You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Python筛选未安装Cortex XDR Agent的终端

筛选未安装Cortex XDR Agent的终端IP

要筛选出未安装Cortex XDR Agent的终端,不需要用正则去扒字符串,直接利用API返回的终端状态字段过滤就行。Cortex XDR的get_endpoints接口返回的每个终端对象里,自带agent_installed字段,值为False就代表该终端未安装Agent。

下面是修改后的代码,逻辑更清晰也更可靠:

import requests

# 替换为你的租户API Key和ID
api_id = 'x'
api_key = 'x'

headers = {
    "x-xdr-auth-id": str(api_id),
    "Authorization": api_key
}
parameters = {}

# 替换为你的租户API地址
api_url = "https://api-subdomain.xdr.region.paloaltonetworks.com/public_api/v1/endpoints/get_endpoints/"
res = requests.post(url=api_url, headers=headers, json=parameters)
res.raise_for_status()  # 捕获API请求失败的情况
endpoints_data = res.json()

# 遍历终端列表,筛选未安装Agent的设备
for endpoint in endpoints_data.get('reply', {}).get('endpoints', []):
    # 检查Agent安装状态,字段名以实际API返回为准,通常为agent_installed
    if not endpoint.get('agent_installed', True):
        # 提取公网IP(如果存在)
        public_ip = endpoint.get('public_ip')
        if public_ip:
            print(public_ip)
        # 提取本地IP列表(如果需要)
        local_ips = endpoint.get('local_ips', [])
        for ip in local_ips:
            print(ip)

关键改动说明

  • 去掉了冗余的正则匹配,直接解析API返回的JSON结构,避免把非IP的数字串误判为IP。
  • 加入res.raise_for_status(),能快速发现API请求失败的问题(比如密钥错误、地址不对)。
  • 用endpoint.get('agent_installed', True)做判断,默认设为True是为了防止字段缺失时误筛正常终端。
  • 分别处理公网IP和本地IP,你可以根据需求选择只输出其中一种。

内容的提问来源于stack exchange,提问作者Yield

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 00:50:29