Which common issue can result in sudden data ingestion loss for a data source that was previously successful?
Before initiating a malware scan action on a Linux workstation, an engineer notices that the Cortex XDR agent's operational status on the workstation is reporting as "partially protected." There have been no configuration changes made from the Cortex XSIAM server.
What are two explanations for this operational status? (Choose two.)
Based on the _raw_log and XQL query information below, what will be the result(s) of the temp_value?

Which action is required to enable use of a custom script in an alert layout?