For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex Cloud Runtime

Manage endpoints

View and manage endpoints in your environment.

The All Endpoints page provides a central location from which you can view and manage the endpoints on which the agent is installed. To access the All Endpoints page, go to InventoryEndpointsAll Endpoints.

To ensure the All Endpoints table is displaying the most accurate list of endpoints, you can perform a one-time or periodic cleanup of duplicated entities. After the cleanup, duplicated entities are removed leaving only one endpoint entry, which is the last endpoint to connect with the server. Deleted endpoint data is retained for 90 days from the last connection timestamp. If a deleted endpoint reconnects, Cortex Cloud recovers and redisplays the endpoint’s existing data.

Go to Settings → Configurations → General → Agent Configurations → Endpoint Administration Cleanup. Enable the Periodic duplicate cleanup and select either One-time cleanup or define a periodic cleanup to run according to the Host Name, Host IP Address, and/or MAC Address fields at a specific time interval.

Endpoint actions

The right-click pivot menu displays the actions you can perform on your endpoints. For more information about these actions, see the topics in this section, and the topics under Manage endpoint protection.

Note

For the Include endpoints from auto upgrade action, you cannot enable auto upgrade for Mobile, VDI, and TS installations.

All Endpoints reference information

The following table describes both the default and additional optional fields that you can view in the All Endpoints table and lists. Clicking on a row in the All Endpoints table opens a detailed view of the endpoint.

Field
Description

Active Directory

Active Directory Groups and Organizational Units to which the user belongs.

Assigned Extensions Policy

Policy related to extensions and devices connected to the endpoint.

Assigned Prevention Policy

Policy assigned to the endpoint.

Agent Version

Agent version that is installed on the endpoint.

Auto Upgrade Status

When Cortex XDR agent auto upgrades are enabled, this field indicates the action status.

Note

If an endpoint is excluded, the auto upgrade profile configuration is not available.

If you exclude the endpoint from auto upgrade while the auto upgrade action is In progress, the ongoing upgrade will still take place.

Cloud Account ID

Unique identifier for the cloud account that owns or manages the workload.

Cloud Info

IBM and Alibaba Cloud metadata reported by the workload.

Cloud Instance ID

(Agent 8.9 and later) Unique identifier for the cloud instance hosting the workload.

Cloud Provider

(Agent 8.9 and later) Cloud service provider hosting the workload.

Cloud Region

(Agent 8.9 and later) Geographical region of the cloud infrastructure where the workload is hosted.

Cluster Name

(Agent 8.9 and later) Cluster name to which the workload belongs.

Content Auto Update

Whether automatic content updates are Enabled or Disabled for the endpoint in the agent settings profile.

Content Release Timestamp

Time and date of when the current content version was released.

Content Rollout Delay (days)

If you configured delayed content rollout, the number of days for delay is displayed here.

Content Version

Content update version used with the agent.

Disabled Capabilities

List of capabilities that were disabled on the endpoint. Options are Live Terminal, Script Execution, and File Retrieval.

You can disable these capabilities during agent installation on the endpoint or through Endpoint Administration. Disabling any of these actions is irreversible. If you later want to enable the action on the endpoint, you must uninstall the agent and install a new package on the endpoint.

Endpoint ID

Unique ID that identifies the endpoint.

Endpoint Name

Hostname of the endpoint. If the agent enables Pro features, this field also includes a PRO badge. For Android endpoints, the hostname comprises the <firstname><lastname> of the registered user, with a separating dash.

Endpoint Type

Type of endpoint.

Endpoint Version

Versions of the agent that runs on the endpoint.

First Seen

Date and time the agent first checked in (registered) with Cortex Cloud.

Group Names

Endpoint Groups to which the endpoint is a member, if applicable.

IP Address

Last known IPv4 address of the endpoint.

IPv6 Address

Last known IPv6 address of the endpoint.

Last Scan

Date and time of the last malware scan on endpoint.

MAC Address

Endpoint MAC address that corresponds to the IP address. Currently, this information is available only for IPv4 addresses.

Operating System

Name of the operating system.

OS Description

Operating system version name.

OS Type

Name of the operating system.

OS Version

Operating system version number.

Platform

Platform architecture.

Tags

Tags associated with the endpoint.

Tags created in the agent are displayed with a shield icon.

User

User that was last logged into the endpoint. On Android endpoints, the Cortex Cloud tenant identifies the user from the email prefix specified during app activation.

Last updated

Was this helpful?