<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Cortex XDR Customer Success Webinar: Endpoint Administration Part 2 in Cortex XDR Videos</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-videos/cortex-xdr-customer-success-webinar-endpoint-administration-part/ta-p/515809</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;H2&gt;Endpoint Administration Part 2&lt;/H2&gt;
&lt;P&gt;Missed Endpoint Administration Part 1? Click &lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-webinars/cortex-xdr-customer-success-webinar-endpoint-administration/ta-p/513051" target="_blank" rel="noopener"&gt;HERE&lt;/A&gt; to watch&lt;/P&gt;
&lt;P&gt;This webinar covers the Cortex XDR agent-related administration task, including agent architecture, Linux agent, and demos.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;div class="video-embed-center video-embed"&gt;&lt;iframe class="embedly-embed" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FETQFKyJp2As%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DETQFKyJp2As&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FETQFKyJp2As%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" width="600" height="337" scrolling="no" title="Cortex XDR Customer Success Webinar: Endpoint Administration Part 2" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture;" allowfullscreen="true"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;/P&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rtsedaka_0-1663936231727.gif" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44114iF284EC27736026BD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rtsedaka_0-1663936231727.gif" alt="rtsedaka_0-1663936231727.gif" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Useful commands:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;===========================&lt;BR /&gt;On Windows -&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-8/cortex-xdr-agent-admin/cortex-xdr-agent-for-windows/troubleshoot-cortex-xdr-for-windows/cytool" target="_blank" rel="noopener"&gt; https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-8/cortex-xdr-agent-admin/cortex-xdr-agent-for-windows/troubleshoot-cortex-xdr-for-windows/cytool&lt;/A&gt;&lt;BR /&gt;===========================&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;- Run CMD as administrator&lt;/P&gt;
&lt;P&gt;- Change directory to Cortex XDR binary folder - un command 'cd "C:\Program Files\Palo Alto Networks\Traps" '&lt;/P&gt;
&lt;P&gt;- Enter the Supervisor Password (=Uninstall Password) for privileged commands&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Drivers &amp;amp; Services&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;cytool runtime query&lt;/P&gt;
&lt;P&gt;Persistent DB's&lt;BR /&gt;cytool persist list&lt;/P&gt;
&lt;P&gt;Registry&lt;BR /&gt;Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Cyvera&lt;BR /&gt;Computer\HKEY_LOCAL_MACHINE\SYSTEM\Cyvera&lt;/P&gt;
&lt;P&gt;File System&lt;BR /&gt;C:\Program Files\Palo Alto Networks\Traps&lt;BR /&gt;C:\ProgramData\Cyvera\&lt;/P&gt;
&lt;P&gt;cytool protect query&lt;BR /&gt;cytool protect disable&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;TSF&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;C:\Users\&amp;lt;Username&amp;gt;\AppData\Roaming\PaloAltoNetworks\Traps\support&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Agent Debug logs&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;To set Log Level:&lt;BR /&gt;cytool log level_set 7 all&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;To collect Log&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;'cytool log collect'&lt;/P&gt;
&lt;P&gt;return log level back to default&lt;BR /&gt;cytool log level_set 6 all&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Procump&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;If we are seeing the virtual memory exhaustion for cyveraserver.exe occur daily at a certain time&lt;BR /&gt;procdump -ma PID, where 4572 is the PID number of active cyveraserver.exe&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;===============&lt;BR /&gt;Linux:&lt;BR /&gt;===============&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;For user space mode&lt;/U&gt; &lt;/FONT&gt;(minimum supported kernel version is v5)&lt;/P&gt;
&lt;P&gt;uname -an&lt;BR /&gt;cat /proc/version&lt;BR /&gt;dmesg | grep Linux&lt;BR /&gt;lsb_release -a&lt;/P&gt;
&lt;P&gt;su&lt;/P&gt;
&lt;P&gt;cd /opt/traps/bin&lt;/P&gt;
