Monitor agent operational status in Cortex XSIAM ↗
Cortex XSIAM provides information about the XDR agent operational status on an endpoint. It indicates whether the agent provides protection according to its predefined security policies and profiles. This information can help you identify technical issues or misconfigurations that interfere with the agent’s protection capabilities or interactions with Cortex XSIAM and other applications.
The XDR agent reports the operational status as follows:
- Protected: Indicates that the XDR agent is running as configured and did not report any exceptions to Cortex XSIAM.
- Partially protected: Indicates that the XDR agent reported one or more exceptions to Cortex XSIAM.
- Unprotected: Indicates the XDR agent is not enforcing protection on the endpoint.
- Local Resource Impact: Indicates that available endpoint resources are insufficient for the XDR agent to operate smoothly.
You can monitor the Cortex XDR agent Operational Status in Endpoints → All Endpoints.
The reported operational status varies according to exceptions reported by the XDR agent.
| Status | Description |
|---|---|
| Protected | (Windows, Mac, and Linux) Indicates all protection modules are running as configured on the endpoint. |
| Partially protected | <p>Windows</p><ul><li>XDR data collection is not running, or not set</li><li>Behavioral threat protection is not running</li><li>Malware protection is not running</li><li>Exploit protection is not running</li></ul><p>Mac</p><ul><li>Operating system adaptive mode*</li><li>XDR Data Collection is not running, or not set</li><li>Behavioral threat protection is not running</li><li>Malware protection is not running</li><li>Exploit protection is not running</li></ul><p>Linux</p><ul><li>Kernel module not loaded</li><li>Kernel module compatible but not loaded</li><li>Kernel version not compatible**</li><li>XDR Data Collection is not running, or not set</li><li>Behavioral threat protection is not running</li><li>Anti-malware flow is asynchronous</li><li>Malware protection is not running</li><li><p>Exploit protection is not running</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Any of the listed items could lead to a partially protected state. Refer to the Cortex XSIAM management console for specific reasons for the state.</p></div></li></ul> |
| Unprotected | <p>Windows, Mac, and Linux:</p><ul><li>Behavioral threat protection and Malware protection are not running</li><li>Exploit protection and malware protection are not running</li><li>The content is unavailable.</li></ul> |
| Local Resource Impact | <p>Windows, Mac, Linux</p><ul><li>Machine CPU impact on the agent operation</li><li>Machine memory impact on the agent operation</li></ul><p>In addition to the status, either one of the following sub-statuses appear:</p><ul><li>Low local available memory</li><li>No local available memory</li></ul> |
A status can have the following implications for the endpoint:
- *(
Status): The exploit protection module is not running. - **(
Status):- XDR data collection is not running
- Behavioral threat protection is not running
- Anti-malware flow is asynchronous
- Local privilege escalation protection is asynchronous