Possible FP alerts on linux

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Possible FP alerts on linux

L2 Linker

Hi,

I seemingly have a problem with the xdr agents installed on ubuntu workstations -I get "local malware analysis" alerts on seemingly benign programs and executables such as chrome, VS code, systemd and such.

WF shows either benign or unknown. 

Problem is, I cant replicate those alerts on my ubuntu test station. 

Did someone else encounter this problem?

2 REPLIES 2

L2 Linker

Hi Daniel,

 

Just to make sure version/kernel is supported? Otherwise you can submit a support case so PA support can investigate further.

https://docs.paloaltonetworks.com/compatibility-matrix/cortex-xdr/where-can-i-install-the-cortex-xdr...

https://docs.paloaltonetworks.com/compatibility-matrix/cortex-xdr/cortex-xdr-supported-kernel-module...

 

Or maybe just corrupted installer that needs to be re-installed? 

 

 

The kernel version is is supported, I checked prior to installing the agent on the hosts

  • 1910 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!