Malware Scan on XDR

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Malware Scan on XDR

L2 Linker



How long does it take for endpoints to go to failed/canceled state from in progress state when malware scan ran on endpoints?


L3 Networker

Hi @RamyashreeMada,

Thank you for writing to Live Community. I'm not sure I fully understand your question.

Do you mean how long it will take the endpoint to go failed/cancelled in case the endpoint was disconnected or something interrupted the scan?

Yes, That's what I mean.

L3 Networker

Hi @RamyashreeMada 

1. In the instance the connection is lost between the Endpoint and XDR cloud, but the scan had already started the scan should be completed and report the status back online if it happens within 24 hours.
2. In the instance the machine was shut down halfway through the scan the scan should indeed be cancelled/failed. This information should arrive to the XDR console in around 5-7 seven minutes, as the the Cortex XDR agent initiates communication with Cortex XDR every five minutes by sending a heartbeat to the server.


You can read more about Agent and Server initiated communication here.


If this helped, please click 'Accept as Solution'.


Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!