Restart agent

You can restart an agent from the Cortex XSIAM tenant.

This action is hidden by default.

As soon as the action is confirmed, the restart command triggers a restart of the agent on the endpoint.

From Cortex XSIAM, navigate to Inventory → Endpoints → All Endpoints. Select the relevant endpoint to restart and right-click + Alt, select Endpoint Control → Restart Agent, and click OK.

Select I agree, and then click OK to confirm restarting the agent on all selected endpoints.