Activate Files and Folders Collector - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR Documentation

Product
Cortex XDR
Creation date
2024-03-06
Last date published
2024-11-07
Category
Administrator Guide
Abstract

Learn more about activating a Broker VM with a Files and Folders Collector applet.

Notice

Ingesting logs and data from external sources requires a Cortex XDR Pro per GB license.

The Broker VM provides a Files and Folders Collector applet that enables you to monitor and collect logs from files and folders in a network share for a Windows or Linux directory, directly to your log repository for query and visualization purposes. The Files and Folders collector applet only starts to collect files that are more than 256 bytes and is only supported with a Network File System version 4 (NFSv4). After you activate the Files and Folders Collector applet, you can collect files as datasets (<Vendor>_<Product>_raw) by defining the following.

  • Details of the folder path on the network share containing the files that you want to monitor and upload to Cortex XDR.

  • Settings related to the list of files to monitor and upload to Cortex XDR, where the log format is either Raw (default), JSON, CSV, TSV, PSV, CEF, LEEF, Corelight, or Cisco.

Note

Cortex XDR only supports ingestion of files encoded in UTF-8 format.

Danger

Before activating the Files and Folders Collector applet, review and perform the following:

  • Set up and configure Broker VM.

  • Know the complete path to the files and folders that you want Cortex XDR to monitor.

  • Ensure that the user permissions for the network share include the ability to rename and delete files in the folder that you want to configure collection.

  1. Select SettingsConfigurationsData BrokerBroker VMs.

  2. Do one of the following:

    • On the Brokers tab, find the Broker VM, and in the APPS column, left-click AddFiles and Folder Collector.

    • On the Clusters tab, find the Broker VM, and in the APPS column, left-click AddFiles and Folder Collector.

  3. Configure the Files and Folder Collector settings.

  4. (Optional) Click Add Connection to define another Files and Folders connection for collecting logs from files and folders in a shared resource.

  5. (Optional) Other available options.

    As needed, you can return to your Files and Folders Collector settings to manage your connections. Here are the actions available to you:

    • Edit the connection name by hovering over the default Collection name, and selecting the edit icon to edit the text.

    • Disable/Enable a connection by hovering over the top area of the connection section, on the opposite side of the connection name, and selecting the applicable button.

    • Delete a connection by hovering over the top area of the connection section, on the opposite side of the connection name, and selecting the delete icon. You can only delete a connection when you have more than one connection configured. Otherwise, this icon is not displayed.

  6. Activate the Files and Folders Collector applet.

    After a successful activation, the APPS field displays File with a green dot indicating a successful connection.

  7. (Optional) To view metrics about the Files and Folders, left-click the File connection in the APPS field for your Broker VM.

    Cortex XDR displays Resources, including the amount of CPU, Memory, and Disk space the applet is using.

  8. Manage the Files and Folders Collector.

    After you activate the Files and Folders Collector, you can make additional changes as needed. To modify a configuration, left-click the File connection in the APPS column to display the Files and Folder Collector settings, and select:

    • Configure to redefine the Files and Folders Collector configurations.

    • Deactivate to disable the Files and Folders Collector.