<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR 7.4.1 crashing server in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/423593#M935</link>
    <description>&lt;P&gt;Does anyone have the process on how to downgrade?&lt;/P&gt;</description>
    <pubDate>Fri, 30 Jul 2021 23:05:05 GMT</pubDate>
    <dc:creator>JasonPeterson</dc:creator>
    <dc:date>2021-07-30T23:05:05Z</dc:date>
    <item>
      <title>Cortex XDR 7.4.1 crashing server</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/422411#M920</link>
      <description>&lt;P&gt;After the installation of xdr 7.4.1, our domain controllers began crashing, and even after a reboot they would lock up.&amp;nbsp; Has anyone had any issues with the 7.4.1 release on Windows Server 2012 R2?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on a Windows Dump, Microsoft reported the following:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;findings-&lt;/U&gt;&lt;/STRONG&gt; We have checked high Contention Count threads where we were able to see Palo Alto Networks driver tedrdrv.sys in the stack trace which is getting loaded at the time of issue when hang happened.&lt;/P&gt;&lt;P&gt;Request you to remove it to isolate the issue, and check if the issue is happening or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since then, we have uninstalled 7.4.1 and reinstalled 7.4.0 and the issues went away.&amp;nbsp; I have created a ticket with Palo Alto to investigate MS claim.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have searched the forums and net but have not found any issues related to what we are experiencing.&amp;nbsp; If anyone has had similar issues, please report here.&amp;nbsp; I will keep this updated with new information as it arises.&amp;nbsp; Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;Update 7/30:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo Alto tech support has confirmed other cases involving AD and DC servers where performance is being affected by agent 7.4.1.&amp;nbsp; Since this is a newly found bug, we are currently testing a deployed fix that occurred within the past 30 mins via our data cortex tenant.&amp;nbsp; For those that are having issues, Palo Alto recommends rolling back to the 7.4.0 agent.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Content update 191-66972 is being tested on our data cortex tenant.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will keep you posted on future updates.&amp;nbsp; Thank you.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 30 Jul 2021 19:43:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/422411#M920</guid>
      <dc:creator>Jason_Castillo</dc:creator>
      <dc:date>2021-07-30T19:43:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR 7.4.1 crashing server</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/422563#M921</link>
      <description>&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Definitely a valid case since the issue went away if you remove 7.4.1 and put 7.4.0.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo Alto support should be able to isolate or possibly reproduce the issue.&lt;/P&gt;&lt;P&gt;Do you happen to remember the exact minor version number? 7.4.1.xxxx ?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2021 04:33:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/422563#M921</guid>
      <dc:creator>jcandelaria</dc:creator>
      <dc:date>2021-07-28T04:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR 7.4.1 crashing server</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/423026#M925</link>
      <description>&lt;P&gt;Any updates to this issue? I think we are experiencing something very similar.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2021 13:33:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/423026#M925</guid>
      <dc:creator>wkasak</dc:creator>
      <dc:date>2021-07-29T13:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR 7.4.1 crashing server</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/423036#M926</link>
      <description>&lt;DIV class="m2"&gt;&lt;DIV class="mrg"&gt;&lt;DIV class="client"&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV class="targetTxt"&gt;&lt;DIV class="txtDiv border3d"&gt;I also had a server malfunction with version 7.4.1 I spoke to the support and they told me to install back to version 7.4.0 and at the moment everything is normal.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 29 Jul 2021 13:43:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/423036#M926</guid>
      <dc:creator>Shmuel</dc:creator>
      <dc:date>2021-07-29T13:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR 7.4.1 crashing server</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/423045#M927</link>
      <description>&lt;P&gt;Just put a ticket in with support. They acknowledged the bug causing DCs with the 7.4.1 client to lock up randomly. They are working to resolve. In the meantime, they recommended downgrading to 7.4.0. It is scheduled to be fixed in the 7.4.2 release&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2021 14:59:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/423045#M927</guid>
      <dc:creator>mbahen</dc:creator>
      <dc:date>2021-07-29T14:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR 7.4.1 crashing server</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/423546#M934</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The agent version is&amp;nbsp;7.4.1.31675.&amp;nbsp; They are currently testing our environment and, if successful, will deploy a fix soon.&amp;nbsp; Will keep everyone posted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 19:40:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/423546#M934</guid>
      <dc:creator>Jason_Castillo</dc:creator>
      <dc:date>2021-07-30T19:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR 7.4.1 crashing server</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/423593#M935</link>
      <description>&lt;P&gt;Does anyone have the process on how to downgrade?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 23:05:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/423593#M935</guid>
      <dc:creator>JasonPeterson</dc:creator>
      <dc:date>2021-07-30T23:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR 7.4.1 crashing server</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/423623#M936</link>
      <description>&lt;P&gt;We do the uninstall from the Cortex Admin console then create an .msi package, copy it locally to the server, and install as administrator.&lt;/P&gt;</description>
      <pubDate>Sat, 31 Jul 2021 11:23:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/423623#M936</guid>
      <dc:creator>wkasak</dc:creator>
      <dc:date>2021-07-31T11:23:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR 7.4.1 crashing server</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/423892#M942</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;There are two ways to do the downgrade: 1) from the console, or 2) using Msiexec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The more direct approach is using Msiexec especially dealing with only a few endpoints.&amp;nbsp; Here is the link on how to complete this process:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-4/cortex-xdr-agent-admin/cortex-xdr-agent-for-windows/uninstall-the-cortex-xdr-agent-for-windows.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-4/cortex-xdr-agent-admin/cortex-xdr-agent-for-windows/uninstall-the-cortex-xdr-agent-for-windows.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 14:19:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/423892#M942</guid>
      <dc:creator>Jason_Castillo</dc:creator>
      <dc:date>2021-08-02T14:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR 7.4.1 crashing server</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/423893#M943</link>
      <description>&lt;P&gt;8/2 Update:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thus far no issues have been reported on our DCs on the fix provided by tech support on 7/30.&amp;nbsp; I Will post once the word is official.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For those that are on 7.4.x, Palo Alto recommends downgrading to 7.3 (Although the 7.4.0 agent worked fine for us once we downgraded).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 14:23:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/423893#M943</guid>
      <dc:creator>Jason_Castillo</dc:creator>
      <dc:date>2021-08-02T14:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR 7.4.1 crashing server</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/424567#M947</link>
      <description>&lt;P&gt;Update 8/4/2021:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have closed the ticket with Palo.&amp;nbsp; The fixed worked.&amp;nbsp; They will have it ready in the next release.&amp;nbsp; No ETA when that will occur.&amp;nbsp; Thank you for all your follow-up on this case.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 20:46:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/424567#M947</guid>
      <dc:creator>Jason_Castillo</dc:creator>
      <dc:date>2021-08-04T20:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR 7.4.1 crashing server</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/559325#M5205</link>
      <description>&lt;P&gt;Hi, what is currently stable version of XDR for windows file server?&lt;/P&gt;
&lt;P&gt;I am about to install xdr on several servers (not all at once) and I am about to use new policy and profile (exploit, malware, agent blades) with all default setting. Are there any option that I should change before putting xdr into production environment?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 09:11:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-7-4-1-crashing-server/m-p/559325#M5205</guid>
      <dc:creator>stefan.tomasevic</dc:creator>
      <dc:date>2023-09-25T09:11:55Z</dc:date>
    </item>
  </channel>
</rss>

