<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Broker VM Log ingestion and forwarding in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-log-ingestion-and-forwarding/m-p/1220024#M7869</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My query is can we forward one broker VM logs to another broker VM.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Use case is I have BVM A and BVM 2,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1. I want to ingest logs into BVM A from Agents or other log sources.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2. Then forward logs from BVM A to BVM B.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;3. BVM B will send logs to XDR or XSIAM tenant.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found one way which is by rsyslog or any other syslogs as intermediate between two broker VMs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone have any other method, or any suggestions or best practices to do fullfill mentioned use case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Cortex XSIAM" id="Cortex_XSIAM"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Feb 2025 15:42:54 GMT</pubDate>
    <dc:creator>P.Ghule</dc:creator>
    <dc:date>2025-02-11T15:42:54Z</dc:date>
    <item>
      <title>Broker VM Log ingestion and forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-log-ingestion-and-forwarding/m-p/1220024#M7869</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My query is can we forward one broker VM logs to another broker VM.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Use case is I have BVM A and BVM 2,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1. I want to ingest logs into BVM A from Agents or other log sources.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2. Then forward logs from BVM A to BVM B.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;3. BVM B will send logs to XDR or XSIAM tenant.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found one way which is by rsyslog or any other syslogs as intermediate between two broker VMs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone have any other method, or any suggestions or best practices to do fullfill mentioned use case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Cortex XSIAM" id="Cortex_XSIAM"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 15:42:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-log-ingestion-and-forwarding/m-p/1220024#M7869</guid>
      <dc:creator>P.Ghule</dc:creator>
      <dc:date>2025-02-11T15:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: Broker VM Log ingestion and forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-log-ingestion-and-forwarding/m-p/1220173#M7874</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/651576993"&gt;@P.Ghule&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, you can proxy the communication between the two Broker VMs.&lt;/P&gt;
&lt;P&gt;You can use the Proxy Server configuration in the Broker VM right-click Configurations menu.&lt;/P&gt;
&lt;P&gt;More information in &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Set-up-and-configure-Broker-VM" target="_self"&gt;this link&lt;/A&gt;, going to&amp;nbsp;&lt;STRONG&gt;Initial Setup - How to configure Broker VM Settings - Proxy Server&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 12:56:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-log-ingestion-and-forwarding/m-p/1220173#M7874</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2025-02-12T12:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Broker VM Log ingestion and forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-log-ingestion-and-forwarding/m-p/1220276#M7876</link>
      <description>&lt;P&gt;Hi @Jmazzezo , Thanks for the solution It looks relevant to my query.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please tell me by doing this, raw logs from Broker A will be send to tenant or it will redirect to Broker B and B will store it to cloud tenant.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 03:50:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-log-ingestion-and-forwarding/m-p/1220276#M7876</guid>
      <dc:creator>P.Ghule</dc:creator>
      <dc:date>2025-02-13T03:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: Broker VM Log ingestion and forwarding</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-log-ingestion-and-forwarding/m-p/1220381#M7880</link>
      <description>&lt;P&gt;You are right&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/651576993"&gt;@P.Ghule&lt;/a&gt;, this is the doc note:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can configure another Broker VM as a proxy server for this Broker VM by selecting the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="guilabel"&gt;HTTP&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;type. When selecting&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="guilabel"&gt;HTTP&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;to route Broker VM communication, you need to add the IP&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="guilabel"&gt;Address&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="guilabel"&gt;Port&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;number (set when activating the Agent Proxy) for another Broker VM registered in your tenant. This designates the other Broker VM as a proxy for this Broker VM.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 15:50:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/broker-vm-log-ingestion-and-forwarding/m-p/1220381#M7880</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2025-02-13T15:50:57Z</dc:date>
    </item>
  </channel>
</rss>

