<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR Agent and system logs in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-and-system-logs/m-p/436443#M1084</link>
    <description>&lt;P&gt;Hi Tejasp04,&lt;/P&gt;&lt;P&gt;You can customize the amount of disk space that the cortex xdr agent uses to store logs and information about events. See in your specific case/instace the space you have occupied so far.&lt;BR /&gt;By default the disk space for storing logs is 5GB. You can check the config under the agent settings and you can increase it up to 10Gb max APROX.&lt;BR /&gt;If you reboot the system the agent is cycling the logging schema in the following way:&lt;BR /&gt;The logs are created under folder C:\ProgramData\Cyvera\Logs&lt;BR /&gt;Go there and check the files trapsd.log*&lt;BR /&gt;The file trapsd.log stores the newest logs.&lt;BR /&gt;The file trapsd.log.9.gz stores the oldest ones so the ones that are deleted/cycled first.&lt;BR /&gt;Once trapsd.log is full, it is renamed to trapsd.log.0.gz and trapsd.log.0.gz to trapsd.log.1.gz and so on ... so trapsd.log.9.gz is lost&lt;BR /&gt;So the log storage and retention period within cortex xdr agent may vary depending upon your config setup, and logs generated by your agent instance.&lt;BR /&gt;If agent lost the logs your are looking for. You could go and look for "some" of the logs at Cortex Data Lake in case you have it (the security related logs should be at CDL but not the agent operations related logs). Again depending on your setup there and the volume of logs generated by your xdr agentS, log retention may vary also at CDL.&lt;BR /&gt;So please take into account that the log limitation is not related to time but to Space quota on the hard disk which means that the more logs your agent/computer generates, the less time log preservation you will have.&lt;/P&gt;&lt;P&gt;I hope I brought some light to the subject.&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR,&lt;BR /&gt;Luis&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 24 Sep 2021 12:21:52 GMT</pubDate>
    <dc:creator>eluis</dc:creator>
    <dc:date>2021-09-24T12:21:52Z</dc:date>
    <item>
      <title>Cortex XDR Agent and system logs</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-and-system-logs/m-p/435417#M1071</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to get logs for cortex XDR agent of more than 1 month old, from system and tech support file however not getting any success. Does anyone knows any method by which we can retieve agent logs/tech support logs for more than 1 month old data?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to retrieve such logs form cortex XDR agent?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in adavance.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 07:31:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-and-system-logs/m-p/435417#M1071</guid>
      <dc:creator>tejasp04</dc:creator>
      <dc:date>2021-09-21T07:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Agent and system logs</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-and-system-logs/m-p/436443#M1084</link>
      <description>&lt;P&gt;Hi Tejasp04,&lt;/P&gt;&lt;P&gt;You can customize the amount of disk space that the cortex xdr agent uses to store logs and information about events. See in your specific case/instace the space you have occupied so far.&lt;BR /&gt;By default the disk space for storing logs is 5GB. You can check the config under the agent settings and you can increase it up to 10Gb max APROX.&lt;BR /&gt;If you reboot the system the agent is cycling the logging schema in the following way:&lt;BR /&gt;The logs are created under folder C:\ProgramData\Cyvera\Logs&lt;BR /&gt;Go there and check the files trapsd.log*&lt;BR /&gt;The file trapsd.log stores the newest logs.&lt;BR /&gt;The file trapsd.log.9.gz stores the oldest ones so the ones that are deleted/cycled first.&lt;BR /&gt;Once trapsd.log is full, it is renamed to trapsd.log.0.gz and trapsd.log.0.gz to trapsd.log.1.gz and so on ... so trapsd.log.9.gz is lost&lt;BR /&gt;So the log storage and retention period within cortex xdr agent may vary depending upon your config setup, and logs generated by your agent instance.&lt;BR /&gt;If agent lost the logs your are looking for. You could go and look for "some" of the logs at Cortex Data Lake in case you have it (the security related logs should be at CDL but not the agent operations related logs). Again depending on your setup there and the volume of logs generated by your xdr agentS, log retention may vary also at CDL.&lt;BR /&gt;So please take into account that the log limitation is not related to time but to Space quota on the hard disk which means that the more logs your agent/computer generates, the less time log preservation you will have.&lt;/P&gt;&lt;P&gt;I hope I brought some light to the subject.&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR,&lt;BR /&gt;Luis&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2021 12:21:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-and-system-logs/m-p/436443#M1084</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2021-09-24T12:21:52Z</dc:date>
    </item>
  </channel>
</rss>

