You can set an application-specific proxy for a Cortex XDR Collector without affecting the communication of other applications on the collector machine.
Notice
Requires the Data Collection add-on.
In environments where Cortex XDR Collectors communicate with the Cortex Cloud server through a wide system proxy, you can set an application-specific proxy for the XDR Collector without affecting the communication of other applications on the collector machine. You can set the proxy after installation from the XDR Collectors Administration page in Cortex Cloud as described in this topic. You can assign up to ten different proxy servers per XDR Collector. The proxy server that the agent uses is selected randomly and with equal probability. If the communication between the XDR Collector and the Cortex Cloud server through the app-specific proxies fails, the XDR Collector resumes communication through the system-wide proxy defined on the collector machine. If that fails as well, the XDR Collector resumes communication with Cortex Cloud directly.
In Cortex Cloud, select → → → .
If needed, filter the list of on-premise collector machines.
Set an agent proxy.
Select the row of the on-premises collector machine that you want to set as a proxy.
Right-click the collector machine, and select Set Collector proxy.
You can assign up to ten different proxies per XDR Collector. For each proxy, specify the IP address and port number. After each Proxy Address and Port added, select
to add the values to a list underneath these fields. Broker VMs in the same tenant can also be configured to use as a proxy, by enabling Agent proxy in the Broker VMs.
Click Set when you’re done.
If necessary later, you can disable the collector proxy by selecting Disable Collector Proxy from the right-click menu.
When you disable the proxy configuration, all proxies associated with that XDR Collector are removed. The XDR Collector resumes communication with the Cortex Cloud server through the wide-system proxy if defined; otherwise, if a wide-system is not defined, the XDR Collector resumes communicating directly with the Cortex Cloud server. If neither a wide-system proxy nor direct communication exist and you disable the proxy, the XDR Collector disconnects from Cortex Cloud.