Collect Broker VM Logs - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR Pro Administrator Guide

Product
Cortex XDR
License
Pro
Creation date
2024-07-16
Last date published
2024-12-02
Category
Administrator Guide
Retire_Doc
Retiring
Link_to_new_Doc
/r/Cortex-XDR/Cortex-XDR-Documentation
Abstract

Learn more about collecting logs from a Broker VM to review them as part of an investigation.

Cortex XDR enables you to collect your Broker VM logs directly from the Cortex XDR management console.

You can collect logs by either regenerating the most up-to-date logs and downloading them once they are ready, or downloading the current logs from the last creation date reflected in the TIMESTAMP.

  1. Select SettingsConfigurationsData BrokerBroker VMs to view the Broker VMs table in the Brokers tab.

  2. Locate your Broker VM, right-click and select one of these options depending on the type of logs you want to download.

    Logs are generated automatically, but can take up to a few minutes depending on the size of the logs.