Cortex uninstall/removing issues - reminisces and files related to the Cortex XDR are left on the hard drive and cannot be removed from the endpoint.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Cortex uninstall/removing issues - reminisces and files related to the Cortex XDR are left on the hard drive and cannot be removed from the endpoint.

L2 Linker

Dear Live Community Members,

 

My customer is facing issues when trying to remove Cortex XDR.

In short, uninstalling the software is not removing all the config, and it gets all the old settings back, like the broker and other stuff.

We even used the command CLEAN_AGGRESIVLY=1, but it still comes back with the wrong broker and settings from the previous install.

 

We've also tried the Cortex_Cleaner_Tool and the customer ran the cleaner once, as an administrator. Then rebooted the machine. Ran the cleaner again as administrator, then rebooted again. But the Cortex broker settings are still there, and the old log files are there as well.

*We've been using the XdrAgentCleaner_7.6.0.43778 version to remove the 7.8 release

So maybe the newest version is required... Has anyone the newest Cortex cleaner tool for version 7.8 and up that could share with me?

 

I'm considering reinstalling the OS on the affected machine, while by reimagining the OS on the endpoint we'll make sure there is nothing left from the old installation of Cortex XDR but it's the last resort and maybe there is something else we could do?

 

I'm wondering if anyone has been faced with a similar issue and could advise what's the best way to move forward?

The customer is also asking if he can manually override these settings, and remove the rest of the Cortex settings/logs.

Should we reinstall the OS, or maybe we could involve the PA TAC to help us with that?

 

 I will really appreciate your help and any hints to address this issue.

 

Thank you in advance!

1 accepted solution

Accepted Solutions

L2 Linker

Dear All,

 

We've escalated this to Palo Alto TAC, and Agent Cleaner for XDR agent version 7.8 has been provided.

The issue has been solved!

 

Thank you!

View solution in original post

3 REPLIES 3

L3 Networker

Hi @A_Adamski,

I would definitely recommend reaching out to TAC in this case before reinstalling the OS on the affected endpoint. There is a newer version of the cleaner tool available for 7.8 which TAC can provide to assist with the removal. 

L5 Sessionator

hi @A_Adamski ,

 

The agent 7.8 has a new agent cleaner which can be used for agent 7.8 and below. Also, once you uninstall, the folders can be deleted post a reboot. 

 

If you have some residual files in the system, you can log in to safe mode and try removing the files post uninstall. 

 

L2 Linker

Dear All,

 

We've escalated this to Palo Alto TAC, and Agent Cleaner for XDR agent version 7.8 has been provided.

The issue has been solved!

 

Thank you!

  • 1 accepted solution
  • 3577 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!