Skip to main content

Cortex XDR disconnected endpoints

This Playbook is part of the Cortex XDR by Palo Alto Networks Pack.#

Supported versions

Supported Cortex XSOAR versions: 5.5.0 and later.

A Job to periodically query disconnected Cortex XDR endpoints with a provided last seen time range playbook input. The Collected data, if found will be generated to a CSV report, including a detailed list of the disconnected endpoints. The report will be sent to the recipient's provided email addresses in the playbook input. The playbook includes an incident type with a dedicated layout to visualize the collected data. To set the job correctly, you will need to.

  1. Create a new recurring job.
  2. Set the recurring schedule.
  3. Add a name.
  4. Set type to Cortex XDR disconnected endpoints.
  5. Set this playbook as the job playbook.

The scheduled run time and the timestamp relative date should be identical, If the job is recurring every 7 days, the time range should be 7 days as well.


This playbook uses the following sub-playbooks, integrations, and scripts.


This playbook does not use any sub-playbooks.


  • CortexXDRIR


  • SetGridField
  • Set
  • ExportToCSV


  • setIncident
  • send-mail
  • xdr-get-endpoints
  • closeInvestigation

Playbook Inputs#

NameDescriptionDefault ValueRequired
LastSeenStartDateLast seen start date, in relative timestamp - "1 Day" or "7 days"Optional
LastSeenEndDateLast seen end date, in relative timestamp - "1 Day" or "7 days"
For the current day use "0 days"
EmailEmail addresses to send the disconnected endpoints report.Optional
MessageBodyBody for the report email message.This message contains an automatically generated report by Cortex XSOAR, including a list of disconnected Cortex XDR endpoints.
Please investigate and remediate according to the organization's policy.

Playbook Outputs#

There are no outputs for this playbook.

Playbook Image#

Cortex XDR disconnected endpoints