Troubleshoot XDR Collectors errors - Learn more about how to verify the XDR Collectors application, connectivity, and processing errors and troubleshoot. - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM Documentation

Product
Cortex XSIAM
Creation date
2024-03-06
Last date published
2025-12-14
Category
Administrator Guide
Abstract

Learn more about how to verify the XDR Collectors application, connectivity, and processing errors and troubleshoot.

You can monitor the status of XDR Collectors from the XDR Collectors Administration page in the Status column. For all XDR Collectors, a status indicator icon indicates whether the collector is connected or has an error. The XDR Collectors provide information to help you troubleshoot by listing specific errors and warnings from the following types of XDR Collectors logs: Filesbeat, Winlogbeat, and XDRC. For a number of these errors and warnings, a recommended action is provided so that you can easily resolve the problem. In addition, you can always monitor your XDR Collectors application, connectivity, and processing errors for supported collectors using the Cortex Query Language (XQL) and the collection_auditing dataset, and by creating correlation rules to trigger collection security issues.