Activate the Syslog Collector

After you have configured and registered your broker VM, activate your Syslog collector application. Activating the Syslog collector requires a Cortex XDR Pro per TB license.
The Syslog Collector allows you to collect syslog logs from within your network by listening to specific ports.
  1. In Cortex XDR, navigate to
    gear.png
    Settings
    Broker
    VMs
    table and locate your broker VM.
  2. Right-click, select
    Syslog Collector
    Activate
    .
  3. In the
    Configure Syslog
    window, define the
    Port
    ,
    Protocol
    , and
    Syslog Format
    . You can define the Syslog collector to listen to multiple ports and select the relevant Syslog format for each of the ports.
    activate-syslog-applet.png
    You are not permitted to configure port number between 0-1024 and 63000-65000, except for 514. In addition, 4369, 5671, 5672, 5986, 6379, 8000, 8888, 9100, 15672, 25672 are also not allowed.
  4. Activate
    your configurations.
    After a successful activation, the
    Apps
    field displays the
    Syslog Collector - Active
    .
  5. In the
    Apps
    filed, select
    Syslog Collector
    to view the following applet metrics:
    • Connectivity Status
      —Whether the applet is connected to Cortex XDR.
    • Logs Received
      and
      Logs Sent
      —Number of logs received and sent by the applet per second over the last 24 hours. If the number of incoming logs received is larger than the number of logs sent, it could indicate a connectivity issue.
    • Resources
      —Displays the amount of
      CPU
      ,
      Memory
      , and
      Disk
      space the applet is using.
    syslog-collector-metrics.png
  6. Manage the Syslog Collector.
    After the syslog collector has been activated, right-click you broker VM and select:
    • Syslog Collector
      Configure
      to redefine the syslog configurations.
    • Syslog Collector
      Deactivate
      to disable the syslog collector.

Recommended For You