<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XDRC Connection Error in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/xdrc-connection-error/m-p/1250551#M380</link>
    <description>&lt;P data-end="249" data-start="228"&gt;Hello SeanDeHarris,&lt;/P&gt;
&lt;P data-end="249" data-start="228"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="393" data-start="251"&gt;Please review the warning descriptions below. If the descriptions match your observations, kindly follow the troubleshooting steps provided.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="informaltable frame-void rules-rows"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="106.55px" height="112px" class="lia-align-center"&gt;
&lt;H5&gt;&lt;STRONG&gt;XDRC Log Collector Type&lt;/STRONG&gt;&lt;/H5&gt;
&lt;/TD&gt;
&lt;TD width="73.95px" height="112px" class="lia-align-center"&gt;
&lt;H5&gt;&lt;STRONG&gt;Event Type&lt;/STRONG&gt;&lt;/H5&gt;
&lt;/TD&gt;
&lt;TD width="224.1px" height="112px" class="lia-align-center"&gt;
&lt;H5&gt;&lt;STRONG&gt;Message in the XDR Collectors Administration Page and Description in the collection_auditing dataset&lt;/STRONG&gt;&lt;/H5&gt;
&lt;/TD&gt;
&lt;TD width="461.183px" height="112px" class="lia-align-center"&gt;
&lt;H5&gt;&lt;STRONG&gt;Root Cause&lt;/STRONG&gt;&lt;/H5&gt;
&lt;/TD&gt;
&lt;TD width="169.933px" height="112px" class="lia-align-center"&gt;
&lt;P&gt;&lt;STRONG&gt;Recommended Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="106.55px" height="179px" class="td"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Filebeat / Winlogbeat&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="73.95px" height="179px" class="td"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Warning&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="224.1px" height="179px" class="td"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Filebeat / Winlogbeat not installed&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="461.183px" height="179px" class="td"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;The Filebeat / Winlogbeat file is missing at the content folder:"C:\ProgramData\XDR Collector\Data\content\filebeat-windows-x86_64\filebeat.exe""C:\ProgramData\XDR Collector\Data\content\winlogbeat-windows-x86_64\winlogbeat.exe"&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="169.933px" height="179px" class="td"&gt;
&lt;DIV class="orderedlist"&gt;
&lt;OL class="orderedlist" type="1"&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Stop the collector.&lt;/FONT&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Delete the Data folder.&lt;/FONT&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Start the collector.&lt;/FONT&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="106.55px" height="117px"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;XDRC&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="73.95px" height="117px"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Warning&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="224.1px" height="117px"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;No incoming data for more than 24 hours&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="461.183px" height="117px"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;The Filebeat / Winlogbeat didn't upload new data in the last 24 hours since the last upload.&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="169.933px" height="117px"&gt;
&lt;DIV class="orderedlist"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Check why the configured files no longer receive log files to upload.&lt;/FONT&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="106.55px" height="30px"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;XDRC&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="73.95px" height="30px"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Warning&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="224.1px" height="30px"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;No incoming data for more than 7 days&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="461.183px" height="30px"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;The Filebeat / Winlogbeat didn't upload new data for the last 7 days since the last upload.&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="169.933px" height="30px"&gt;
&lt;DIV class="orderedlist"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Check why the configured files no longer receive log files to upload.&lt;/FONT&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;H2 data-end="228" data-start="161" data-section-id="htkngk"&gt;&lt;SPAN&gt;Step 1: Check if Filebeat / Winlogbeat processes are running&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P style="margin: 0px;" data-end="295" data-start="232"&gt;&lt;SPAN&gt;1. On the collector server, open Task Manager (or PowerShell).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="326" data-start="299"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="326" data-start="299"&gt;&lt;SPAN&gt;2. Look for these processes:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="348" data-start="332"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="348" data-start="332"&gt;&lt;SPAN&gt;- &lt;CODE data-end="346" data-start="332"&gt;filebeat.exe&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="372" data-start="354"&gt;&lt;SPAN&gt;- &lt;CODE data-end="370" data-start="354"&gt;winlogbeat.exe&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="438" data-start="376"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="438" data-start="376"&gt;&lt;SPAN&gt;3. If they are not running, the collector cannot send logs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="438" data-start="376"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="461" data-start="440"&gt;&lt;SPAN&gt;If not running:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="494" data-start="464"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="494" data-start="464"&gt;&lt;SPAN&gt;- Start the collector service:&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute inset-x-4 top-12 bottom-4"&gt;
