Agent Health Monitoring

Track endpoint availability, telemetry gaps, and agent health before they affect security visibility.

XDRShield Agent Health Monitoring helps operators understand whether endpoint agents are reporting as expected, where telemetry gaps exist, and which systems need attention before detection, inventory, policy, or response decisions rely on stale data.

Availability historyDowntime gap reviewHealth-state filters
Why it matters

Agent health is the reliability layer behind every endpoint security workflow.

Detection, inventory, policy sync, alert triage, and response workflows all depend on endpoint agents reporting consistently. Agent Health Monitoring gives operations teams a practical view of reporting continuity, recent gaps, and endpoints that need follow-up.

01

Protect evidence freshnessIdentify agents with missing or delayed telemetry before analysts depend on incomplete endpoint evidence.
02

Prioritize unavailable endpointsFilter by current state, last 24-hour availability, and downtime patterns to focus operational work.
03

Validate policy and sync readinessUse health and last-report context before treating rule assignments or policy coverage as complete.
04

Support MSP operationsReview health across tenant-scoped endpoints while keeping customer-specific follow-up organized.
Operating model

Review availability timelines, downtime thresholds, and health states in one operational view.

The health view compares expected telemetry continuity with observed reporting. Green availability segments show normal reporting; red downtime segments show gaps longer than the configured threshold. Operators can adjust thresholds for environments with different reporting patterns, then filter to healthy, drifting, or unavailable agents.

  • Availability history shows each agent as a horizontal timeline for fast gap recognition.
  • Downtime is inferred from missing metric samples beyond the selected graph-gap threshold.
  • State filters combine online status, freshness windows, and last 24-hour availability.
  • Search and scoped filtering help teams isolate endpoints that need agent, network, or policy attention.
XDRShield architecture connecting endpoint visibility, investigation, response, and operations
Feature capabilities

What XDRShield Agent Health Monitoring helps teams do.

Each capability helps administrators distinguish normal reporting delays from operational risk, triage unhealthy endpoints, and keep endpoint visibility trustworthy.

Downtime gap thresholding

Adjust graph-gap thresholds to suit standard or slower-reporting environments without misreading expected delays as outages.

Explore Downtime gap thresholding →

Health-state filtering

Filter by healthy, drifting, or unavailable state using current online status, freshness, and recent availability.

Explore Health-state filtering →

Last-seen validation

Check whether an endpoint recently reported before trusting alert, inventory, policy, or response context.

Explore Last-seen validation →

Policy readiness checks

Use health status before assigning or troubleshooting policies so missing sync is not mistaken for policy failure.

Explore Policy readiness checks →

Operating workflow

From health signal to endpoint follow-up.

A repeatable agent-health workflow helps teams move from broad visibility into targeted remediation without overreacting to normal reporting variation.

Select the right scope

Choose tenant, customer, platform, or endpoint filters before reviewing health so the queue reflects the operational group you own.

Review current state

Check online status, freshness, and last-reported telemetry to confirm whether the endpoint is available now.

Inspect availability history

Use the timeline to identify repeated gaps, long outages, or recent downtime that may affect evidence quality.

Tune threshold context

Apply an appropriate downtime threshold for the environment so slower reporting patterns are interpreted correctly.

Prioritize follow-up

Start with unavailable or repeatedly drifting agents that affect critical systems, active policies, or open investigations.

Validate recovery

Refresh health and last-sync context after remediation to confirm the agent has returned to expected reporting.

Common use cases

Where Agent Health Monitoring helps most.

Use health monitoring when endpoint reporting reliability affects detection coverage, operational SLAs, policy rollout, or customer support.

Coverage assurance

Confirm agents are reporting before relying on file, registry, process, URL, AV, IOC, inventory, or vulnerability evidence.

Downtime analysis

Identify repeated or extended telemetry gaps that may indicate endpoint shutdown, network blockage, or agent service issues.

Policy rollout validation

Check health and sync status before investigating why a policy, rule, or assignment does not appear to be active.

Incident investigation support

Validate whether an endpoint was reporting during the incident window before interpreting missing evidence.

Service review reporting

Use availability history as operational evidence for MSP customer reviews and internal uptime follow-up.

Multi-tenant operations

Triage unhealthy agents by customer or workspace so service-provider teams can keep ownership clear.

Health-state reference

Understand the operational meaning of common health signals.

This comparison helps teams decide whether to watch, investigate, or remediate an endpoint based on reporting behavior.

Area What it means How teams use it
Available The agent reported telemetry within the expected heartbeat/freshness window. Use as normal monitoring context, while still checking policy sync for new assignments.
Drifting or intermittent The agent has recent telemetry but shows gaps or reduced availability over the selected period. Review network stability, endpoint sleep/offline patterns, service state, and threshold selection.
Unavailable The agent has not reported within the expected freshness window or has extended downtime. Prioritize remediation when the endpoint is business-critical or part of an active investigation.
Stale evidence risk Security, inventory, or policy data may not represent the current endpoint state. Validate health before making response or compliance decisions from old telemetry.
Operational use

Agent health for security and operations teams.

The same health data supports different decisions across SOC, IT, and service-provider workflows.

For SOC and investigation teams

Use agent health to validate whether missing evidence is meaningful during alert triage, hunts, and case timelines.

  • Check if an endpoint was reporting during the incident window.
  • Avoid assuming no telemetry means no suspicious activity.
  • Escalate unavailable endpoints that affect active cases.

Explore investigation workflows →

For IT and MSP operations

Use agent health to maintain endpoint coverage, troubleshoot reporting gaps, and support customer-facing service reviews.

  • Prioritize unavailable agents by tenant, platform, and criticality.
  • Validate policy deployment and sync readiness.
  • Use availability history for operational review and follow-up.

Explore agent management →

Questions buyers ask

Agent Health Monitoring FAQs.

What is Agent Health Monitoring in XDRShield?

Agent Health Monitoring shows endpoint agent availability, telemetry freshness, downtime gaps, and health-state filters so teams can identify endpoints that are not reporting reliably.

How is downtime identified?

Downtime is inferred when expected telemetry samples are missing for longer than the configured graph-gap threshold. Teams can choose a threshold that matches normal reporting behavior for the environment.

Why does agent health matter for security operations?

Alerts, events, inventory, policies, and response decisions depend on current endpoint telemetry. If an agent is stale or unavailable, security evidence may be incomplete.

Can MSP teams review agent health by customer?

Yes. Agent health review is designed for tenant-scoped operations so service-provider teams can focus follow-up by customer, workspace, platform, or endpoint set.

What should teams check before broad agent remediation?

Start with filters, last-seen time, availability history, endpoint state, network conditions, and policy sync context. Avoid treating every short reporting delay as a failure.

Keep endpoint evidence trustworthy

Find unhealthy agents before they create blind spots.

Use XDRShield Agent Health Monitoring to track reporting continuity, prioritize unhealthy endpoints, and keep detection and investigation evidence dependable.