> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-windows/troubleshooting-resources-for-windows.md).

# Troubleshooting Resources for Windows

| Resource                                  | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| ----------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Services, Drivers, and Processes          | <p>Services:</p><ul><li><code>C:\Program Files\Palo Alto Networks\Traps\cyserver.exe</code></li><li><code>C:\Program Files\Palo Alto Networks\Cortex XDR Health Helper\xdrhealth.exe</code></li></ul><p>Drivers:</p><ul><li><code>C:\Program Files\Palo Alto Networks\Traps\cyverak.sys</code></li><li><code>C:\Program Files\Palo Alto Networks\Traps\cyvrmtgn.sys</code></li><li><code>C:\Program Files\Palo Alto Networks\Traps\cyvrfsfd.sys</code></li><li><code>C:\Program Files\Palo Alto Networks\Traps\tedrdrv.sys</code></li><li><code>C:\Program Files\Palo Alto Networks\Traps\tdevflt.sys</code></li><li><code>C:\Program Files\Palo Alto Networks\Traps\tedrpers-\<version>.sys</code></li><li><code>C:\Windows\System32\drivers\telam.sys</code></li></ul><p>Processes:</p><ul><li><code>C:\Program Files\Palo Alto Networks\Traps\CyveraConsole.exe</code></li><li><code>C:\Program Files\Palo Alto Networks\Traps\tlaworker.exe</code> (background process that is always running)</li><li><code>C:\Program Files\Palo Alto Networks\Traps\cytray.exe</code> (background process that is always running)</li><li><code>C:\Program Files\Palo Alto Networks\Traps\cytool.exe</code></li><li><code>C:\Program Files\Palo Alto Networks\Traps\cydump.exe</code></li><li><code>C:\Program Files\Palo Alto Networks\Traps\cyreport.exe</code></li><li><code>C:\Program Files\Palo Alto Networks\Traps\cyrprtui.exe</code></li><li><code>C:\Program Files (x86)\Palo Alto Networks\Traps\cyreport.exe</code></li><li><code>C:\Program Files (x86)\Palo Alto Networks\Traps\cyrprtui.exe</code></li></ul> |
| Cortex XDR installation log               | Specifies any errors encountered during installation of agent components. Use this log file when you need to troubleshoot installation issues. On Windows endpoints, the installer stores the log files in the `%temp%` or `C:\Users\<user_name>\AppData\Local\Temp` folder.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Cortex XDR agent service log              | <p>Indicates information, warnings, and errors related to the Cortex XDR. The Service log is located in the following folder on the endpoint:</p><ul><li><strong>Windows Vista or a later Windows OS</strong>—<code>%ProgramData%\Cyvera\Logs</code></li><li><strong>Windows XP</strong>—<code>C:\Document and Settings\All Users\Application Data\Cyvera\Logs</code></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Cortex XDR agent console log              | <p>Indicates information, warnings, and errors related to the agent console. The Console log is located in the following folder on the endpoint:</p><ul><li><strong>Windows Vista or a later Windows OS</strong>—<code>C:\Users\&#x3C;username>\AppData\Roaming\Cyvera</code></li><li><strong>Windows XP</strong>—<code>C:\Document and Settings\&#x3C;username>\Application Data\Cyvera\Logs</code></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Supervisor Command Line Tool (cytool.exe) | Allows you to manage agent features and perform advanced troubleshooting on the local endpoint from a command line interface. For more information, see [Cytool for Windows](/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-windows/troubleshooting-resources-for-windows/cytool-for-windows.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Unknown files for analysis                | <p>The agent stores unknown files to send to Cortex XDR in the <code>C:\ProgramData\Cyvera\Temp</code> folder. After Cortex XDR submits a file to WildFire, the agent deletes the file from the Temp folder.</p><p>In some cases, third-party Antivirus (AV) applications raise an alert for this folder. If this occurs, we recommend that you whitelist this folder in the third-party AV application.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Cortex XDR Health Helper                  | Improves the upgrade process of the Cortex XDR agent, which monitors the machine at startup and initiates an upgrade rollback in case of a failed upgrade. As upgrades have multiple re-tries, the next try works on the agent of its original version with no interference. The service only runs at startup and remains in pause mode during other times. To ensure this service is not removed, a periodic task would re-instate the process in case it was removed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/7.8-eol/cortex-xdr-agent-7.8-for-windows/troubleshooting-resources-for-windows.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