&lt;DIV class="pointer-events-none sticky z-40 shrink-0 z-1!"&gt;
&lt;DIV class="sticky bg-token-border-light"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;&lt;SPAN class="ͼt"&gt;net&lt;/SPAN&gt; &lt;SPAN class="ͼs"&gt;start&lt;/SPAN&gt; &lt;SPAN class="ͼr"&gt;"XDR Collector"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;HR data-end="543" data-start="540" /&gt;
&lt;H2 data-end="585" data-start="545" data-section-id="vwi44t"&gt;&lt;SPAN&gt;Step 2: Verify the log file paths&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P style="margin: 0px;" data-end="640" data-start="589"&gt;&lt;SPAN&gt;1. Check which files are configured to be collected:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="738" data-start="646"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="738" data-start="646"&gt;&lt;SPAN&gt;- Filebeat: &lt;CODE data-end="736" data-start="656"&gt;C:\ProgramData\XDR Collector\Data\content\filebeat-windows-x86_64\filebeat.yml&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="842" data-start="744"&gt;&lt;SPAN&gt;- Winlogbeat: &lt;CODE data-end="840" data-start="756"&gt;C:\ProgramData\XDR Collector\Data\content\winlogbeat-windows-x86_64\winlogbeat.yml&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="896" data-start="847"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="896" data-start="847"&gt;&lt;SPAN&gt;2. Open the &lt;CODE data-end="862" data-start="856"&gt;.yml&lt;/CODE&gt; configuration files and verify:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1005" data-start="902"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1005" data-start="902"&gt;&lt;SPAN&gt;- Input paths exist (&lt;CODE data-end="961" data-start="921"&gt;C:\Windows\System32\winevt\Logs\*.evtx&lt;/CODE&gt; for Winlogbeat, custom logs for Filebeat)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1039" data-start="1011"&gt;&lt;SPAN&gt;- There are no syntax errors&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR data-end="1044" data-start="1041" /&gt;
&lt;H2 data-end="1078" data-start="1046" data-section-id="rlyjj4"&gt;&lt;SPAN&gt;Step 3: Check permissions&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P style="margin: 0px;" data-end="1185" data-start="1082"&gt;&lt;SPAN&gt;1. Ensure the XDR Collector service account can read the log files and write to the Data folder.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1213" data-start="1189"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1213" data-start="1189"&gt;&lt;SPAN&gt;2. Verify permissions on:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1264" data-start="1219"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1264" data-start="1219"&gt;&lt;SPAN&gt;- &lt;CODE data-end="1262" data-start="1219"&gt;C:\ProgramData\XDR Collector\Data\content&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1328" data-start="1270"&gt;&lt;SPAN&gt;- The directories containing the log files to be collected&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR data-end="1333" data-start="1330" /&gt;
&lt;H2 data-end="1383" data-start="1335" data-section-id="i9dk89"&gt;&lt;SPAN&gt;Step 4: Review Filebeat / Winlogbeat logs&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P style="margin: 0px;" data-end="1412" data-start="1387"&gt;&lt;SPAN&gt;1. Navigate to log folder:&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;C:\ProgramData\XDR Collector\Data\log&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P style="margin: 0px;" data-end="1508" data-start="1466"&gt;&lt;SPAN&gt;2. Open &lt;CODE data-end="1485" data-start="1471"&gt;filebeat.log&lt;/CODE&gt; and &lt;CODE data-end="1506" data-start="1490"&gt;winlogbeat.log&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1535" data-start="1512"&gt;&lt;SPAN&gt;3. Look for errors like:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1557" data-start="1541"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1557" data-start="1541"&gt;&lt;SPAN&gt;- File not found&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1582" data-start="1563"&gt;&lt;SPAN&gt;- Permission denied&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1649" data-start="1588"&gt;&lt;SPAN&gt;- Network errors (cannot reach broker or distribution server)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1649" data-start="1588"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1649" data-start="1588"&gt;&lt;SPAN&gt;Please help out other users and “Accept as Solution” if a post helps solve your problem !&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/blogs/how-and-why-to-accept-solutions/ba-p/553827" target="_blank"&gt;Read more about how and why to accept solutions.&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Mar 2026 10:36:06 GMT</pubDate>
    <dc:creator>Vinothkumar_SBA</dc:creator>
    <dc:date>2026-03-19T10:36:06Z</dc:date>
    <item>
      <title>XDRC Connection Error</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/xdrc-connection-error/m-p/1250435#M378</link>
