<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 回應： [Cortex XSIAM ] XDR Collector Collect Windows Security Log。XDR Collectors Administration Status display &amp;quot;Error&amp;quot;. in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam-xdr-collector-collect-windows-security-log-xdr/m-p/1245712#M301</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Anothenr one solution :&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- Add Filebeat profile for X&lt;SPAN&gt;DR Collector Logs&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- Aplly&amp;nbsp; winlogbet and filebeat Profile on policy&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;- View target status on XDR Collctors Administration&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This necessitated the collection of additional xdr logs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jchen644219_0-1768527313806.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70370i34A7BE4C6410E51D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jchen644219_0-1768527313806.png" alt="jchen644219_0-1768527313806.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jchen644219_1-1768527333788.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70371i610319AFCE18D3EB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jchen644219_1-1768527333788.png" alt="jchen644219_1-1768527333788.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 16 Jan 2026 01:39:17 GMT</pubDate>
    <dc:creator>j.chen644219</dc:creator>
    <dc:date>2026-01-16T01:39:17Z</dc:date>
    <item>
      <title>[Cortex XSIAM ] XDR Collector Collect Windows Security Log。XDR Collectors Administration Status display "Error".</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam-xdr-collector-collect-windows-security-log-xdr/m-p/1243411#M285</link>
      <description>&lt;P&gt;Currently, I'm using the default templates.&lt;/P&gt;
&lt;P&gt;Despite trying many tests, this error message persists.&lt;/P&gt;
&lt;P&gt;Am I missing any information?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;XDR Collectors Administration Status display &lt;FONT color="#FF0000"&gt;"Error".&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;Error Message :&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Exiting: no modules or inputs enabled and configuration reloading disabled.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;What files do you want me to watch?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4" color="#FF6600"&gt;&lt;STRONG&gt;XDR Collectors Administration&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jchen644219_0-1765245869642.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70062iCD280B35C34A0061/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jchen644219_0-1765245869642.png" alt="jchen644219_0-1765245869642.png" /&gt;&lt;/span&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="5" color="#FF6600"&gt;&lt;FONT size="4"&gt;View Collector Policy - Filebeat&amp;nbsp; (Use Default Template)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="4"&gt;View Collector Policy - Winlogbeat (Windows Security / Microsoft ADFS&lt;/FONT&gt; &lt;FONT size="4"&gt;Template)&lt;/FONT&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jchen644219_2-1765246646357.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70065iB2CBA94CA85332B1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jchen644219_2-1765246646357.png" alt="jchen644219_2-1765246646357.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="4" color="#FF6600"&gt;Query Builder - search microsoft_windows_raw&amp;nbsp; (collected windows security log)&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jchen644219_3-1765246972416.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70066i82930F2176B60524/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jchen644219_3-1765246972416.png" alt="jchen644219_3-1765246972416.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would appreciate any further suggestions on how to resolve this.&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 02:27:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam-xdr-collector-collect-windows-security-log-xdr/m-p/1243411#M285</guid>
      <dc:creator>j.chen644219</dc:creator>
      <dc:date>2025-12-09T02:27:34Z</dc:date>
    </item>
    <item>
      <title>回應： [Cortex XSIAM ] XDR Collector Collect Windows Security Log。XDR Collectors Administration Status display "Error".</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam-xdr-collector-collect-windows-security-log-xdr/m-p/1243584#M286</link>
      <description>&lt;P&gt;Now the profile changed Configuration .&lt;/P&gt;
&lt;P&gt;I'm wondering if the YAML itself is the problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's possible that XDRC is unable to communicate with XSIAM.&lt;/P&gt;
&lt;P&gt;1. Remove the agent remotely via XSIAM.&lt;/P&gt;
&lt;P&gt;2. Changes to the weblogbeat profile's YAML file can be synchronized to the Windows server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Therefore, I don't understand...&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;1. What does this "error" status affect?&lt;/P&gt;
&lt;P&gt;​​2. What does this "Error" status mean?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;winlogbeat YAML :&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;
&lt;DIV&gt;---&lt;BR /&gt;winlogbeat.event_logs:&lt;BR /&gt;- name: Security&lt;BR /&gt;ignore_older: 1h&lt;BR /&gt;processors:&lt;BR /&gt;- drop_event.when.not.or:&lt;BR /&gt;- regexp.winlog.event_id: (110[0-2]|462[45]|4634|464[78]|4662|4672|4674|46[89]8)&lt;BR /&gt;- regexp.winlog.event_id: (4702|4713|4720|472[2-9]|473[1-3578]|474[0-3]|475[4-7]|476[4-9])&lt;BR /&gt;- regexp.winlog.event_id: (477[0126]|4780|4799|480[0-3]|482[1-5]|488[67]|4899|4900|505[89]|5061|5140)&lt;BR /&gt;- name: System&lt;BR /&gt;- name: Application&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;YAML Test is "Valid YAML!"&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jchen644219_0-1765351369556.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70081iE2FB693D3B72B59E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jchen644219_0-1765351369556.png" alt="jchen644219_0-1765351369556.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Query Log&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jchen644219_1-1765352148619.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70082i649A758BD71C8EAF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jchen644219_1-1765352148619.png" alt="jchen644219_1-1765352148619.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 10 Dec 2025 07:38:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam-xdr-collector-collect-windows-security-log-xdr/m-p/1243584#M286</guid>
      <dc:creator>j.chen644219</dc:creator>
      <dc:date>2025-12-10T07:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: [Cortex XSIAM ] XDR Collector Collect Windows Security Log。XDR Collectors Administration Status display "Error".</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam-xdr-collector-collect-windows-security-log-xdr/m-p/1245649#M300</link>
      <description>&lt;P&gt;Dear,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Same problem using cortex xdr, i have opened a Tac a days before, below what they said:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;//***************************//&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hi Fabrizio,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Greetings of the day!&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thank you for your patience.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I would like to update you that if the profile running on this machine—or the YAML configuration applied—is only a Winlogbeat profile, then this error is expected. As long as the customer has not configured or is not using any Filebeat service on these XDR Collectors, this error can be safely ignored.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Additionally, the backend team is aware of this issue, and it is expected to be fixed in the next release of the XDR Collector.&lt;/SPAN&gt;&lt;BR /&gt;//***************************//&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jan 2026 09:42:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam-xdr-collector-collect-windows-security-log-xdr/m-p/1245649#M300</guid>
      <dc:creator>F.Ronchi</dc:creator>
      <dc:date>2026-01-15T09:42:51Z</dc:date>
    </item>
    <item>
      <title>回應： [Cortex XSIAM ] XDR Collector Collect Windows Security Log。XDR Collectors Administration Status display "Error".</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam-xdr-collector-collect-windows-security-log-xdr/m-p/1245712#M301</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Anothenr one solution :&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- Add Filebeat profile for X&lt;SPAN&gt;DR Collector Logs&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- Aplly&amp;nbsp; winlogbet and filebeat Profile on policy&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;- View target status on XDR Collctors Administration&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This necessitated the collection of additional xdr logs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jchen644219_0-1768527313806.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70370i34A7BE4C6410E51D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jchen644219_0-1768527313806.png" alt="jchen644219_0-1768527313806.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jchen644219_1-1768527333788.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70371i610319AFCE18D3EB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jchen644219_1-1768527333788.png" alt="jchen644219_1-1768527333788.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2026 01:39:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam-xdr-collector-collect-windows-security-log-xdr/m-p/1245712#M301</guid>
      <dc:creator>j.chen644219</dc:creator>
      <dc:date>2026-01-16T01:39:17Z</dc:date>
    </item>
  </channel>
</rss>

