria_0-1627572518328.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35317i9046BC2B5F6CC370/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jcandelaria_0-1627572518328.png" alt="jcandelaria_0-1627572518328.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2021 15:29:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/devices-that-are-down-cortex-xdr/m-p/423065#M928</guid>
      <dc:creator>jcandelaria</dc:creator>
      <dc:date>2021-07-29T15:29:22Z</dc:date>
    </item>
    <item>
      <title>Re: Devices that are down cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/devices-that-are-down-cortex-xdr/m-p/423089#M929</link>
      <description>&lt;DIV class="m2"&gt;&lt;DIV class="mrg"&gt;&lt;DIV class="client"&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV class="targetTxt"&gt;&lt;DIV class="txtDiv border3d"&gt;Hi&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/39296" target="_self"&gt;&lt;SPAN class=""&gt;Jcandelaria&lt;/SPAN&gt;&lt;/A&gt;&lt;/DIV&gt;&lt;DIV class="txtDiv border3d"&gt;I'll explain. I have a user's computer that has Traps in place but is disabled.&amp;nbsp; I am looking for a computer name in an administrative interface I do not see the computer. That's why I want to scan my network and find stations that don't communicate with the server&lt;/DIV&gt;&lt;DIV class="txtDiv border3d"&gt;&lt;DIV class="m2"&gt;&lt;DIV class="mrg"&gt;&lt;DIV class="client"&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV class="targetTxt"&gt;&lt;DIV class="txtDiv border3d"&gt;I'm uploading, you a screenshot.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="txtDiv border3d"&gt;&amp;nbsp;Thank you.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 29 Jul 2021 16:08:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/devices-that-are-down-cortex-xdr/m-p/423089#M929</guid>
      <dc:creator>Shmuel</dc:creator>
      <dc:date>2021-07-29T16:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: Devices that are down cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/devices-that-are-down-cortex-xdr/m-p/423132#M930</link>
      <description>&lt;P&gt;This is a little bit tricky, since the agent is disconnected for a long time probably more than 180 or either some issue with agent itself that cause it to be disconnected to the tenant. Once its past 180 days, the endpoint is gone on from the table.&lt;/P&gt;&lt;P&gt;I believe your issue might be that most of these endpoints have older-older &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; version possibly 7.1&lt;/P&gt;&lt;P&gt;A possible workaround is looking at agent audit logs then filter Sub-Type = Stop, then from there you can filter XDR Agent Version Contains contains 7.1 . That will give you the list of the agents to start with. Then you can compare the list with connected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other option is to use a tool like sccm to check the protection status of the agent. You can submit a support case on this and ask for the registry that you can use.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2021 16:57:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/devices-that-are-down-cortex-xdr/m-p/423132#M930</guid>
      <dc:creator>jcandelaria</dc:creator>
      <dc:date>2021-07-29T16:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: Devices that are down cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/devices-that-are-down-cortex-xdr/m-p/423188#M932</link>
      <description>Thank you&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 29 Jul 2021 18:24:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/devices-that-are-down-cortex-xdr/m-p/423188#M932</guid>
      <dc:creator>Shmuel</dc:creator>
      <dc:date>2021-07-29T18:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: Devices that are down cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/devices-that-are-down-cortex-xdr/m-p/423675#M938</link>
      <description>&lt;DIV class="m2"&gt;&lt;DIV class="mrg"&gt;&lt;DIV class="client"&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV class="targetTxt"&gt;&lt;DIV class="txtDiv border3d"&gt;Hello everyone&lt;/DIV&gt;&lt;DIV class="txtDiv border3d"&gt;I'm updating that after a conversation with support at the moment there is no way to find devices that are not on a management panel and are in the status&amp;nbsp;&lt;SPAN&gt;disabled.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="txtDiv border3d"&gt;Thank you&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 01 Aug 2021 17:14:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/devices-that-are-down-cortex-xdr/m-p/423675#M938</guid>
      <dc:creator>Shmuel</dc:creator>
      <dc:date>2021-08-01T17:14:10Z</dc:date>
    </item>
  </channel>
</rss>