      <description>&lt;P&gt;Hello experts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have two XDRC installed on W2016 server, both are connected through same BrokerVM. Even tried test if the BVM and XDRC connection was fine, I did a test to run "uninstall collector" from Console, it was successful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From XDRC Adminsitration, The status shown :Warning, however, the last seen was up to date.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From XQL queries:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;dataset = collection_auditing&lt;/P&gt;
&lt;P&gt;It shown "Failed to get local ip by connecting to server address: 'distributions.traps.paloaltonetworks.com'."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SSH to the BVM&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. openssl s_client -connect distributions.traps.paloaltonetworks.com:443&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. ping&amp;nbsp;distributions.traps.paloaltonetworks.com&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Both succeeded.&amp;nbsp;&lt;BR /&gt;Any ides?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XSIAM" id="Cortex_XSIAM"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2026 09:24:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/xdrc-connection-error/m-p/1250435#M378</guid>
      <dc:creator>SeanDeHarris</dc:creator>
      <dc:date>2026-03-18T09:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: XDRC Connection Error</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/xdrc-connection-error/m-p/1250551#M380</link>
      <description>&lt;P data-end="249" data-start="228"&gt;Hello SeanDeHarris,&lt;/P&gt;
&lt;P data-end="249" data-start="228"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="393" data-start="251"&gt;Please review the warning descriptions below. If the descriptions match your observations, kindly follow the troubleshooting steps provided.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="informaltable frame-void rules-rows"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="106.55px" height="112px" class="lia-align-center"&gt;
&lt;H5&gt;&lt;STRONG&gt;XDRC Log Collector Type&lt;/STRONG&gt;&lt;/H5&gt;
&lt;/TD&gt;
&lt;TD width="73.95px" height="112px" class="lia-align-center"&gt;
&lt;H5&gt;&lt;STRONG&gt;Event Type&lt;/STRONG&gt;&lt;/H5&gt;
&lt;/TD&gt;
&lt;TD width="224.1px" height="112px" class="lia-align-center"&gt;
&lt;H5&gt;&lt;STRONG&gt;Message in the XDR Collectors Administration Page and Description in the collection_auditing dataset&lt;/STRONG&gt;&lt;/H5&gt;
&lt;/TD&gt;
&lt;TD width="461.183px" height="112px" class="lia-align-center"&gt;
&lt;H5&gt;&lt;STRONG&gt;Root Cause&lt;/STRONG&gt;&lt;/H5&gt;
&lt;/TD&gt;
&lt;TD width="169.933px" height="112px" class="lia-align-center"&gt;
&lt;P&gt;&lt;STRONG&gt;Recommended Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="106.55px" height="179px" class="td"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Filebeat / Winlogbeat&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="73.95px" height="179px" class="td"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Warning&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="224.1px" height="179px" class="td"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Filebeat / Winlogbeat not installed&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="461.183px" height="179px" class="td"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;The Filebeat / Winlogbeat file is missing at the content folder:"C:\ProgramData\XDR Collector\Data\content\filebeat-windows-x86_64\filebeat.exe""C:\ProgramData\XDR Collector\Data\content\winlogbeat-windows-x86_64\winlogbeat.exe"&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="169.933px" height="179px" class="td"&gt;
&lt;DIV class="orderedlist"&gt;
&lt;OL class="orderedlist" type="1"&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Stop the collector.&lt;/FONT&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Delete the Data folder.&lt;/FONT&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Start the collector.&lt;/FONT&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="106.55px" height="117px"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;XDRC&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="73.95px" height="117px"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Warning&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="224.1px" height="117px"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;No incoming data for more than 24 hours&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="461.183px" height="117px"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;The Filebeat / Winlogbeat didn't upload new data in the last 24 hours since the last upload.&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="169.933px" height="117px"&gt;
&lt;DIV class="orderedlist"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Check why the configured files no longer receive log files to upload.&lt;/FONT&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="106.55px" height="30px"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;XDRC&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="73.95px" height="30px"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Warning&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="224.1px" height="30px"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;No incoming data for more than 7 days&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="461.183px" height="30px"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;The Filebeat / Winlogbeat didn't upload new data for the last 7 days since the last upload.&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="169.933px" height="30px"&gt;
