<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cortex xdr agent connection problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-agent-connection-problem/m-p/488615#M104835</link>
    <description>&lt;P&gt;problem solved&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;</description>
    <pubDate>Thu, 19 May 2022 15:13:18 GMT</pubDate>
    <dc:creator>Land-Salzburg</dc:creator>
    <dc:date>2022-05-19T15:13:18Z</dc:date>
    <item>
      <title>cortex xdr agent connection problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-agent-connection-problem/m-p/488185#M104790</link>
      <description>&lt;P&gt;hi everybody,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we've installed cortex xdr agent on a terminal-master server which gets cloned for distribution&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;xdr-agent on master has active connection to cortex-cloud&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but cloned servers can't connect...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;xdr-log:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;2022/05/18T14:32:44.590+02:00 &amp;lt;Info&amp;gt; LVTS41 [3608:5152 ] {trapsd:VerdictService:WfDeferredRequestsTimer:} Calling cloud for 3 WildFire verdicts&lt;BR /&gt;2022/05/18T14:32:44.590+02:00 &amp;lt;Info&amp;gt; LVTS41 [3608:5152 ] {trapsd:Communication:WfDeferredRequestsTimer:} No authentication ID - checking if registration is required&lt;BR /&gt;2022/05/18T14:32:44.590+02:00 &amp;lt;Notice&amp;gt; LVTS41 [3608:5152 ] {trapsd:Communication:WfDeferredRequestsTimer:} The agent is not registered. Registering with the cloud.&lt;BR /&gt;2022/05/18T14:32:44.593+02:00 &amp;lt;Info&amp;gt; LVTS41 [3608:5152 ] {trapsd:AgentIdentification:WfDeferredRequestsTimer:} Stored hardware id is {17300142-0AC2-FECE-D0E6-DEFD980093ED}, calculated hardware id is {17300142-0AC2-FECE-D0E6-DEFD980093ED}&lt;BR /&gt;2022/05/18T14:32:44.593+02:00 &amp;lt;Info&amp;gt; LVTS41 [3608:5152 ] {trapsd:AgentIdentification:WfDeferredRequestsTimer:} All checks done, registering&lt;BR /&gt;2022/05/18T14:32:44.596+02:00 &amp;lt;Info&amp;gt; LVTS41 [3608:5152 ] {trapsd:AgentIdentification:WfDeferredRequestsTimer:} Registering using agent ID &lt;BR /&gt;2022/05/18T14:32:44.597+02:00 &amp;lt;Warning&amp;gt; LVTS41 [3608:5152 ] {trapsd:AgentIdentification:WfDeferredRequestsTimer:} GetCurrentUserInfo returned with error code 0, continue with registration.&lt;BR /&gt;2022/05/18T14:32:44.607+02:00 &amp;lt;Notice&amp;gt; LVTS41 [3608:5152 ] {trapsd:Communication:WfDeferredRequestsTimer:/operations/provision/register:} Communication with server is disabled. Replace distribution ID to reconnect.&lt;BR /&gt;2022/05/18T14:32:44.609+02:00 &amp;lt;Warning&amp;gt; LVTS41 [3608:5152 ] {trapsd:Communication:WfDeferredRequestsTimer:} Connectivity Error, error_type = 3&lt;BR /&gt;2022/05/18T14:32:44.632+02:00 &amp;lt;Error&amp;gt; LVTS41 [3608:5152 ] {trapsd:AgentIdentification:WfDeferredRequestsTimer:} Error registering with the server, error 4. Error data: &lt;BR /&gt;2022/05/18T14:32:44.651+02:00 &amp;lt;Notice&amp;gt; LVTS41 [3608:5152 ] {trapsd:AgentIdentification:WfDeferredRequestsTimer:} Registration failed, hardware_id='{17300142-0AC2-FECE-D0E6-DEFD980093ED}' distribution_id='520620aa0360410e9e081a9d38886436' trial_count=170 error=4&lt;BR /&gt;2022/05/18T14:32:44.666+02:00 &amp;lt;Info&amp;gt; LVTS41 [3608:5152 ] {trapsd:Communication:WfDeferredRequestsTimer:} Unable to obtain authentication ID, aborting request.&lt;BR /&gt;2022/05/18T14:32:44.667+02:00 &amp;lt;Info&amp;gt; LVTS41 [3608:5152 ] {trapsd:VerdictService:WfDeferredRequestsTimer:} Failed calling server with error 307 - treating all 3 verdict(s) as NoConnection&lt;BR /&gt;2022/05/18T14:32:44.667+02:00 &amp;lt;Info&amp;gt; LVTS41 [3608:5152 ] {trapsd:VerdictService:WfDeferredRequestsTimer:} No server response for hash '1a9e9ddcdec423fe5fe8c24d4a3cdfa5ae63b2e355dfe2e8d3dc1ac9061c1608' - treating as NoConnection&lt;BR /&gt;2022/05/18T14:32:44.667+02:00 &amp;lt;Info&amp;gt; LVTS41 [3608:5152 ] {trapsd:VerdictService:WfDeferredRequestsTimer:} No server response for hash '2d177e445025b0d9421ae293274ccda237991b4522cf496dc9b84dd2b00dc3bb' - treating as NoConnection&lt;BR /&gt;2022/05/18T14:32:44.667+02:00 &amp;lt;Info&amp;gt; LVTS41 [3608:5152 ] {trapsd:VerdictService:WfDeferredRequestsTimer:} No server response for hash 'e40d261541fb62362a9b17aef1cf5d639a27623f6fb28d7d35e4e69f81850a6f' - treating as NoConnection&lt;BR /&gt;2022/05/18T14:33:46.351+02:00 &amp;lt;Info&amp;gt; LVTS41 [3608:7596 ] {trapsd:SecurityEventService:EcEventCollectionPipeline:} Raising security event from component 0x152, status 0xC0400097. Starting event rule matching...