XDR endpoints not scanning

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

XDR endpoints not scanning

L2 Linker

Is there a way to look at only the endpoints that have not been scanned in certain amount of time?
I know I can view all the have been scanned in the last day/week/month etc, but I want to look at the devices that have NOT been scanned. 
I need a "does NOT equal" button, on the Endpoint Administration tab.

pdysart_0-1641414295405.png

 

3 REPLIES 3

L3 Networker

I would think that you should at least be able to look at your "assigned prevention policy" and ensure that the "malware" profile assigned to all assets has scans enabled.

 

does this make sense? 

Yes, the assigned prevention policy is set to scan all of these endpoints on a weekly basis. But we have several thousand endpoints that have not had a successful scan in months, and those are the endpoints I am interested in looking at. 
I am less concerned about endpoints that "Aborted" their last scan, but had a successful scan a couple weeks ago, and more concerned about endpoints that haven't successfully scanned in several months.

pdysart_0-1641488952827.png

 

L2 Linker

Hello Pdysart, 

 

For monitoring, you can generate a Custom Dashboard by navigating to Reporting>Dashboards Manager+ New Dashboard.

 

jtalton_0-1641583468897.png

 

 

You may build the report by creating a Custom XQL Widget and build an XQL query filtering on the last_succesful_scan attribute:

dataset = endpoints |fields last_successful_scan, endpoint_name

 

jtalton_1-1641583468925.png

 

 

Your query can have a specific time range such as an endpoint last scanned in 24H (hours), last 7D (days), last 1M (month), or select a Custom time period. Save and Run to review the results.

 

Please reference for assistance with creating XQL queries.

Build a Custom Dashboard (paloaltonetworks.com)

Search Queries (paloaltonetworks.com)

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!