View Broker VM Details - Administrator Guide - Cortex XDR - Cortex XSIAM - Cortex - Security Operations

Cortex XDR Pro Administrator Guide

Product
Cortex XDR
License
Pro
Creation date
2023-03-30
Last date published
2023-03-30

In Cortex XDR , select SettingsConfigurationsData BrokerBroker VMs to view detailed information regarding your registered broker VMs.

The Broker VMs table enables you to monitor and mange your broker VM and applet connectivity status, version management, device details, and usage metrics.

The following table describes both the default fields and additional optional fields that you can add to the alerts table using the column manager and lists the fields in alphabetical order.

Field

Description

Status Indicator (

alert-status.png

)

Identifies in the following columns:

  • DEVICE NAME—Whether the broker machine is registered and connected to Cortex XDR.

  • VERSION—Whether the broker VM is running the latest version.

  • APPS—Whether the available applications are connected to Cortex XDR.

Colors depict the following statuses:

  • Black—Disconnected to Cortex XDR

  • Red - Disconnected from Cortex XDR

  • Orange—Past Version

  • Green—Connected, Current Version

check-box.png

Check box to select one or more broker devices on which to perform actions.

ALL interfaces

All IP addresses of the different interfaces on the device.

APPS

List of active or inactive applets and the connectivity status for each.

CPU USAGE

CPU usage of the broker device in percentage synced every 5 minutes.

CONFIGURATION STATUS

Broker VM configuration status. Status is defined by the following according to changes made to any of the broker VM configurations.

  • up to date—Broker VM configuration changes made through the Cortex XDR console have been applied.

    in progress—Broker VM configuration changes made through the Cortex XDR console are being applied.

    submitted—Broker VM configuration changes made through the Cortex XDR console have reached the broker machine and awaiting implementation.

    failed—Broker VM configuration changes made through the Cortex XDR console have failed. Need to open a Palo Alto Networks support ticket.

DEVICE ID

Device ID allocated to the broker machine by Cortex XDR after registration.

DEVICE NAME

Same as the Device ID.

A expired-broker.pngicon notifies of an expired broker. To reconnect, generate a new token and re-register your broker as described in steps 1 through 7 of Configure the Broker VM. Once registered, all previous broker configurations are reinstated.

DISK USAGE

Disk usage of the broker in portion of computer storage that is currently in use.

Notification about low disk space appear in the Notification Center.

EXTERNAL INTERFACE

The IP interface the broker is using to communicate with the server.

For AWS and Azure cloud environments, the field displays the Internal IP value.

LAST SEEN

Indicates when the broker VM was last seen on the network.

MEMORY USAGE

Memory usage of the broker device in percentage synced every 5 minutes.

STATUS

Connection status of the broker device. Status is defined by either Connected or Disconnected.

Disconnected broker devices do not display CPU Usage, Memory Usage, and Disk Usage information.

Notifications about the broker VM losing connectivity to Cortex XDR appear in the Notification Center.

UPGRADE TIME

Timestamp of when the broker device was upgraded.

VERSION

Version number of the broker device. If the status indicator is not green, then the broker is not running the latest version.

Notifications about the available new broker VM version appear in the Notification Center.