&lt;P&gt;./cytool /?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Processes Protected by Cortex XDR&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;./cytool enum info&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Websocket&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;./cytool websocket query&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Checkin&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;./cytool Checkin&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Last Time Checkin&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;./cytool last_checkin&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Cortex XDR Processes&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;./cytool runtime query&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Agent files and directories&lt;/U&gt;&lt;/FONT&gt;&amp;nbsp; (for logs, edr, download, etc)&lt;BR /&gt;cat /opt/traps/config/common.xml&lt;/P&gt;
&lt;P&gt;Cortex XDR or Traps configuration&lt;BR /&gt;cat /opt/traps/config/trapsd.xml&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Connectivity&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;./cytool connectivity_test&lt;/P&gt;
&lt;P&gt;Agent version&lt;BR /&gt;cat /opt/traps/version.txt&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Agent ID&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;cat /etc/traps/agent.id&lt;/P&gt;
&lt;P&gt;Distribution ID&lt;BR /&gt;cat /opt/traps/config/trapsd.xml | grep -i distribution_id&lt;BR /&gt;cat /opt/traps/config/db_backup/distribution_id.txt&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Reconnect&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;./cytool reconnect&lt;BR /&gt;./cytool reconnect force XXX (replace XXX with the distribution ID)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Proxy IP address Configured&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;cat /opt/traps/config/trapsd.xml | grep -i proxy_list&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;To restart Cortex XDR processes&lt;/U&gt;&lt;/FONT&gt; (This does not survive reboot)&lt;BR /&gt;./cytool runtime query&lt;BR /&gt;./cytool runtime stop all&lt;BR /&gt;./cytool runtime start all&lt;BR /&gt;./cytool runtime restart all&lt;BR /&gt;./cytool runtime query&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;To change Cortex XDR processes behaviour at OS startup&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;./cytool startup query&lt;BR /&gt;./cytool startup disable all&lt;BR /&gt;./cytool startup enable all&lt;BR /&gt;./cytool startup query&lt;/P&gt;
&lt;P&gt;To check the protection status of the agent&lt;BR /&gt;./cytool security query&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;To query, disable and enable event_collection&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;./cytool event_collection query&lt;BR /&gt;./cytool event_collection disable&lt;BR /&gt;./cytool event_collection enable&lt;BR /&gt;./cytool event_collection query&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;To check Linux Operation Mode&lt;/U&gt; &lt;/FONT&gt;(Empty: kernel module not installed or user space, otherwise, Kernel operation mode)&lt;BR /&gt;lsmod | grep traps&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Resource Utilization&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;top -s&lt;BR /&gt;ps -ef | grep pmd&lt;BR /&gt;ps aux | grep pmd&lt;/P&gt;
&lt;P&gt;When has pmd being running&lt;BR /&gt;systemctl status traps_pmd&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Verify the agent was installed on the endpoint&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;dpkg -l | grep cortex-agent&lt;BR /&gt;rpm -qa | grep cortex-agent&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;logs&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;/var/log/traps/pmd.log&lt;/P&gt;
&lt;P&gt;./cytool log collect&lt;BR /&gt;sudo strace -ff -o cytool_tsf /opt/traps/bin/cytool log collect&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;===============&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Adaptive Policy:&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;cytool adaptive_collection /?&lt;/P&gt;
&lt;P&gt;cytool adaptive_collection query&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Disable Adaptive Policy&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;cytool adaptive_policy interval 0&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;===============&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have any questions about the topic presented, please post them on our &lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bd-p/Analytics_Discussions" target="_blank" rel="noopener"&gt;discussion page&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Thu, 03 Nov 2022 21:09:10 GMT</pubDate>
    <dc:creator>rtsedaka</dc:creator>
    <dc:date>2022-11-03T21:09:10Z</dc:date>
    <item>
