<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Do we need to install XDR Collectors in our servers to Collect Windows Events ? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/do-we-need-to-install-xdr-collectors-in-our-servers-to-collect/m-p/1232093#M8456</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167148"&gt;@mavraham&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does the XDR collector support Event Forwarding funtion?&amp;nbsp;&lt;BR /&gt;Or we need to install the XDRC on each endpoints/servers/DC to collect the Windows event?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jun 2025 05:50:19 GMT</pubDate>
    <dc:creator>SeanDeHarris</dc:creator>
    <dc:date>2025-06-19T05:50:19Z</dc:date>
    <item>
      <title>Do we need to install XDR Collectors in our servers to Collect Windows Events ?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/do-we-need-to-install-xdr-collectors-in-our-servers-to-collect/m-p/526746#M3387</link>
      <description>&lt;P&gt;HI&lt;/P&gt;
&lt;P&gt;We are using cortex XDR and planning to deploy the XSIAM. We are working on the deployment. While reading the below document for collecting Windows events,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/XDR-Collector-Machine-Requirements-and-Supported-Operating-Systems" target="_blank"&gt;XDR Collector Machine Requirements and Supported Operating Systems • Cortex XDR Pro Administrator Guide • Reader • Palo Alto Networks documentation portal&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;My question is,&lt;/P&gt;
&lt;P&gt;We have the broker VM configured.&lt;/P&gt;
&lt;P&gt;All the Windows Servers are running XDR agents 7.9&lt;/P&gt;
&lt;P&gt;As per document, the solution requires to install XDR collector in the servers. So, As we are running XDR agents, so do we need to install XDR collectors in the server which will reside with XDR agents parallelly and will collect the Windows Events ?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 04:14:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/do-we-need-to-install-xdr-collectors-in-our-servers-to-collect/m-p/526746#M3387</guid>
      <dc:creator>Ariq_Aziz</dc:creator>
      <dc:date>2023-01-12T04:14:36Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need to install XDR Collectors in our servers to Collect Windows Events ?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/do-we-need-to-install-xdr-collectors-in-our-servers-to-collect/m-p/526813#M3394</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/248058"&gt;@Ariq_Aziz&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Thank you for writing to live community.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Please allow me to explain the difference between using BrokerVM and XDR Collectors to collect windows events:&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Both BrokerVM and the XDR Collector are able to collect any kind of windows event log.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;The main difference between the two would be that BrokerVM needs to be &lt;/SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Activate-the-Windows-Event-Collector?tocId=3WWvlzLnB_9RU9HZjnJyVw" target="_blank"&gt;&lt;SPAN&gt;configured on the domain controller level&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;, establishes a remote connection and allows all Windows domain members to push their logs into BrokerVM. Whereas, the XDR Collector is an agent reading directly from the filesystem and enables you to &lt;/SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Add-an-XDR-Collector-Profile-for-Windows" target="_blank"&gt;&lt;SPAN&gt;collect file and log data using the Elasticsearch Filebeat default&lt;/SPAN&gt; &lt;SPAN&gt;configuration file&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In your instance, if you are already using BrokerVM to collect Windows event longs (assuming you tested and made sure it works) installing the XDR Collector is optional.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 17:24:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/do-we-need-to-install-xdr-collectors-in-our-servers-to-collect/m-p/526813#M3394</guid>
      <dc:creator>mavraham</dc:creator>
      <dc:date>2023-01-12T17:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need to install XDR Collectors in our servers to Collect Windows Events ?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/do-we-need-to-install-xdr-collectors-in-our-servers-to-collect/m-p/527062#M3398</link>
      <description>&lt;P&gt;HI Mavraham&lt;/P&gt;
&lt;P&gt;Thanks a lot for the reply. It's really helpful. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; it seems like we dont need Collector as we have the Broker VM. Thanks again.&lt;/P&gt;</description>
      <pubDate>Sat, 14 Jan 2023 22:02:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/do-we-need-to-install-xdr-collectors-in-our-servers-to-collect/m-p/527062#M3398</guid>
      <dc:creator>Ariq_Aziz</dc:creator>
      <dc:date>2023-01-14T22:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need to install XDR Collectors in our servers to Collect Windows Events ?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/do-we-need-to-install-xdr-collectors-in-our-servers-to-collect/m-p/578452#M6155</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167148"&gt;@mavraham&lt;/a&gt;, If we use XDR collector to colelct WEC logs, do we need to install that agent on all endpoints?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 11:24:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/do-we-need-to-install-xdr-collectors-in-our-servers-to-collect/m-p/578452#M6155</guid>
      <dc:creator>JahidAliyev</dc:creator>
      <dc:date>2024-02-27T11:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need to install XDR Collectors in our servers to Collect Windows Events ?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/do-we-need-to-install-xdr-collectors-in-our-servers-to-collect/m-p/1232093#M8456</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167148"&gt;@mavraham&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does the XDR collector support Event Forwarding funtion?&amp;nbsp;&lt;BR /&gt;Or we need to install the XDRC on each endpoints/servers/DC to collect the Windows event?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2025 05:50:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/do-we-need-to-install-xdr-collectors-in-our-servers-to-collect/m-p/1232093#M8456</guid>
      <dc:creator>SeanDeHarris</dc:creator>
      <dc:date>2025-06-19T05:50:19Z</dc:date>
    </item>
  </channel>
</rss>

