<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows Event Collector vs XDR collector in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/windows-event-collector-vs-xdr-collector/m-p/1250216#M9188</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;STRONG data-end="242" data-start="220"&gt;Sekar,&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Just wondering if XDRC required internet connection for each XDRC agent, can I leverage BVM for this?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SDH&lt;/P&gt;</description>
    <pubDate>Mon, 16 Mar 2026 03:10:25 GMT</pubDate>
    <dc:creator>SeanDeHarris</dc:creator>
    <dc:date>2026-03-16T03:10:25Z</dc:date>
    <item>
      <title>Windows Event Collector vs XDR collector</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/windows-event-collector-vs-xdr-collector/m-p/1242963#M8897</link>
      <description>&lt;P&gt;Hello guru,&lt;/P&gt;
&lt;P&gt;it seems both served the same purpose to me. all i would like to ingest the event logs for analystic purpose.&lt;/P&gt;
&lt;P&gt;except the configuration nature, like WEC required AD config and XDR collector need an agent installed.&lt;/P&gt;
&lt;P&gt;what is the pros and cons for for WEC and XDR collector?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any use case for each?&lt;/P&gt;
&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SdG&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 09:44:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/windows-event-collector-vs-xdr-collector/m-p/1242963#M8897</guid>
      <dc:creator>SeanDeHarris</dc:creator>
      <dc:date>2025-12-02T09:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Event Collector vs XDR collector</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/windows-event-collector-vs-xdr-collector/m-p/1244412#M8925</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184443"&gt;@SeanDeHarris&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Both the &lt;STRONG data-start="217" data-end="250"&gt;Windows Event Collector (WEC)&lt;/STRONG&gt; applet and the &lt;STRONG data-start="266" data-end="297"&gt;Cortex XDR Collector (XDRC)&lt;/STRONG&gt; are designed to ingest Windows event logs into the Cortex XDR / XSIAM data lake for analysis and detection. While they share the same primary objective, they differ significantly in architecture, deployment complexity, and supported use cases.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;TABLE&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH&gt;Feature&lt;/TH&gt;
&lt;TH&gt;&lt;STRONG&gt;Windows Event Collector (WEC)&lt;/STRONG&gt;&lt;/TH&gt;
&lt;TH&gt;Cortex XDR Collector (XDRC)&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Architecture&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Centralized collection using a Broker VM with the WEC applet&lt;/TD&gt;
&lt;TD&gt;Distributed collection using a dedicated XDR Collector service installed per host&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Host Configuration&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Agentless on source servers; relies on native Windows Event Forwarding (WEF)&lt;/TD&gt;
&lt;TD&gt;Agent-based; requires installation of the XDR Collector service (separate from the standard XDR Agent)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Setup Complexity&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;High; requires configuration of WEF, subscription managers, Group Policy Objects (GPOs), and TLS certificates&lt;/TD&gt;
&lt;TD&gt;Moderate; requires agent installation but avoids complex WEF infrastructure&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Data Types Supported&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Windows Event Logs (Security, System, Application)&lt;/TD&gt;
&lt;TD&gt;Windows Event Logs, file-based logs, and DNS/DHCP logs&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Operating System Support&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Windows only&lt;/TD&gt;
&lt;TD&gt;Windows and Linux&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-start="1528" data-end="1557"&gt;&lt;STRONG&gt;Advantages and Limitations&lt;/STRONG&gt;&lt;/H4&gt;
&lt;H5 data-start="1559" data-end="1592"&gt;Windows Event Collector (WEC)&lt;/H5&gt;
&lt;P data-start="1594" data-end="1608"&gt;&lt;STRONG data-start="1594" data-end="1608"&gt;Advantages&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="1609" data-end="1937"&gt;
&lt;LI data-start="1609" data-end="1728"&gt;
&lt;P data-start="1611" data-end="1728"&gt;&lt;STRONG data-start="1611" data-end="1636"&gt;Agentless deployment:&lt;/STRONG&gt; Uses built-in Windows capabilities without requiring additional software on source servers.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1729" data-end="1850"&gt;
&lt;P data-start="1731" data-end="1850"&gt;&lt;STRONG data-start="1731" data-end="1758"&gt;Centralized efficiency:&lt;/STRONG&gt; Well suited for aggregating logs from a large number of servers through a single Broker VM.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1851" data-end="1937"&gt;
