For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex Cloud Runtime

Upgrade Cortex XDR agents

You can upgrade the Cortex XDR agent software by using the appropriate method for the endpoint operating system.

After you install the Cortex XDR agent and the agent registers with Cortex Cloud, you can upgrade the Cortex XDR agent software using a method supported by the endpoint platform:

  • Android: Upgrade the app directly from the Google Play Store or push the app to your endpoints from an endpoint management system such as AirWatch.

  • iOS: Upgrade the app directly from the Apple App Store (agent version 8.6 or later), or push the app to your endpoints from an endpoint management system.

  • Windows, Mac, or Linux: Create new installation packages and push the Cortex XDR agent package to up to 5,000 endpoints from Cortex Cloud.

Upgrades are supported using actions that you can initiate from the Action Center or from All Endpoints as described in this workflow.

How to upgrade Cortex XDR agent software

1

Create an agent installation package for each operating system version for which you want to upgrade the Cortex XDR agent.

Note the installation package names.

2

Select Inventory → Endpoints → All Endpoints.

If needed, filter the list of endpoints. To reduce the number of results, use the endpoint name search and filters Filters at the top of the page.

3

Select the endpoints you want to upgrade.

You can also select endpoints running different operating systems to upgrade the agents at the same time.

4

Right-click your selection and select Endpoint Control → Upgrade Agent Version.

For each platform, select the name of the installation package you want to push to the selected endpoints.

You can install the Cortex XDR agent on Linux endpoints using a package manager. If you do not want to use the package manager, clear the option Upgrade to installation by package manager.

When you upgrade an agent on a Linux endpoint that is not using a package manager, Cortex Cloud upgrades the installation process by default according to the endpoint Linux distribution.

Note:

The Cortex XDR agent keeps the name of the original installation package after every upgrade.

5

Upgrade.

Cortex Cloud distributes the installation package to the selected endpoints at the next heartbeat communication with the agent. To monitor the status of the upgrades, go to Investigation & Response → Response → Action Center.

From the Action Center you can also view additional information about the upgrade; right-click the action and select Additional data. Whilst the upgrade status is Pending, it can be canceled, right-click the action and select Cancel Agent Upgrade.

Last updated

Was this helpful?