After you have configured and registered your
broker VM, activate your Syslog collector application. Activating
the Syslog collector requires a Cortex XDR Pro per TB license.
Syslog Collector allows you to collect syslog logs from within your
network by listening to specific ports.
In Cortex XDR, navigate to
and locate your broker VM.
. You can define the Syslog
collector to listen to multiple ports and select the relevant Syslog
format for each of the ports.
are not permitted to configure port number between 0-1024 and 63000-65000,
except for 514. In addition, 4369, 5671, 5672, 5986, 6379, 8000,
8888, 9100, 15672, 25672 are also not allowed.
After a successful activation, the
Syslog Collector - Active
to view the following applet metrics:
the applet is connected to Cortex XDR.
—Number of logs received and sent by the applet
per second over the last 24 hours. If the number of incoming logs
received is larger than the number of logs sent, it could indicate
a connectivity issue.
—Displays the amount of
space the applet is using.
Manage the Syslog Collector.
After the syslog collector has been activated, right-click
you broker VM and select: