<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Broker VM and connection to the agents visibility in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-and-connection-to-the-agents-visibility/m-p/512526#M2653</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Aside to above, to check if your agent proxy is working,&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You may run the following commands&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Windows&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;C:\Program Files\Palo Alto Networks\Traps&amp;gt;cytool proxy query&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Mac&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Sudo /Library/Application\ Support/PaloAltoNetworks/Traps/bin/cytool proxy query&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Linux&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/opt/traps/bin/cytool proxy query&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The BVM IP address and port should be listed under Last good Proxy in the command output. If there is no Last Good Proxy, it means your agent cannot connect to Broker VM .If Proxy server is not configured properly, you can run this command to configure Proxy.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;“cytool proxy set X.X.X.X:YYYY”&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;*replace X.X.X.X with BVM IP address and YYYY with BVM port&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 22 Aug 2022 12:05:25 GMT</pubDate>
    <dc:creator>creddy</dc:creator>
    <dc:date>2022-08-22T12:05:25Z</dc:date>
    <item>
      <title>Broker VM and connection to the agents visibility</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-and-connection-to-the-agents-visibility/m-p/512510#M2650</link>
      <description>&lt;P&gt;Hello dear community,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;now I setup everything what I needed to get an agent running with the broker vm. The agent is also connecting through P2P and directly to the server.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But where and how can I see, if the communication is ok through the broker vm?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 10:17:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-and-connection-to-the-agents-visibility/m-p/512510#M2650</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-08-22T10:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: Broker VM and connection to the agents visibility</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-and-connection-to-the-agents-visibility/m-p/512523#M2652</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;You can test access from agent to broker VM by reaching agent registration URL.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The Cortex XDR agent will use registration URL to register to Cortex XDR Server.&lt;/P&gt;
&lt;P&gt;To get this URL, we need to have Agent Installer ID at first place.&lt;/P&gt;
&lt;P&gt;The Cortex XDR agent installer ID can be checked from the Cortex XDR Management console -&amp;gt; Endpoints -&amp;gt; Agent Installations page. Add the Id column in the Layout to view installer ID.&lt;/P&gt;
&lt;P&gt;Take the ID of the package that you have used to install agent before.&lt;/P&gt;
&lt;P&gt;Add this installer ID in the end of below URL&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;A href="https://distributions.traps.paloaltonetworks.com/operations/provision/register-url/" target="_blank"&gt;https://distributions.traps.paloaltonetworks.com/operations/provision/register-url/&lt;/A&gt;&amp;lt;insert the installer ID here&amp;gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Configure the browser application (on the endpoint you are testing) to use the BVM proxy. In below screenshot with Firefox browser, 192.168.0.189 is the Broker VM IP address and port 8888 is the port configured in BVM Local Agent Settings.&lt;BR /&gt;Access the above URL from this broswer.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;The expected result here are the following:&lt;BR /&gt;"chUrl":"https:\/\/ch-&amp;lt;xdr-tenant&amp;gt;.traps.paloaltonetworks.com",&lt;BR /&gt;"ccUrl":"https:\/\/cc-&amp;lt;xdr-tenant&amp;gt;.traps.paloaltonetworks.com",&lt;BR /&gt;"cdcUrl":"https:\/\/dc-&amp;lt;xdr-tenant&amp;gt;.traps.paloaltonetworks.com",&lt;BR /&gt;"instType":0&lt;BR /&gt;&lt;BR /&gt;If you get above expected result, it means the connection between agent and server is fine.&lt;BR /&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 12:01:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-and-connection-to-the-agents-visibility/m-p/512523#M2652</guid>
      <dc:creator>creddy</dc:creator>
      <dc:date>2022-08-22T12:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: Broker VM and connection to the agents visibility</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-and-connection-to-the-agents-visibility/m-p/512526#M2653</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Aside to above, to check if your agent proxy is working,&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You may run the following commands&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Windows&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;C:\Program Files\Palo Alto Networks\Traps&amp;gt;cytool proxy query&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Mac&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Sudo /Library/Application\ Support/PaloAltoNetworks/Traps/bin/cytool proxy query&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Linux&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/opt/traps/bin/cytool proxy query&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The BVM IP address and port should be listed under Last good Proxy in the command output. If there is no Last Good Proxy, it means your agent cannot connect to Broker VM .If Proxy server is not configured properly, you can run this command to configure Proxy.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;“cytool proxy set X.X.X.X:YYYY”&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;*replace X.X.X.X with BVM IP address and YYYY with BVM port&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 12:05:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-and-connection-to-the-agents-visibility/m-p/512526#M2653</guid>
      <dc:creator>creddy</dc:creator>
      <dc:date>2022-08-22T12:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: Broker VM and connection to the agents visibility</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-and-connection-to-the-agents-visibility/m-p/512533#M2654</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Couple of questions before answering in detail,what is your requirement? :&lt;/P&gt;
&lt;P&gt;1. Do you want the agent to communicate to cloud via proxy?&lt;/P&gt;
&lt;P&gt;2. Do you want the agent to take content and agent upgrades via Broker VM?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Answer 1:&amp;nbsp;&lt;/STRONG&gt;If you need the agents to Cortex XDR cloud via agent proxy on the broker VM, following are the steps:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;On the Broker VM applet, right click on&amp;nbsp;&lt;STRONG&gt;Local Agent Settings&amp;gt; Activate.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;On the Agent Proxy, select Enable, Choose Port number(remember not to use reserved ports and others mentioned in the broker vm configuration document) and the listening interface(optional).&lt;/LI&gt;
&lt;LI&gt;If you have already installed agents, please follow instructions provided by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192854"&gt;@creddy&lt;/a&gt;. Steps may differ for Windows, Linux and MacOS machines. Make sure you follow the installation guides for the same.&lt;/LI&gt;
&lt;LI&gt;Once you have the proxy IP and port configured, you can use cytool commands as mentioned by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192854"&gt;@creddy&lt;/a&gt;&amp;nbsp; or from the Broker VM console on cortex XDR, hover your cursor on the Local Agent Settings applet and you should see the number of active connections. The active connection number denotes the number of agents connecting to Cortex XDR via the Broker VM.
