<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR Broker VM Down in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-broker-vm-down/m-p/504372#M2213</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/221857"&gt;@RameshShrestha&lt;/a&gt;&amp;nbsp;having a single Broker VM is not a recommended approach. The official guide indicates 1 Broker VM per 10,000 endpoints. Given that, we also need to keep in mind HA, which is to have minimum of 1 on top of the recommendation to ensure your endpoints continue to operate as usual. You can review the other options for download sources as listed in Step 14 &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/customizable-agent-settings/add-agent-settings-profile" target="_blank"&gt;here.&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;If Direct Server Access is enabled in your tenant, the agents will fallback to connecting directly to the tenant via host proxy configurations.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_0-1655431482584.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41854i0C10679115F61363/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_0-1655431482584.png" alt="bbarmanroy_0-1655431482584.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For your second question, I'd recommend you to leverage your exisitng infrastructure monitoring tools to detect when the BVM IP/domain/landing page is unreachable and trigger an alert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Jun 2022 02:20:16 GMT</pubDate>
    <dc:creator>bbarmanroy</dc:creator>
    <dc:date>2022-06-17T02:20:16Z</dc:date>
    <item>
      <title>Cortex XDR Broker VM Down</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-broker-vm-down/m-p/504144#M2212</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was looking for an answer in a scenario where only 1 broker VM is available.&lt;/P&gt;&lt;P&gt;What happens when the VM goes down. How does the end point connect to XDR console and how can we get the visibility when VM goes down for long period.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 10:14:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-broker-vm-down/m-p/504144#M2212</guid>
      <dc:creator>RameshShrestha</dc:creator>
      <dc:date>2022-06-16T10:14:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Broker VM Down</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-broker-vm-down/m-p/504372#M2213</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/221857"&gt;@RameshShrestha&lt;/a&gt;&amp;nbsp;having a single Broker VM is not a recommended approach. The official guide indicates 1 Broker VM per 10,000 endpoints. Given that, we also need to keep in mind HA, which is to have minimum of 1 on top of the recommendation to ensure your endpoints continue to operate as usual. You can review the other options for download sources as listed in Step 14 &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/customizable-agent-settings/add-agent-settings-profile" target="_blank"&gt;here.&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;If Direct Server Access is enabled in your tenant, the agents will fallback to connecting directly to the tenant via host proxy configurations.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_0-1655431482584.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41854i0C10679115F61363/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_0-1655431482584.png" alt="bbarmanroy_0-1655431482584.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For your second question, I'd recommend you to leverage your exisitng infrastructure monitoring tools to detect when the BVM IP/domain/landing page is unreachable and trigger an alert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 02:20:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-broker-vm-down/m-p/504372#M2213</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-06-17T02:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Broker VM Down</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-broker-vm-down/m-p/504391#M2214</link>
      <description>&lt;P&gt;Hi Bbarmanroy,&lt;/P&gt;&lt;P&gt;One of our clients has only around 200 endpoints that don't have direct internet access and have only 1 VM. Those endpoints need Broker VM to access to Cortex Server. So in that case, if the VM goes down for some days, can we get the logs of activities of endpoints after VM comes online?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 03:41:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-broker-vm-down/m-p/504391#M2214</guid>
      <dc:creator>RameshShrestha</dc:creator>
      <dc:date>2022-06-17T03:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Broker VM Down</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-broker-vm-down/m-p/504447#M2215</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/221857"&gt;@RameshShrestha&lt;/a&gt;&amp;nbsp;yes, the customer will get the logs once connectivity is resumed (assuming the alloted disk space is not full, else FIFO). Since this is an airgapped environment, the customer should have at least 2 BVM's to ensure the connectivity is maintained. You can also write a Correlation rule to count the number of endpoints that have gone offline. If the count is equal to the total number of endpoints, that should fire off an alert.&lt;BR /&gt;&lt;BR /&gt;You can use this as a sample XQL query:&lt;BR /&gt;dataset = endpoints&lt;BR /&gt;| filter endpoint_status = ENUM.DISCONNECTED&lt;BR /&gt;| comp count(endpoint_name ) as Count by endpoint_status&lt;BR /&gt;| filter Count =200 // indicates all endpoints are offline&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 09:26:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-broker-vm-down/m-p/504447#M2215</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-06-17T09:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Broker VM Down</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-broker-vm-down/m-p/504453#M2216</link>
      <description>&lt;P&gt;thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192661"&gt;@bbarmanroy&lt;/a&gt; &lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 09:40:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-broker-vm-down/m-p/504453#M2216</guid>
      <dc:creator>RameshShrestha</dc:creator>
      <dc:date>2022-06-17T09:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Broker VM Down</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-broker-vm-down/m-p/504494#M2218</link>
      <description>&lt;P&gt;additional info on broker VM losing connectivity.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jcandelaria_0-1655479665753.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41870i6139B43CE3C8C963/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jcandelaria_0-1655479665753.png" alt="jcandelaria_0-1655479665753.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 15:27:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-broker-vm-down/m-p/504494#M2218</guid>
      <dc:creator>jcandelaria</dc:creator>
      <dc:date>2022-06-17T15:27:55Z</dc:date>
    </item>
  </channel>
</rss>

