> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-152-major-20.md).

# XDR Collectors 1.5.2 (Major)

The XDR Collectors major release for Windows 1.5.2.2326 and Linux 1.5.2.2173 was released as part of the following releases of Cortex XSIAM:

* 2.0 on January 28, 2026

The following table describes the changes integrated for this release:

| ISSUE                                 | DESCRIPTION                                                                                                                                                                                                                                                                                                                       |
| ------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| CPATR-32437, CPATR-32546, CPATR-32547 | Upgraded the SQLite package to version (3.50.4) for both Linux and Windows XDR Collectors. This update addresses known vulnerabilities on previous SQLite versions.                                                                                                                                                               |
| CPATR-33046                           | Resolved an issue where XDR Collectors failed to start at initialization due to a third-party package.                                                                                                                                                                                                                            |
| CPATR-33166                           | Updated the "No incoming data" warning string to specify the associated application, for example, "winlogbeat: No incoming data for more than 7 days". This improves visibility by clarifying whether the alert refers to Winlogbeat or Filebeat data streams.                                                                    |
| CPATR-33262                           | Fixed a validation logic error where XDR Collectors incorrectly displayed an "Error" status when only Filebeat or Winlogbeat was configured. The collector now accurately reflects a "Connected" status based on the active YAML configuration, eliminating false error indications while data ingestion is functioning properly. |
| CPATR-34604                           | Resolved an issue where XDR Collectors failed to retrieve MAC addresses or hardware IDs, causing redundant re-registrations. This fix ensures stable device identification and prevents duplicate collector entries in the console.                                                                                               |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/previous-maintenance-releases/xdr-collectors/xdr-collectors-152-major-20.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