&lt;BR /&gt;2022/05/18T14:33:46.351+02:00 &amp;lt;Info&amp;gt; LVTS41 [3608:7596 ] {trapsd:SecurityEventService:EcEventCollectionPipeline:} Security event rules matching result: Match, rule name=DPI-1000000002&lt;BR /&gt;2022/05/18T14:33:46.351+02:00 &amp;lt;Info&amp;gt; LVTS41 [3608:7596 ] {trapsd:SecurityEventService:EcEventCollectionPipeline:} Ignoring security event by policy&lt;BR /&gt;2022/05/18T14:33:55.864+02:00 &amp;lt;Info&amp;gt; LVTS41 [3608:3104 default[#2]:7] {trapsd:Protection:VerifyAgentStatus:} AuthTokens value doesn't exist - returning empty tokens vector&lt;BR /&gt;2022/05/18T14:34:00.483+02:00 &amp;lt;Notice&amp;gt; LVTS41 [3608:7292 AgentOperationalStatusReporterThread:5] {trapsd:Telemetry:AgentOperationalStatusReporter:} Current agent operational status {&lt;BR /&gt;"antiexploitStatus" : 0,&lt;BR /&gt;"antimalwareStatus" : 0,&lt;BR /&gt;"dseStatus" : 0,&lt;BR /&gt;"edrStatus" : 0,&lt;BR /&gt;"generalStatus" : 0,&lt;BR /&gt;"hostfirewallStatus" : 0&lt;BR /&gt;}&lt;BR /&gt;2022/05/18T14:34:00.485+02:00 &amp;lt;Notice&amp;gt; LVTS41 [3608:7292 AgentOperationalStatusReporterThread:5] {trapsd:Telemetry:AgentOperationalStatusReporter:} &lt;BR /&gt;Agent operational status - EDR upload statistics&lt;BR /&gt;EDR upload success ratio : 0 %&lt;BR /&gt;Last succeeded upload time: N/A&lt;BR /&gt;Last failed upload time: 2022-05-18T12:32:25.765Z&lt;BR /&gt;2022/05/18T14:34:00.502+02:00 &amp;lt;Info&amp;gt; LVTS41 [3608:7292 AgentOperationalStatusReporterThread:5] {trapsd:Telemetry:AgentOperationalStatusReporter:} Waiting for 300 seconds&lt;/PRE&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what is the problem?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is it only possible to install on running-cloned server?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thx for any help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 12:48:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-agent-connection-problem/m-p/488185#M104790</guid>
      <dc:creator>Land-Salzburg</dc:creator>
      <dc:date>2022-05-18T12:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: cortex xdr agent connection problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-agent-connection-problem/m-p/488374#M104810</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184036"&gt;@Land-Salzburg&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;From your logs, the distribution ID error means that the installation package was removed from your tenant. You'll need to go into Endpoint Management -&amp;gt; Agent Installations and regenerate an installer with a new distribution ID. Going forward, don't delete an Agent Installation that you're actively using, it'll remove the association with the distribution ID and cause installations to fail.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 21:44:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-agent-connection-problem/m-p/488374#M104810</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-05-18T21:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: cortex xdr agent connection problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-agent-connection-problem/m-p/488514#M104823</link>
      <description>&lt;P&gt;hi, thx for your info, server-group told me they maybe used new installer, i've generated a newly on and now we are taking another approach&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 08:48:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-agent-connection-problem/m-p/488514#M104823</guid>
      <dc:creator>Land-Salzburg</dc:creator>
      <dc:date>2022-05-19T08:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: cortex xdr agent connection problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-agent-connection-problem/m-p/488615#M104835</link>
      <description>&lt;P&gt;problem solved&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 15:13:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-agent-connection-problem/m-p/488615#M104835</guid>
      <dc:creator>Land-Salzburg</dc:creator>
      <dc:date>2022-05-19T15:13:18Z</dc:date>
    </item>
  </channel>
</rss>

