Hi @Shashanksinha ,
- Initiating Malware Scan from XDR console should be similar to any other action/configuration. XDR agent is performing check-in every 5mins (this is fixed and cannot be changed). The Check-in have multiple purposes - it is used as heartbeat by the agent to notify the console it is still alive/connected. But most importantly check-in is used by the agent to check if there are any policy changes, or any actions that needs to be performed by the agent. When you trigger scan from the console, agent will receive the message on the next check-in. Agent should perform check-in after boot as well.
- I am not sure if user will receive notification for initiated scan as in our setup we have disabled all notifications and completely hide XDR agent GUI from the end user. You can disable either the notifications or end user access to XDR agent console by updating the Agent Settings Profile - https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Customizabl...
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!