Activate Files and Folders Collector - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM Documentation

Product
Cortex XSIAM
Creation date
2024-03-06
Last date published
2024-10-13
Category
Administrator Guide
Abstract

Learn more about activating a Broker VM with a Files and Folders Collector applet.

The Broker VM provides a Files and Folders Collector applet that enables you to monitor and collect logs from files and folders in a network share for a Windows or Linux directory, directly to your log repository for query and visualization purposes. The Files and Folders collector applet only starts to collect files that are more than 256 bytes and is only supported with a Network File System version 4 (NFSv4). After you activate the Files and Folders Collector applet, you can collect files as datasets (<Vendor>_<Product>_raw) by defining the following.

  • Details of the folder path on the network share containing the files that you want to monitor and upload to Cortex XSIAM.

  • Settings related to the list of files to monitor and upload to Cortex XSIAM, where the log format is either Raw (default), JSON, CSV, TSV, PSV, CEF, LEEF, Corelight, or Cisco.

Note

Cortex XSIAM only supports ingestion of files encoded in UTF-8 format.

Danger

Before activating the Files and Folders Collector applet, review and perform the following:

  • Set up and configure Broker VM.

  • Know the complete path to the files and folders that you want Cortex XSIAM to monitor.

  • Ensure that the user permissions for the network share include the ability to rename and delete files in the folder that you want to configure collection.

  1. Select SettingsConfigurationsData BrokerBroker VMs.

  2. Do one of the following:

    • On the Brokers tab, find the Broker VM, and in the APPS column, left-click AddFiles and Folder Collector.

    • On the Clusters tab, find the Broker VM, and in the APPS column, left-click AddFiles and Folder Collector.

  3. Configure the Files and Folder Collector settings.

  4. (Optional) Click Add Connection to define another Files and Folders connection for collecting logs from files and folders in a shared resource.

  5. (Optional) Other available options.

    As needed, you can return to your Files and Folders Collector settings to manage your connections. Here are the actions available to you:

    • Edit the connection name by hovering over the default Collection name, and selecting the edit icon to edit the text.

    • Disable/Enable a connection by hovering over the top area of the connection section, on the opposite side of the connection name, and selecting the applicable button.

    • Delete a connection by hovering over the top area of the connection section, on the opposite side of the connection name, and selecting the delete icon. You can only delete a connection when you have more than one connection configured. Otherwise, this icon is not displayed.

  6. Activate the Files and Folders Collector applet.

    After a successful activation, the APPS field displays File with a green dot indicating a successful connection.

  7. (Optional) To view metrics about the Files and Folders, left-click the File connection in the APPS field for your Broker VM.

    Cortex XSIAM displays Resources, including the amount of CPU, Memory, and Disk space the applet is using.

  8. Manage the Files and Folders Collector.

    After you activate the Files and Folders Collector, you can make additional changes as needed. To modify a configuration, left-click the File connection in the APPS column to display the Files and Folder Collector settings, and select:

    • Configure to redefine the Files and Folders Collector configurations.

    • Deactivate to disable the Files and Folders Collector.