      <title>Cortex XDR Customer Success Webinar: Endpoint Administration Part 2</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-videos/cortex-xdr-customer-success-webinar-endpoint-administration-part/ta-p/515809</link>
      <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;H2&gt;Endpoint Administration Part 2&lt;/H2&gt;
&lt;P&gt;Missed Endpoint Administration Part 1? Click &lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-webinars/cortex-xdr-customer-success-webinar-endpoint-administration/ta-p/513051" target="_blank" rel="noopener"&gt;HERE&lt;/A&gt; to watch&lt;/P&gt;
&lt;P&gt;This webinar covers the Cortex XDR agent-related administration task, including agent architecture, Linux agent, and demos.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;div class="video-embed-center video-embed"&gt;&lt;iframe class="embedly-embed" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FETQFKyJp2As%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DETQFKyJp2As&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FETQFKyJp2As%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" width="600" height="337" scrolling="no" title="Cortex XDR Customer Success Webinar: Endpoint Administration Part 2" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture;" allowfullscreen="true"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;/P&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rtsedaka_0-1663936231727.gif" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44114iF284EC27736026BD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rtsedaka_0-1663936231727.gif" alt="rtsedaka_0-1663936231727.gif" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Useful commands:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;===========================&lt;BR /&gt;On Windows -&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-8/cortex-xdr-agent-admin/cortex-xdr-agent-for-windows/troubleshoot-cortex-xdr-for-windows/cytool" target="_blank" rel="noopener"&gt; https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-8/cortex-xdr-agent-admin/cortex-xdr-agent-for-windows/troubleshoot-cortex-xdr-for-windows/cytool&lt;/A&gt;&lt;BR /&gt;===========================&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;- Run CMD as administrator&lt;/P&gt;
&lt;P&gt;- Change directory to Cortex XDR binary folder - un command 'cd "C:\Program Files\Palo Alto Networks\Traps" '&lt;/P&gt;
&lt;P&gt;- Enter the Supervisor Password (=Uninstall Password) for privileged commands&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Drivers &amp;amp; Services&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;cytool runtime query&lt;/P&gt;
&lt;P&gt;Persistent DB's&lt;BR /&gt;cytool persist list&lt;/P&gt;
&lt;P&gt;Registry&lt;BR /&gt;Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Cyvera&lt;BR /&gt;Computer\HKEY_LOCAL_MACHINE\SYSTEM\Cyvera&lt;/P&gt;
&lt;P&gt;File System&lt;BR /&gt;C:\Program Files\Palo Alto Networks\Traps&lt;BR /&gt;C:\ProgramData\Cyvera\&lt;/P&gt;
&lt;P&gt;cytool protect query&lt;BR /&gt;cytool protect disable&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;TSF&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;C:\Users\&amp;lt;Username&amp;gt;\AppData\Roaming\PaloAltoNetworks\Traps\support&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Agent Debug logs&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;To set Log Level:&lt;BR /&gt;cytool log level_set 7 all&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;To collect Log&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;'cytool log collect'&lt;/P&gt;
&lt;P&gt;return log level back to default&lt;BR /&gt;cytool log level_set 6 all&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Procump&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;If we are seeing the virtual memory exhaustion for cyveraserver.exe occur daily at a certain time&lt;BR /&gt;procdump -ma PID, where 4572 is the PID number of active cyveraserver.exe&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;===============&lt;BR /&gt;Linux:&lt;BR /&gt;===============&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;For user space mode&lt;/U&gt; &lt;/FONT&gt;(minimum supported kernel version is v5)&lt;/P&gt;
&lt;P&gt;uname -an&lt;BR /&gt;cat /proc/version&lt;BR /&gt;dmesg | grep Linux&lt;BR /&gt;lsb_release -a&lt;/P&gt;
&lt;P&gt;su&lt;/P&gt;
&lt;P&gt;cd /opt/traps/bin&lt;/P&gt;
