Cortex XDR Agent - Connection Lost on Endpoints

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cortex XDR Agent - Connection Lost on Endpoints

L3 Networker

Hi Team,

 

We are facing connection loss issues with some of the endpoints. When we try to reconnect, it fails. We also attempted to retrieve the agent logs, but that also failed. Could you please let us know if there is a possible path to retrieve the agent logs

2 REPLIES 2

L3 Networker

Hi @Vinothkumar_SBA 

Thank you for your query on LC!


I suppose, we first need to understand why the status is "connection lost" to proceed accordingly.
Is it because the agents/host was inactive hence the licenses were retrieved to the pool OR may be other reasons?
- If force reconnect is failing, I believe above could be the reason and because of this logs fetching also failing because the agent could be dead.

If so, the next steps would be fresh re-install, I think this feature would also be helpful in this case- refer to step7- Configure the Cortex XDR Agent license revocation and deletion period- https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Configure-G...

If the reason is not because of license or active agents reaching connection lost status for some other reason and want to check the logs then please raise a TAC case where they share other ways of collecting the logs(generally a tool if all the options fails).

Give it a like or Accept as solution if this answer helps.

Best,
Naveen






Hi Mr. Naveen,

 

Thanks for your response. We are affecting a large number of endpoints, so reinstallation is not possible. We have tried some endpoints, and the logs are available. Reconnecting them is working fine. However, in another case, we have not been able to retrieve logs for the affected endpoints.

  • 277 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!