Endpoint scanning

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Endpoint scanning

L3 Networker

Hello,

 

  • For Scans applied through polices for the pending machines how long the scan command remains upon scan initiation. for eg: I enabled scan policy on Monday the system was in disconnected state on that day and it comes back online on Thursday will the policy applied to it and initiate the scan on that system. Note: The policy will be not disabled.
  • Few scan are getting failed due to the user cancel scan manually. Is there any notification sent to the user once the scan is initiated. if yes is there any way to disable the notifications and is there any option to disable the access to the user to cancel the scan.

1 REPLY 1

Hi @Shashanksinha ,

- Initiating Malware Scan from XDR console should be similar to any other action/configuration. XDR agent is performing check-in every 5mins (this is fixed and cannot be changed). The Check-in have multiple purposes - it is used as heartbeat by the agent to notify the console it is still alive/connected. But most importantly check-in is used by the agent to check if there are any policy changes, or any actions that needs to be performed by the agent. When you trigger scan from the console, agent will receive the message on the next check-in.  Agent should perform check-in after boot as well.

 

- I am not sure if user will receive notification for initiated scan as in our setup we have disabled all notifications and completely hide XDR agent GUI from the end user. You can disable either the notifications or end user access to XDR agent console by updating the Agent Settings Profile - https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Customizabl...

  • 826 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!