&lt;P&gt;./cytool /?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Processes Protected by Cortex XDR&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;./cytool enum info&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Websocket&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;./cytool websocket query&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Checkin&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;./cytool Checkin&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Last Time Checkin&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;./cytool last_checkin&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Cortex XDR Processes&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;./cytool runtime query&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Agent files and directories&lt;/U&gt;&lt;/FONT&gt;&amp;nbsp; (for logs, edr, download, etc)&lt;BR /&gt;cat /opt/traps/config/common.xml&lt;/P&gt;
&lt;P&gt;Cortex XDR or Traps configuration&lt;BR /&gt;cat /opt/traps/config/trapsd.xml&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Connectivity&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;./cytool connectivity_test&lt;/P&gt;
&lt;P&gt;Agent version&lt;BR /&gt;cat /opt/traps/version.txt&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Agent ID&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;cat /etc/traps/agent.id&lt;/P&gt;
&lt;P&gt;Distribution ID&lt;BR /&gt;cat /opt/traps/config/trapsd.xml | grep -i distribution_id&lt;BR /&gt;cat /opt/traps/config/db_backup/distribution_id.txt&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Reconnect&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;./cytool reconnect&lt;BR /&gt;./cytool reconnect force XXX (replace XXX with the distribution ID)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Proxy IP address Configured&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;cat /opt/traps/config/trapsd.xml | grep -i proxy_list&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;To restart Cortex XDR processes&lt;/U&gt;&lt;/FONT&gt; (This does not survive reboot)&lt;BR /&gt;./cytool runtime query&lt;BR /&gt;./cytool runtime stop all&lt;BR /&gt;./cytool runtime start all&lt;BR /&gt;./cytool runtime restart all&lt;BR /&gt;./cytool runtime query&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;To change Cortex XDR processes behaviour at OS startup&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;./cytool startup query&lt;BR /&gt;./cytool startup disable all&lt;BR /&gt;./cytool startup enable all&lt;BR /&gt;./cytool startup query&lt;/P&gt;
&lt;P&gt;To check the protection status of the agent&lt;BR /&gt;./cytool security query&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;To query, disable and enable event_collection&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;./cytool event_collection query&lt;BR /&gt;./cytool event_collection disable&lt;BR /&gt;./cytool event_collection enable&lt;BR /&gt;./cytool event_collection query&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;To check Linux Operation Mode&lt;/U&gt; &lt;/FONT&gt;(Empty: kernel module not installed or user space, otherwise, Kernel operation mode)&lt;BR /&gt;lsmod | grep traps&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Resource Utilization&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;top -s&lt;BR /&gt;ps -ef | grep pmd&lt;BR /&gt;ps aux | grep pmd&lt;/P&gt;
&lt;P&gt;When has pmd being running&lt;BR /&gt;systemctl status traps_pmd&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Verify the agent was installed on the endpoint&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;dpkg -l | grep cortex-agent&lt;BR /&gt;rpm -qa | grep cortex-agent&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;logs&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;/var/log/traps/pmd.log&lt;/P&gt;
&lt;P&gt;./cytool log collect&lt;BR /&gt;sudo strace -ff -o cytool_tsf /opt/traps/bin/cytool log collect&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;===============&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Adaptive Policy:&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;cytool adaptive_collection /?&lt;/P&gt;
&lt;P&gt;cytool adaptive_collection query&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;Disable Adaptive Policy&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;cytool adaptive_policy interval 0&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;===============&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have any questions about the topic presented, please post them on our &lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bd-p/Analytics_Discussions" target="_blank" rel="noopener"&gt;discussion page&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 03 Nov 2022 21:09:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-videos/cortex-xdr-customer-success-webinar-endpoint-administration-part/ta-p/515809</guid>
      <dc:creator>rtsedaka</dc:creator>
      <dc:date>2022-11-03T21:09:10Z</dc:date>
    </item>
  </channel>
</rss>

