<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cyserver stopped by ntdll. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cyserver-stopped-by-ntdll/m-p/585811#M116926</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/309887"&gt;@MarcoMJ&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;My current knowledge and hands-on experience with Cortex XDR is limited, but this has been a thing ever since they moved it to the cloud. I can't recall having as many issues locally outside of agent updates that failed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I would personally recommend doing is utilizing your inventory/AD/MDM/etc to get a list of computers that Cortex &lt;EM&gt;should &lt;/EM&gt;show in console, and then utilize the API to identify any agents that aren't communicating properly. The script doesn't have to do anything difficult, simply look at the last connection time and pair it with a simple ICMP test. If the last connection time isn't today, and it's responding to ICMP, you have a bunk client that you need to fix.&lt;/P&gt;
&lt;P&gt;I wish I had a better answer for you, but I spent &lt;EM&gt;a lot &lt;/EM&gt;of time reporting agents that got disconnected and working to try and identify root cause so that I didn't have to spend as much time fixing things. &lt;/P&gt;</description>
    <pubDate>Sun, 05 May 2024 02:41:38 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2024-05-05T02:41:38Z</dc:date>
    <item>
      <title>Cyserver stopped by ntdll.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cyserver-stopped-by-ntdll/m-p/585808#M116925</link>
      <description>&lt;P&gt;&lt;SPAN data-preserver-spaces="true"&gt;Hi team,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-preserver-spaces="true"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-preserver-spaces="true"&gt;Recently, We discovered endpoints that got disconnected from the console&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-preserver-spaces="true"&gt;and&lt;/SPAN&gt;&lt;SPAN data-preserver-spaces="true"&gt;&amp;nbsp;there is no clue on trapsd why it happened because the agent didn't record logs since its last_seenn on the console&lt;/SPAN&gt;&lt;SPAN data-preserver-spaces="true"&gt;,&amp;nbsp;for&lt;/SPAN&gt;&lt;SPAN data-preserver-spaces="true"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-preserver-spaces="true"&gt;example;&lt;/SPAN&gt;&lt;SPAN data-preserver-spaces="true"&gt;&amp;nbsp;the agent has a last_seen on 1 May 2024&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-preserver-spaces="true"&gt;and&lt;/SPAN&gt;&lt;SPAN data-preserver-spaces="true"&gt;&amp;nbsp;you reconnected the agent on 4 May 2024, there are no logs between 1 May and 4 May. We discover a log like this on&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-preserver-spaces="true"&gt;application&lt;/SPAN&gt;&lt;SPAN data-preserver-spaces="true"&gt;.evtx;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-preserver-spaces="true"&gt;Faulting application name: cyserver.exe, version: 8.2.1.47908&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-preserver-spaces="true"&gt;Faulting module name: ntdll.dll, version: 10.0.19041.3636&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-preserver-spaces="true"&gt;Exception code: 0xc0000374&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-preserver-spaces="true"&gt;Fault offset: 0x00000000000ff349&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-preserver-spaces="true"&gt;Faulting process id: 0x1a90&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-preserver-spaces="true"&gt;Faulting application path: C:\Program Files\Palo Alto Networks\Traps\cyserver.exe&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-preserver-spaces="true"&gt;Faulting module path: C:\Windows\SYSTEM32\ntdll.dll&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-preserver-spaces="true"&gt;After that, when we started to check other endpoints, we discovered the same situation, Does anyone know a little more about this or has this happened?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-preserver-spaces="true"&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-preserver-spaces="true"&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 04 May 2024 07:38:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cyserver-stopped-by-ntdll/m-p/585808#M116925</guid>
      <dc:creator>MarcoMJ</dc:creator>
      <dc:date>2024-05-04T07:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cyserver stopped by ntdll.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cyserver-stopped-by-ntdll/m-p/585811#M116926</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/309887"&gt;@MarcoMJ&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;My current knowledge and hands-on experience with Cortex XDR is limited, but this has been a thing ever since they moved it to the cloud. I can't recall having as many issues locally outside of agent updates that failed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I would personally recommend doing is utilizing your inventory/AD/MDM/etc to get a list of computers that Cortex &lt;EM&gt;should &lt;/EM&gt;show in console, and then utilize the API to identify any agents that aren't communicating properly. The script doesn't have to do anything difficult, simply look at the last connection time and pair it with a simple ICMP test. If the last connection time isn't today, and it's responding to ICMP, you have a bunk client that you need to fix.&lt;/P&gt;
&lt;P&gt;I wish I had a better answer for you, but I spent &lt;EM&gt;a lot &lt;/EM&gt;of time reporting agents that got disconnected and working to try and identify root cause so that I didn't have to spend as much time fixing things. &lt;/P&gt;</description>
      <pubDate>Sun, 05 May 2024 02:41:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cyserver-stopped-by-ntdll/m-p/585811#M116926</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-05-05T02:41:38Z</dc:date>
    </item>
  </channel>
</rss>

