Activate the CSV Collector - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM Administrator Guide

Product
Cortex XSIAM
Creation date
2024-02-26
Last date published
2024-04-18
Category
Administrator Guide
Abstract

Learn more about activating the broker VM with a CSV Collector applet.

The Broker VM provides a CSV Collector applet that enables you to monitor and collect CSV (comma-separated values) log files from a shared Windows directory directly to your log repository for query and visualization purposes. After you activate the CSV Collector applet on a Broker VM in your network, you can ingest CSV files as datasets by defining the list of folders mounted to the Broker VM and setting the list of CSV files to monitor and upload to Cortex XSIAM using a username and password.

Danger

Before activating the CSV Collector applet, review and perform the following:

  • Configure the Broker VM.

  • Ensure that you share the applicable CSV files.

  • Know the complete file path for the Windows directory.

  1. Select SettingsConfigurationsData BrokerBroker VMs.

  2. In either the Brokers tab or the Clusters tab, locate your Broker VM.

  3. You can either right-click the Broker VM and select Add AppCSV Collector, or in the APPS column, left-click AddCSV Collector.

  4. Configure your CSV Collector by defining the list of folders mounted to the Broker VM and specifying the list of CSV files to monitor and upload to Cortex XSIAM. You must also specify a username and password.

  5. Activate the CSV Collector applet.

    After a successful activation, the APPS field displays CSV with a green dot indicating a successful connection.

    Note

    The CSV Collector checks for new CSV files every 10 minutes.

  6. (Optional) To view metrics about the CSV Collector, left-click the CSV connection in the APPS field for your Broker VM.

    Cortex XSIAM displays Resources, including the amount of CPU, Memory, and Disk space the applet is using.

  7. Manage the CSV Collector.

    After you activate the CSV Collector, you can make additional changes as needed. To modify a configuration, left-click the CSV connection in the APPS column to display the CSV settings, and select:

    • Configure to redefine the CSV Collector configurations.

    • Deactivate to disable the CSV Collector.

    You can also Ingest CSV Files as Datasets.