Trouble with HIP checks for Anti-Malware

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Trouble with HIP checks for Anti-Malware

L2 Linker

Hi Community!

I have some issues getting HIP checks to work on a PA820.
Have configured a couple Objects that checks whether the Cortex XDR agent or Windows Defender is installed/enabled


And have them added to a profile that I have added to the GlobalProtect Gateway.

This seems to be working fine on a LAB-PA220 - triggers whenever Cortex XDR is not found, or if Defender is turned off. Verified on three separate devices (VM running Windows 10, Laptop running Windows 10, VM running server 2016).

On the PA820 however, users get the "Not Match Message" regardless of Cortex XDR / Defender status.

The funny part is that on the test machines mentioned above, I'm unable to reproduce the issues my coworkers are seeing. HIP works as intended.

Anyone know what could cause this behavior? My guess is that this is due to some local issues on Windows - but could there also be some issues where the firewalls (in general, or PA820 specifically?) are unable to get the the Host Information for some reason?

Appreciate any help!


L7 Applicator

It is strange that it acts differently on the 2 different devices, as it should act the same on both.

Do you mind letting us know what PAN-OS version is running on those 2 devices?


LIVEcommunity team member
Stay Secure,
Don't forget to Like items if a post is helpful to you!

Thanks for your reply!
Indeed - the PA220 is running 10.0.3, and the PA820 is running 10.0.4 (I know, the PA220 should be the one "on the bleeding edge-SW", rather than the PA820, but haven't found a fitting moment for it yet.

L7 Applicator

@pasmartin Thanks for the PAN-OS versions..  I was thinking it would be drastically different..  So that isn't it, or don't think so.. other than ensuring the versions match.. 

What about dynamic updates versions? between the 2 devices?

LIVEcommunity team member
Stay Secure,
Don't forget to Like items if a post is helpful to you!

@jdelio Oh snap - the PA220 had no check or action for antivirus - but other than that, they are configured the same for app&threat, wildfire are on the same versions. 

  • 4 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!