Endpoint Insights Collected by Prisma Agent
Focus
Focus
Prisma Agent

Endpoint Insights Collected by Prisma Agent

Table of Contents

Endpoint Insights Collected by Prisma Agent

Learn about the key data points collected by Prisma Agent for endpoint insights, which provide you with a comprehensive view of the endpoint and agent state for effective troubleshooting.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access (Managed by Panorama)
  • NGFW (Managed by Panorama)
  • Check the prerequisites for the deployment you're using
  • Minimum required Prisma Agent version: 25.4
  • macOS 14 and later or Windows 10 version 2024 and later desktop devices
  • Contact your Palo Alto Networks account representative to activate the Prisma Agent feature
Prisma Agent collects endpoint insights, a comprehensive set of data points to provide detailed visibility into endpoint and Prisma Agent performance. This data is crucial for effective troubleshooting and monitoring. Here's an overview of the key data categories and specific items collected:
Endpoint Insight CategoryData Collected
Device Details
(Endpoint OS version and agent version)
  • OS type
  • OS version
  • Agent version
  • Agent ID
  • User ID
Agent Details
(Deployment, configurations, and connection status)
  • Tunnel connection status
  • Tunnel type (IPSec, SSL)
  • Gateway selection method (manual or best available)
  • Gateway connect method (Always on, On-demand)
  • Gateway
  • Gateway type (internal or external)
  • Gateway session duration
  • PMTU
  • MTU optimized (true or false)
Troubleshooting Logs
(Agent debug logs and OS logs)
  • Agent log bundle (debug)
  • Windows event logs
  • Mac system logs
  • Mac network extension logs
This comprehensive data collection enables you to gain deep insights into endpoint behavior, network performance, and agent functionality, facilitating efficient troubleshooting and optimization of Prisma Agent deployments.