The Cortex XDR agent logs these endpoint events using one of the following categories:
Log message that describes the action.
Domain to which the endpoint belongs.
Unique ID assigned by the Cortex XDR agent.
If the action or activity failed, this field indicates the identified cause.
Date and time when the action was received by the agent and reported back to Cortex XDR.
The result of the action (
Severity associated with the log:
Type and Sub-Type
Additional classification of agent log (Type and Sub-Type:
Date and time when the action occurred.
XDR Agent Version
Version of the Cortex XDR agent running on the endpoint.