Retrieve files from an endpoint
Retrieve files from an endpoint for investigation.
During an investigation, you can retrieve files from one or more endpoints by initiating a files retrieval request. For each file retrieval request, Cortex Cloud supports up to:
20 files
500MB in total size
10 different endpoints
The request instructs the agent to locate the files on the endpoint and upload them to Cortex Cloud. The agent collects all requested files into one archive and includes a log in JSON format containing additional status information. When the files are successfully uploaded, you can download them from the Action Center.
How to retrieve files from an endpoint
Go to Investigation & Response → Response → Action Center → New Action.
Select Files Retrieval.
Click Next.
Select the target endpoints (up to 10) from which you want to retrieve files and click Next.
Review the action summary and click Done.
To track the status of a file retrieval action, return to the Action Center. Cortex Cloud retains retrieved files for up to 30 days.
If at any time you need to cancel the action, right-click, and select Cancel for pending endpoint. You can cancel the retrieval action only if the endpoint is still in Pending status and no files have been retrieved from it yet. The cancellation does not affect endpoints that are already in the process of retrieving files.
To view additional data and download the retrieved files, right-click the action and select Additional data.
This view displays all endpoints from which files are being retrieved, including their IP Address, Status, and Additional Data such as error messages of names of files that were not retrieved.
Disable file retrieval
If you want to prevent Cortex Cloud from retrieving files from an endpoint running the agent, you can disable this capability during agent installation or later on from the All Endpoints page. Disabling script execution is irreversible. If you later want to re-enable this capability on the endpoint, you must re-install the agent. See the XDR agent administrator’s guide for more information.
Last updated
Was this helpful?
