Activate the Syslog Collector - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR Pro Administrator Guide

Product
Cortex XDR
License
Pro
Creation date
2023-10-31
Last date published
2024-03-27
Category
Administrator Guide
Abstract

Learn how to set up and activate the Syslog Collector applet on a Broker VM within your network.

Notice

Ingesting Logs and Data from external sources requires a Cortex XDR Pro per GB license.

To receive Syslog data from an external source, you must first set up the Syslog Collector applet on a Broker VM within your network. The Syslog Collector supports a log ingestion rate of 90,000 logs per second (lps) with the recommended Broker VM setup.

To increase the log ingestion rate, you can add additional CPUs to the Broker VM. The Syslog Collector listens for logs on specific ports and from any or specific IP addresses.

Perform the following procedures in the order listed below.

  1. Select SettingsConfigurationsData BrokerBroker VMs.

  2. In either the Brokers tab or the Clusters tab, locate your Broker VM.

  3. You can either right-click the Broker VM and select Add AppSyslog Collector, or in the APPS column, left-click AddSyslog Collector.

Cortex XDR supports multiple sources over a single port on a single Syslog Collector. The following options are available:

  • Edit the Optional Settings of the default PORT/PROTOCOL: 514/UDP. See Task 3.

    Note

    Once configured, you cannot change the Port/PROTOCOL. If you don’t want to use a data source, ensure to remove the data source from the list as explained in Task 5.

  • Add a new Syslog Collector data source. See Task 4.

  1. Right-click the 514/UDP PORT/PROTOCOL, and select Edit.

  2. Configure these Optional Settings:

    After each configuration, select blue-arrow.png to save the changes and then Done to update the Syslog Collector with your settings.

  1. Select Add New.

  2. Configure these mandatory General settings:

  3. Configure these Optional Settings:

    After each configuration, select blue-arrow.png to save the changes and then Done to update the Syslog Collector with your settings.

  • To remove a Syslog Collector data source, right-click the row after the Port/Protocol entry, and select Remove.

  • To prioritize the order of the Syslog formats listed for the protocols and ports configured, drag and drop the rows to the order you require.

Click Save. After a successful activation, the APPS field displays Syslog with a green dot indicating a successful connection.

To view metrics about the Syslog Collector, left-click the Syslog connection in the APPS field for your Broker VM. Cortex XDR displays the following information:

After the Syslog Collector has been activated, you can make additional changes to your configuration if needed. To modify a configuration, left-click the Syslog connection in the APPS column to display the Syslog Collector settings, and select:

  • Configure to redefine the Syslog configurations.

  • Deactivate to disable the Syslog Collector.