&lt;P&gt; &lt;/P&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-08-22 at 8.33.44 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43259i89E99E2117EA0FD8/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2022-08-22 at 8.33.44 PM.png" alt="Screenshot 2022-08-22 at 8.33.44 PM.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Answer 2: for content updates and agent upgrades to happen via broker&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Make sure you fulfill all the requirements mentioned in the guide. Link provided &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/broker-vm/set-up-broker-vm/activate-the-agent-proxy-for-closed-networks#:~:text=Agent%20Installer%20and%20Content%20Caching,your%20Agent%20Settings%20Profile." target="_blank" rel="noopener"&gt;&lt;STRONG&gt;here&lt;/STRONG&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Add the FQDN in the broker VM configuration page.&lt;/LI&gt;
&lt;LI&gt;Activate the Local Agent Settings&amp;gt; Agent Installer and Content Caching&amp;gt;Select &lt;STRONG&gt;Enable&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Go to your Cortex XDR agent setting profile and under the Download Sources, select all the options(P2P, Cortex Server, Broker VM)&lt;/LI&gt;
&lt;LI&gt;Choose your configured broker VM from the list&lt;/LI&gt;
&lt;LI&gt;The validation of the agent taking updates from the broker will be available in the agent logs once they upgrade automatically.&lt;/LI&gt;
&lt;LI&gt;Check the agent logs for your broker VM FQDN and you should find the content upgrade actions list.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 22 Aug 2022 12:41:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-and-connection-to-the-agents-visibility/m-p/512533#M2654</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2022-08-22T12:41:51Z</dc:date>
    </item>
    <item>
      <title>Re: Broker VM and connection to the agents visibility</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-and-connection-to-the-agents-visibility/m-p/512975#M2695</link>
      <description>&lt;P&gt;Thank you! This worked for me for checking it localy!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 10:57:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-and-connection-to-the-agents-visibility/m-p/512975#M2695</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-08-25T10:57:34Z</dc:date>
    </item>
    <item>
      <title>Re: Broker VM and connection to the agents visibility</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-and-connection-to-the-agents-visibility/m-p/512978#M2697</link>
      <description>&lt;P&gt;Hello Neelrohit,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you, yes both questions cover my requirements.&lt;/P&gt;
&lt;P&gt;Do you know a way, how can we be informed by mail/alert when a broker vm is down? Until now, I only could find out, this message about the broker vm status appears in the notifications and in the settings in the app cloud console.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would prefer it in an audit log to throw a alert/mail.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 11:51:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-and-connection-to-the-agents-visibility/m-p/512978#M2697</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-08-25T11:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: Broker VM and connection to the agents visibility</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-and-connection-to-the-agents-visibility/m-p/512979#M2698</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The data for broker VM connectivity and other associated detail is audited and logged in the management audit logs. You can filter the same and create a notification forwarding for the Broker VM disconnections.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Neel&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 12:08:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-and-connection-to-the-agents-visibility/m-p/512979#M2698</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2022-08-25T12:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: Broker VM and connection to the agents visibility</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-and-connection-to-the-agents-visibility/m-p/513349#M2745</link>
      <description>&lt;P&gt;Hello Neelrohit!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It takes one hour until the log entry is written to management audit logs. It this one hour delay adjustable?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 09:45:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-and-connection-to-the-agents-visibility/m-p/513349#M2745</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-08-30T09:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: Broker VM and connection to the agents visibility</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-and-connection-to-the-agents-visibility/m-p/513416#M2746</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As of now, this is not adjustable. We request you to kindly open a support case and report the issue and the engineering team can fix this to optimise the latency in the log status.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/174539"&gt;@neelrohit&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2022 01:39:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-and-connection-to-the-agents-visibility/m-p/513416#M2746</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2022-08-31T01:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: Broker VM and connection to the agents visibility</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-and-connection-to-the-agents-visibility/m-p/513447#M2747</link>
      <description>&lt;P&gt;Thank you! I will ask them.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2022 11:41:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-and-connection-to-the-agents-visibility/m-p/513447#M2747</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-08-31T11:41:38Z</dc:date>
    </item>
  </channel>
</rss>

