You can monitor the activity of any Cortex XDR agent
that you manage.
Viewing agent audit logs requires either
Pro per Endpoint license.
XDR agent logs entries for events
that are monitored by the
and reports the logs back to
the logs for 365 days. To view the
agent logs, select
To ensure you and your colleagues stay informed about agent activity,
you can Configure Notification Forwarding to
forward your Agent Audit log to an email distribution list, Syslog
server, or Slack channel.