如何使用Python筛选未安装Cortex XDR Agent的终端
筛选未安装Cortex XDR Agent的终端IP
要筛选出未安装Cortex XDR Agent的终端,不需要用正则去扒字符串,直接利用API返回的终端状态字段过滤就行。Cortex XDR的get_endpoints接口返回的每个终端对象里,自带agent_installed字段,值为False就代表该终端未安装Agent。
下面是修改后的代码,逻辑更清晰也更可靠:
import requests # 替换为你的租户API Key和ID api_id = 'x' api_key = 'x' headers = { "x-xdr-auth-id": str(api_id), "Authorization": api_key } parameters = {} # 替换为你的租户API地址 api_url = "https://api-subdomain.xdr.region.paloaltonetworks.com/public_api/v1/endpoints/get_endpoints/" res = requests.post(url=api_url, headers=headers, json=parameters) res.raise_for_status() # 捕获API请求失败的情况 endpoints_data = res.json() # 遍历终端列表,筛选未安装Agent的设备 for endpoint in endpoints_data.get('reply', {}).get('endpoints', []): # 检查Agent安装状态,字段名以实际API返回为准,通常为agent_installed if not endpoint.get('agent_installed', True): # 提取公网IP(如果存在) public_ip = endpoint.get('public_ip') if public_ip: print(public_ip) # 提取本地IP列表(如果需要) local_ips = endpoint.get('local_ips', []) for ip in local_ips: print(ip)
关键改动说明
- 去掉了冗余的正则匹配,直接解析API返回的JSON结构,避免把非IP的数字串误判为IP。
- 加入
res.raise_for_status(),能快速发现API请求失败的问题(比如密钥错误、地址不对)。 - 用
endpoint.get('agent_installed', True)做判断,默认设为True是为了防止字段缺失时误筛正常终端。 - 分别处理公网IP和本地IP,你可以根据需求选择只输出其中一种。
内容的提问来源于stack exchange,提问作者Yield
相关产品推荐
相关产品推荐

