Cortex XDR service getting stoppage on machines

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Cortex XDR service getting stoppage on machines

L1 Bithead

why the Monitoring agent service getting stopped on Hosts. When we checked the logs of some machines we got this error " XDR service cyserver was stopped on ABCDdesktop. Could you please explain 

2 REPLIES 2

L5 Sessionator

Hi @VineethArumulla ,

 

Since this is a public forum for discussion, it would be difficult to answer and investigate. Request you to kindly open a support case with our technical team with support files for investigation and fix(if any).

 

Not sure where did you check the logs, however, if it was in the agent audit logs, it is also possible that Cortex XDR sends this audit log when endpoints are powered off. When the endpoint is shutdown, then the agent service stops and hence the XDR sends this in form on an agent audit log. However, if you see this happening for the endpoints and then you don't get a start service from the same endpoint for some defined number of days that can be an anomaly in your environment, then you should also investigate on the endpoint level to see if there is some issue.

Screenshot 2023-02-03 at 6.48.22 PM.png

 

 

Hope this helps!

 

Please mark the response as  "Accept as Solution" if it answers your query.

 

Regards

L1 Bithead

I noticed a similar trend with systems in our environment. When looking at the logs of a specific endpoint and the comparing activity of others, the cyserver service gets stopped when Cortex XDR performs a policy update. These two events are usually within 1 minute of each other. If you did open a ticket, I'm sure others here would like to know what the official resolution was to the question.

  • 1626 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!