Malware Scan on XDR

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Malware Scan on XDR

L3 Networker

Hello,

 

How long does it take for endpoints to go to failed/canceled state from in progress state when malware scan ran on endpoints?

6 REPLIES 6

L4 Transporter

Hi @RamyashreeMada,

Thank you for writing to Live Community. I'm not sure I fully understand your question.

Do you mean how long it will take the endpoint to go failed/cancelled in case the endpoint was disconnected or something interrupted the scan?

Visit our Cortex XDR Customer Corner on Live Community to access resources for your product journey, engage in discussions with community members and subject matter experts, and register for upcoming events: Cortex XDR Customer Corner

Yes, That's what I mean.

L4 Transporter

Hi @RamyashreeMada 


1. In the instance the connection is lost between the Endpoint and XDR cloud, but the scan had already started the scan should be completed and report the status back online if it happens within 24 hours.
2. In the instance the machine was shut down halfway through the scan the scan should indeed be cancelled/failed. This information should arrive to the XDR console in around 5-7 seven minutes, as the the Cortex XDR agent initiates communication with Cortex XDR every five minutes by sending a heartbeat to the server.

 

You can read more about Agent and Server initiated communication here.


 

If this helped, please click 'Accept as Solution'.

 

Visit our Cortex XDR Customer Corner on Live Community to access resources for your product journey, engage in discussions with community members and subject matter experts, and register for upcoming events: Cortex XDR Customer Corner

After how long it should get cancelled or failed if system scan is in progress and system is also connected to console.

I mean what is the timeout period for Cortex XDR to cancel or fail the scan progress. I have seen few agents it keeps on scanning for more than 2-3 days .

L4 Transporter

@TejasPatil,

 

If you are experiencing scanning that is taking 2-3 days to complete please submit this information in a case to our support center.  The amount of time it takes to perform a scan is dependant on several factors not limited to endpoint hardware.  In any case 2-3 days seems extremely excessive and support will be able to look into the issue deeper to ensure there are no underlying issues we're unaware of.

 

In reference to the question of timeout period, I don't' believe there is a timeout period for the scan.  Once the command has been sent, unless a disconnection is made the scan will commence and run until complete.

 

I hope you find this information helpful.

 

Have a great day!

L4 Transporter

Hi @RamyashreeMada,

 

I just wanted to a supply a quick information update.  You asked earlier about how long it would take a scan to time out.  I was unaware of the time out, but can now confirm that the scan command should timeout after 24 hours.  This amount of time can be changed with a Support Exception, but would require having a ticket in with our support team.

 

  • 1937 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!