Collect Broker VM Logs - Administrator Guide - Cortex XDR - Cortex XSIAM - Cortex - Security Operations

Cortex XDR Pro Administrator Guide

Product
Cortex XDR
License
Pro
Creation date
2023-03-30
Last date published
2023-03-30

Cortex XDR enables you to collect your broker VM logs directly from the Cortex XDR management console.

You can collect logs by either regenerating the most up-to-date logs and downloading them once they are ready, or downloading the current logs from the last creation date reflected in the TIMESTAMP.

  1. In Cortex XDR , select SettingsConfigurationsData BrokerBroker VMs to view the Broker VMs table.

  2. Locate your broker VM, right-click and select one of these options depending on the type of logs you want to download.

    • Generate New Logs— Regenerates the most up-to-date logs and downloads them once they are ready.

    • Download Logs (<TIMESTAMP>)—Downloads the logs from the last creation date reflected in the <TIMESTAMP> displayed. This option is only displayed when you’ve downloaded your logs previously using Generate New Logs.

    Logs are generated automatically, but can take up to a few minutes depending on the size of the logs.