<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR Collector Installations query in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-collector-installations-query/m-p/563282#M5430</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/243138"&gt;@Vinothkumar_SBA&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on Live Community!&lt;/P&gt;
&lt;P&gt;Deployment of XDR collector depends on what kind of logs you want to collect. If you only want to collect logs from DHCP server as an endpoint from security point of perspective then XDR agent itself collect a good amount of logs. Please refer to below link to see what kind of data XDR agent collects.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Endpoint-Data-Collection" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Endpoint-Data-Collection&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;However, if you particularly wants to collect DHCP service logs then you can deploy XDR collector or as an alternate can use elastic search filebeat that can be integrated with XDR tenant directly and push logs. More information on collecting DHCP logs can be found in below link.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Ingest-Logs-from-Windows-DHCP-using-Elasticsearch-Filebeat?tocId=FWLYuyT54W_un30sGaw9jw" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Ingest-Logs-from-Windows-DHCP-using-Elasticsearch-Filebeat?tocId=FWLYuyT54W_un30sGaw9jw&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;XDR collector is only for log collection and cannot provide prevention capabilities.&lt;/P&gt;</description>
    <pubDate>Thu, 26 Oct 2023 17:53:40 GMT</pubDate>
    <dc:creator>nsinghvirk</dc:creator>
    <dc:date>2023-10-26T17:53:40Z</dc:date>
    <item>
      <title>Cortex XDR Collector Installations query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-collector-installations-query/m-p/562831#M5421</link>
      <description>&lt;DIV class="lia-quilt-row lia-quilt-row-message-main"&gt;
&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-message-main-content"&gt;
&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;
&lt;DIV id="bodyDisplay" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P style="margin: 0px;"&gt;Hi Team,&lt;/P&gt;
&lt;P style="margin: 0px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;"&gt;We are planning to install XDR collectors on our DHCP server. At the same time, we already have Cortex XDR agents installed on the DHCP server. Could you please confirm whether we should install both agents or just one of them?&lt;/P&gt;
&lt;P style="margin: 0px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;"&gt;Additionally, we are unsure if XDR collectors are solely responsible for log collection or if they also serve a dual purpose of &lt;STRONG&gt;log collection&lt;/STRONG&gt; and &lt;STRONG&gt;prevention&lt;/STRONG&gt;. We haven't identified any &lt;STRONG&gt;prevention policies&lt;/STRONG&gt; in the &lt;STRONG&gt;XDR collectors&lt;/STRONG&gt;' settings.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 24 Oct 2023 06:06:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-collector-installations-query/m-p/562831#M5421</guid>
      <dc:creator>Vinothkumar_SBA</dc:creator>
      <dc:date>2023-10-24T06:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Collector Installations query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-collector-installations-query/m-p/563282#M5430</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/243138"&gt;@Vinothkumar_SBA&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on Live Community!&lt;/P&gt;
&lt;P&gt;Deployment of XDR collector depends on what kind of logs you want to collect. If you only want to collect logs from DHCP server as an endpoint from security point of perspective then XDR agent itself collect a good amount of logs. Please refer to below link to see what kind of data XDR agent collects.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Endpoint-Data-Collection" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Endpoint-Data-Collection&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;However, if you particularly wants to collect DHCP service logs then you can deploy XDR collector or as an alternate can use elastic search filebeat that can be integrated with XDR tenant directly and push logs. More information on collecting DHCP logs can be found in below link.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Ingest-Logs-from-Windows-DHCP-using-Elasticsearch-Filebeat?tocId=FWLYuyT54W_un30sGaw9jw" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Ingest-Logs-from-Windows-DHCP-using-Elasticsearch-Filebeat?tocId=FWLYuyT54W_un30sGaw9jw&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;XDR collector is only for log collection and cannot provide prevention capabilities.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 17:53:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-collector-installations-query/m-p/563282#M5430</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2023-10-26T17:53:40Z</dc:date>
    </item>
  </channel>
</rss>

