Activate the Files and Folders Collector - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR Pro Administrator Guide

Product
Cortex XDR
License
Pro
Creation date
2023-10-31
Last date published
2024-03-27
Category
Administrator Guide
Abstract

Learn more about activating a broker VM with a Files and Folders Collector applet.

Notice

Ingesting Logs and Data from external sources requires a Cortex XDR Pro per GB license.

The Broker VM provides a Files and Folders Collector applet that enables you to monitor and collect logs from files and folders in a network share for a Windows or Linux directory, directly to your log repository for query and visualization purposes. The Files and Folders collector applet only starts to collect files that are more than 256 bytes and is only supported with a Network File System version 4 (NFSv4). After you activate the Files and Folders Collector applet, you can collect files as datasets (<Vendor>_<Product>_raw) by defining the following.

  • Details of the folder path on the network share containing the files that you want to monitor and upload to Cortex XDR.

  • Settings related to the list of files to monitor and upload to Cortex XDR, where the log format is either Raw (default), JSON, CSV, TSV, PSV, CEF, LEEF, Corelight, or Cisco.

Danger

Before activating the Files and Folders Collector applet, review and perform the following:

  • Configure the Broker VM.

  • Know the complete path to the files and folders that you want Cortex XDR to monitor.

  • Ensure that the user permissions for the network share include the ability to rename and delete files in the folder that you want to configure collection.

  1. Select SettingsConfigurationsData BrokerBroker VMs.

  2. In either the Brokers tab or the Clusters tab, locate your Broker VM.

  3. You can either right-click the Broker VM and select Add AppFiles and Folder Collector, or in the APPS column, left-click AddFiles and Folder Collector.

  4. Configure the Files and Folders Collector settings.

  5. (optional) Add Connection to define another Files and Folders connection for collecting logs from files and folders in a shared resource.

  6. (optional) Other available options.

    As needed, you can return to your Files and Folders Collector settings to manage your connections. Here are the actions available to you.

    • Edit the connection name by hovering over the default Collection name, and selecting the edit icon to edit the text.

    • Disable/Enable a connection by hovering over the top area of the connection section, on the opposite side of the connection name, and selecting the applicable button.

    • Delete a connection by hovering over the top area of the connection section, on the opposite side of the connection name, and selecting the delete icon. You can only delete a connection when you have more than one connection configured. Otherwise, this icon is not displayed.

  7. Activate the Files and Folders Collector applet.

    After a successful activation, the APPS field displays File with a green dot indicating a successful connection.

  8. (Optional) To view metrics about the Files and Folders, left-click the File connection in the APPS field for your Broker VM.

    Cortex XDR displays Resources, including the amount of CPU, Memory, and Disk space the applet is using.

  9. Manage the Files and Folders Collector.

    After you activate the Files and Folders Collector, you can make additional changes as needed. To modify a configuration, left-click the File connection in the APPS column to display the Files and Folder Collector settings, and select:

    • Configure to redefine the Files and Folders Collector configurations.

    • Deactivate to disable the Files and Folders Collector.

    You can also Ingest Logs in a Network Share as Datasets.