<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File and folders collector in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-and-folders-collector/m-p/530097#M3575</link>
    <description>&lt;P&gt;Hi Ulkar,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What this collector is gives us ?&lt;/P&gt;
&lt;P&gt;Actually this is directly related what you want to collect and analyses. This collector might read, application logs or network device logs, OS logs etc. changes based on your scenario.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You cannot view remotely formats but you can filter remotely what you want to collect.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can use wildcard in "Include" part. (like *.json)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Product and Vendor is generally helping for automatic parsing or keeping data in specific dataset.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you write Vendor = X and Product = Y&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your collected data will be in X_Y_raw dataset.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope that helps&lt;/P&gt;</description>
    <pubDate>Tue, 07 Feb 2023 10:44:20 GMT</pubDate>
    <dc:creator>etugriceri</dc:creator>
    <dc:date>2023-02-07T10:44:20Z</dc:date>
    <item>
      <title>File and folders collector</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-and-folders-collector/m-p/529567#M3530</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;
&lt;P&gt;I have questions about setting up file and folder collector.I do not understand what the inclusion of logs of this collector gives us.How can I view all files of any formats that are in the folder?What is the vendor and product responsible for?I ask you to bring an example, in the official guide it is written very briefly&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2023 05:35:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-and-folders-collector/m-p/529567#M3530</guid>
      <dc:creator>Ulkar_Hasanova</dc:creator>
      <dc:date>2023-02-02T05:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: File and folders collector</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-and-folders-collector/m-p/530097#M3575</link>
      <description>&lt;P&gt;Hi Ulkar,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What this collector is gives us ?&lt;/P&gt;
&lt;P&gt;Actually this is directly related what you want to collect and analyses. This collector might read, application logs or network device logs, OS logs etc. changes based on your scenario.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You cannot view remotely formats but you can filter remotely what you want to collect.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can use wildcard in "Include" part. (like *.json)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Product and Vendor is generally helping for automatic parsing or keeping data in specific dataset.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you write Vendor = X and Product = Y&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your collected data will be in X_Y_raw dataset.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope that helps&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 10:44:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-and-folders-collector/m-p/530097#M3575</guid>
      <dc:creator>etugriceri</dc:creator>
      <dc:date>2023-02-07T10:44:20Z</dc:date>
    </item>
  </channel>
</rss>

