> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/monitor-agent-activity.md).

# Monitor agent activity

The Cortex XDR agent logs entries for events that are monitored by the Cortex XDR agent and hourly reports the logs back to Cortex XDR. Cortex XDR stores the logs for 365 days. To view the Cortex XDR agent logs, select Settings → Agent Audit Logs.

To ensure you and your colleagues stay informed about agent activity, you can configure notification forwarding to forward your Agent Audit log to an email distribution list, Syslog server, or Slack channel. See the Configure Notifications Forwarding section.

You can customize your view of the logs by adding or removing filters to the Agent Audit Logs table. You can also filter the page result to narrow down your search. The following table describes the default and optional fields that you can view in the Cortex XDR Agents Audit Logs table:

| Field             | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ----------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Category          | <p>The XDR agent logs these endpoint events using one of the following categories:</p><ul><li>Audit: Successful changes to the agent indicating correct behavior.</li><li>Monitoring: Unsuccessful changes to the agent that may require administrator intervention.</li><li>Status: Indication of the agent status.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Description       | Log message that describes the action.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Domain            | Domain to which the endpoint belongs.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Endpoint ID       | A unique ID assigned by the XDR agent.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Endpoint Name     | Endpoint hostname.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Received Time     | Date and time when the action was received by the agent and reported back to Cortex XDR.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Result            | The result of the action (Success, Fail, or N/A)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Severity          | <p>Severity associated with the log:</p><ul><li>Critical</li><li>High</li><li>Medium</li><li>Low</li><li>Informational</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Type and Sub-Type | <p>Additional classification of agent log (Type and Sub-Type):</p><ul><li><p>Installation:</p><ul><li>Install</li><li>Uninstall</li><li>Upgrade</li></ul></li><li><p>Policy change:</p><ul><li>Local Configuration Change</li><li>Content Update</li><li>Policy Update</li><li>Process Exception</li><li>Hash Exception</li></ul></li><li><p>Agent service:</p><ul><li>Service start (reported only when the agent fails to start and the RESULT is <code>Fail</code>)</li><li>Service stopped</li><li>Anti-Tampering (reported when anti-tamper protection is disabled locally on an agent)</li></ul></li><li><p>Agent modules:</p><ul><li>Module initialization</li><li>Local analysis module</li><li>Local analysis feature extraction</li></ul></li><li><p>Agent status:</p><ul><li>Fully protected</li><li>OS incompatible</li><li>Software incompatible</li><li>Kernel driver initialization</li><li>Kernel extension initialization</li><li>Proxy communication</li><li>Quota exceeded (reported when old prevention data is being deleted from the endpoint)</li><li>Minimal content</li></ul></li><li><p>Action:</p><ul><li>Endpoint Token</li><li>Scan</li><li>File retrieval</li><li>Terminate process</li><li>Isolate</li><li>Cancel isolation</li><li>Payload execution</li><li>Quarantine</li><li>Restore</li><li>Block IP address</li><li>Unblock IP address</li><li>Tagging</li></ul></li></ul> |
| Timestamp         | Date and time when the action occurred.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| XDR Agent Version | The version of the XDR agent running on the endpoint.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/monitor-agent-activity.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