&lt;P data-start="1853" data-end="1937"&gt;&lt;STRONG data-start="1853" data-end="1873"&gt;Rich event data:&lt;/STRONG&gt; Recommended for detailed and well-parsed Windows event logging.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="1939" data-end="1954"&gt;&lt;STRONG data-start="1939" data-end="1954"&gt;Limitations&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="1955" data-end="2173"&gt;
&lt;LI data-start="1955" data-end="2075"&gt;
&lt;P data-start="1957" data-end="2075"&gt;&lt;STRONG data-start="1957" data-end="1983"&gt;Complex configuration:&lt;/STRONG&gt; Requires careful management of GPOs, certificates, and WEF subscriptions across the domain.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2076" data-end="2173"&gt;
&lt;P data-start="2078" data-end="2173"&gt;&lt;STRONG data-start="2078" data-end="2108"&gt;Infrastructure dependency:&lt;/STRONG&gt; Relies on a functioning Broker VM and stable WinRM connectivity.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Cortex XDR Collector (XDRC)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-start="2213" data-end="2227"&gt;&lt;STRONG data-start="2213" data-end="2227"&gt;Advantages&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="2228" data-end="2576"&gt;
&lt;LI data-start="2228" data-end="2337"&gt;
&lt;P data-start="2230" data-end="2337"&gt;&lt;STRONG data-start="2230" data-end="2256"&gt;Simplified deployment:&lt;/STRONG&gt; Faster to deploy compared to building and maintaining a full WEF infrastructure.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2338" data-end="2473"&gt;
&lt;P data-start="2340" data-end="2473"&gt;&lt;STRONG data-start="2340" data-end="2356"&gt;Versatility:&lt;/STRONG&gt; Supports Linux systems and can ingest a wider range of log types, including file-based logs that WEC cannot collect.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2474" data-end="2576"&gt;
&lt;P data-start="2476" data-end="2576"&gt;&lt;STRONG data-start="2476" data-end="2497"&gt;Granular control:&lt;/STRONG&gt; YAML-based configuration allows precise filtering and custom collection rules.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="2578" data-end="2593"&gt;&lt;STRONG data-start="2578" data-end="2593"&gt;Limitations&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="2594" data-end="2813"&gt;
&lt;LI data-start="2594" data-end="2681"&gt;
&lt;P data-start="2596" data-end="2681"&gt;&lt;STRONG data-start="2596" data-end="2626"&gt;Additional agent overhead:&lt;/STRONG&gt; Requires maintaining an extra service on the endpoint.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2682" data-end="2813"&gt;
&lt;P data-start="2684" data-end="2813"&gt;&lt;STRONG data-start="2684" data-end="2714"&gt;Configuration sensitivity:&lt;/STRONG&gt; YAML configuration files are strict; syntax or indentation errors can cause log ingestion to fail.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;FYI:&amp;nbsp;Licensing Considerations&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-start="3519" data-end="3881"&gt;Both WEC and XDRC generally require &lt;STRONG data-start="3555" data-end="3580"&gt;Cortex XDR Pro per GB&lt;/STRONG&gt; licensing for log ingestion. While the standard Cortex XDR Agent with an Extended Threat Hunting (XTH) add-on can collect a limited subset of Windows event logs, it is subject to rate limiting and is not intended for high-volume audit logging environments such as heavily utilized Domain Controllers.&lt;/P&gt;
&lt;P data-start="3519" data-end="3881"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="74" data-end="198"&gt;If this response has answered your query, please let us know by clicking &lt;STRONG data-start="147" data-end="155"&gt;Like&lt;/STRONG&gt; and selecting &lt;STRONG data-start="170" data-end="197"&gt;Mark this as a Solution&lt;/STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P data-start="200" data-end="242"&gt;Thanks &amp;amp; Regards,&lt;BR data-start="217" data-end="220" /&gt;&lt;STRONG data-start="220" data-end="242"&gt;S. Subashkar Sekar&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Dec 2025 20:30:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/windows-event-collector-vs-xdr-collector/m-p/1244412#M8925</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2025-12-22T20:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Event Collector vs XDR collector</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/windows-event-collector-vs-xdr-collector/m-p/1250216#M9188</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;STRONG data-end="242" data-start="220"&gt;Sekar,&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Just wondering if XDRC required internet connection for each XDRC agent, can I leverage BVM for this?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SDH&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2026 03:10:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/windows-event-collector-vs-xdr-collector/m-p/1250216#M9188</guid>
      <dc:creator>SeanDeHarris</dc:creator>
      <dc:date>2026-03-16T03:10:25Z</dc:date>
    </item>
  </channel>
</rss>

