Troubleshooting Resources for Mac

ResourceDescription
Processes

Launch Daemons:

  • /Applications/Cortex XDR.app/Contents/MacOS/Cortex XDR
  • /Library/Application Support/PaloAltoNetworks/Traps/bin/pmd
  • /Library/Application Support/PaloAltoNetworks/Traps/bin/authorized

Launch Agents:

  • /Library/Application Support/PaloAltoNetworks/Traps/bin/Cortex XDR Agent.app/Contents/MacOS/Cortex XDR Agent

System Extensions:

  • com.paloaltonetworks.traps.securityextension
  • com.paloaltonetworks.traps.networkextension

Payload:

  • /Library/Application Support/PaloAltoNetworks/Traps/download/content/cortex-xdr-payload
Cortex XDR agent installation logSpecifies any errors encountered during the installation of agent components. Use this log file when you need to troubleshoot installation issues. On Mac OS endpoints, the system records installation events in the global install log located at /var/log/install.log.
Cortex XDR agent console log

Indicates information, warnings, and errors related to the agent console. The Console log is located in the following folder on the endpoint:

  • Mac OS X 10.10 and OSX 10.11—/var/log/traps/agent/
  • macOS 10.12 and later releases—View logs from the Console application in /Library/Logs/PaloAltoNetworks/Cortex XDR/.
Cortex XDR agent service log

Indicates information, warnings, and errors related to Cortex XDR. The Service log is located in the following folder on the endpoint:

  • Mac OS X 10.10 and OSX 10.11—/var/log/traps/
  • macOS 10.12 and later releases—View logs from the Console application in /Library/Logs/PaloAltoNetworks/Cortex XDR/.
Supervisor Command Line Tool (cytool)Allows you to manage agent features and perform advanced troubleshooting on the local endpoint from a command line interface. For more information, see Cytool for Mac.