Action Center reference information

The following table describes both the default and additional optional fields that you can view from the All Actions tab of the Action Center and lists the fields in alphabetical order.

Action center field reference

FieldDescription
Action TypeType of action initiated on the endpoint.
Agent Restart

Status of the restart action on the endpoint.

Statuses:

  • In progress: Action initiated, but no start indication from agent after stop.
  • Failed: Agent reports failed back to the Cortex XSIAM server if it was started after more than 10 minutes after restart initiation.
  • Expired: After 4 days.
  • Success: Agent reports success to the Cortex XSIAM server if it was started within 10 minutes after restart initiation.
Created ByName of the user who initiated the action.
Creation TimestampDate and time the action was created.
DescriptionAction scope of affected endpoints and additional data relevant to each of the specific actions, such as agent version, file path, and file hash.
Expiration Date

Time the action will expire. To set an expiration date, the action must apply to one or more endpoints.

By default, Cortex XSIAM assigns a 30-day expiration limit to the following actions:

  • Agent Uninstall
  • Agent Upgrade
  • Files Retrieval
  • Isolate
  • Cancel Endpoint Isolation

Additional actions such as malware scans, quarantine, and endpoint data retrieval are assigned a 4-day expiration limit.

After the expiration limit, the status for any remaining Pending actions on endpoints change to Expired and these endpoints will not perform the action.

StatusCurrent status of the action.
Additional data: If additional details are available for an action or for specific endpoints, you can pivot to the Additional data view. You can also export the additional data to a TSV file. The page can include details in the following fields but varies depending on the type of action.
Endpoint NameTarget host name of each endpoint for which an action was initiated.
IP AddressesIP address associated with the endpoint.
StatusStatus of the action for the specific endpoint. (Linux)—Completed with Partial Success for a single endpoint that did not complete the action successfully.
Action Last UpdateTime at which the last status update occurred for the action.
Advanced AnalysisFor Retrieve issue data requests related to Cortex XSIAM issues triggered by exploit protection modules, Cortex XSIAM can analyze the memory state for additional verdict verification. This field displays the analysis progress and resulting verdict.
Action ParametersSummary of the action including the issue name and ID.
Additional Data | Malicious FilesAdditional data, if any is available, for the action. For malware scans, this field is titled Malicious Files and indicates the number of malicious files identified during the scan.