<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR Agent management questions - stragglers and operation status in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-agent-management-questions-stragglers-and-operation/m-p/398619#M91526</link>
    <description>&lt;P&gt;I've deployed the cortex agent to all of our servers and now need to find stragglers (servers without agents running).&amp;nbsp; I also need a method to know that not only are the agents installed and running but they are actually running as designed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I noticed there is a network scan in the portal for cortex but it only shows IPs for the devices, so I dont (easily) what is a server and not a server nor do I know if its simply a switch.&amp;nbsp; Is there a way to get the scan to use DNS or something to show the names of devices without the agent installed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lastly, anyone have a method to understand if the agents are actually active, have up to date definitions (is this "content" in cortex?) and are essentially doing what they are supposed to do? We dont want to get caught with pants down just because we know the agent is installed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Thu, 15 Apr 2021 15:27:11 GMT</pubDate>
    <dc:creator>ESJosephPrinz</dc:creator>
    <dc:date>2021-04-15T15:27:11Z</dc:date>
    <item>
      <title>Cortex XDR Agent management questions - stragglers and operation status</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-agent-management-questions-stragglers-and-operation/m-p/398619#M91526</link>
      <description>&lt;P&gt;I've deployed the cortex agent to all of our servers and now need to find stragglers (servers without agents running).&amp;nbsp; I also need a method to know that not only are the agents installed and running but they are actually running as designed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I noticed there is a network scan in the portal for cortex but it only shows IPs for the devices, so I dont (easily) what is a server and not a server nor do I know if its simply a switch.&amp;nbsp; Is there a way to get the scan to use DNS or something to show the names of devices without the agent installed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lastly, anyone have a method to understand if the agents are actually active, have up to date definitions (is this "content" in cortex?) and are essentially doing what they are supposed to do? We dont want to get caught with pants down just because we know the agent is installed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Thu, 15 Apr 2021 15:27:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-agent-management-questions-stragglers-and-operation/m-p/398619#M91526</guid>
      <dc:creator>ESJosephPrinz</dc:creator>
      <dc:date>2021-04-15T15:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Agent management questions - stragglers and operation status</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-agent-management-questions-stragglers-and-operation/m-p/398820#M91535</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176081"&gt;@ESJosephPrinz&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I don't believe there is currently a way to get the DNS name of the host on the Network Mapper results, however you can export that so you can create a simple PowerShell or Python script or whatever to attempt to resolve the IP and run through your export.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As to testing the agent, I've not found a good way outside of confirming Network Mapper results with your endpoint results through exports and scripts to ensure that the agents are actually active across your device fleet. You can use&amp;nbsp;&lt;A href="http://wildfire.paloaltonetworks.com/publicapi/test/pe" target="_blank"&gt;wildfire.paloaltonetworks.com/publicapi/test/pe&lt;/A&gt;&amp;nbsp;to test a detection on the endpoint and script that download and execution if you want to validate Cortex is actually working, but if an endpoint becomes unregistered it obviously won't trigger anything except on the functional hosts, so a review is what I recommend.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have had agents become unregistered from the portal, albeit on a much lesser amount now than previously, that you won't know about unless you review your endpoint list and actively check for "Connection Lost" and manually reviewing your host list. This used to happen much more frequently, but we still run across it occasionally.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Apr 2021 22:34:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-agent-management-questions-stragglers-and-operation/m-p/398820#M91535</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-04-15T22:34:24Z</dc:date>
    </item>
  </channel>
</rss>