&lt;DIV class="orderedlist"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Check why the configured files no longer receive log files to upload.&lt;/FONT&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;H2 data-end="228" data-start="161" data-section-id="htkngk"&gt;&lt;SPAN&gt;Step 1: Check if Filebeat / Winlogbeat processes are running&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P style="margin: 0px;" data-end="295" data-start="232"&gt;&lt;SPAN&gt;1. On the collector server, open Task Manager (or PowerShell).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="326" data-start="299"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="326" data-start="299"&gt;&lt;SPAN&gt;2. Look for these processes:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="348" data-start="332"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="348" data-start="332"&gt;&lt;SPAN&gt;- &lt;CODE data-end="346" data-start="332"&gt;filebeat.exe&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="372" data-start="354"&gt;&lt;SPAN&gt;- &lt;CODE data-end="370" data-start="354"&gt;winlogbeat.exe&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="438" data-start="376"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="438" data-start="376"&gt;&lt;SPAN&gt;3. If they are not running, the collector cannot send logs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="438" data-start="376"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="461" data-start="440"&gt;&lt;SPAN&gt;If not running:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="494" data-start="464"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="494" data-start="464"&gt;&lt;SPAN&gt;- Start the collector service:&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute inset-x-4 top-12 bottom-4"&gt;
&lt;DIV class="pointer-events-none sticky z-40 shrink-0 z-1!"&gt;
&lt;DIV class="sticky bg-token-border-light"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;&lt;SPAN class="ͼt"&gt;net&lt;/SPAN&gt; &lt;SPAN class="ͼs"&gt;start&lt;/SPAN&gt; &lt;SPAN class="ͼr"&gt;"XDR Collector"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;HR data-end="543" data-start="540" /&gt;
&lt;H2 data-end="585" data-start="545" data-section-id="vwi44t"&gt;&lt;SPAN&gt;Step 2: Verify the log file paths&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P style="margin: 0px;" data-end="640" data-start="589"&gt;&lt;SPAN&gt;1. Check which files are configured to be collected:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="738" data-start="646"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="738" data-start="646"&gt;&lt;SPAN&gt;- Filebeat: &lt;CODE data-end="736" data-start="656"&gt;C:\ProgramData\XDR Collector\Data\content\filebeat-windows-x86_64\filebeat.yml&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="842" data-start="744"&gt;&lt;SPAN&gt;- Winlogbeat: &lt;CODE data-end="840" data-start="756"&gt;C:\ProgramData\XDR Collector\Data\content\winlogbeat-windows-x86_64\winlogbeat.yml&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="896" data-start="847"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="896" data-start="847"&gt;&lt;SPAN&gt;2. Open the &lt;CODE data-end="862" data-start="856"&gt;.yml&lt;/CODE&gt; configuration files and verify:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1005" data-start="902"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1005" data-start="902"&gt;&lt;SPAN&gt;- Input paths exist (&lt;CODE data-end="961" data-start="921"&gt;C:\Windows\System32\winevt\Logs\*.evtx&lt;/CODE&gt; for Winlogbeat, custom logs for Filebeat)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1039" data-start="1011"&gt;&lt;SPAN&gt;- There are no syntax errors&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR data-end="1044" data-start="1041" /&gt;
&lt;H2 data-end="1078" data-start="1046" data-section-id="rlyjj4"&gt;&lt;SPAN&gt;Step 3: Check permissions&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P style="margin: 0px;" data-end="1185" data-start="1082"&gt;&lt;SPAN&gt;1. Ensure the XDR Collector service account can read the log files and write to the Data folder.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1213" data-start="1189"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1213" data-start="1189"&gt;&lt;SPAN&gt;2. Verify permissions on:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1264" data-start="1219"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1264" data-start="1219"&gt;&lt;SPAN&gt;- &lt;CODE data-end="1262" data-start="1219"&gt;C:\ProgramData\XDR Collector\Data\content&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1328" data-start="1270"&gt;&lt;SPAN&gt;- The directories containing the log files to be collected&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR data-end="1333" data-start="1330" /&gt;
&lt;H2 data-end="1383" data-start="1335" data-section-id="i9dk89"&gt;&lt;SPAN&gt;Step 4: Review Filebeat / Winlogbeat logs&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P style="margin: 0px;" data-end="1412" data-start="1387"&gt;&lt;SPAN&gt;1. Navigate to log folder:&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;C:\ProgramData\XDR Collector\Data\log&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P style="margin: 0px;" data-end="1508" data-start="1466"&gt;&lt;SPAN&gt;2. Open &lt;CODE data-end="1485" data-start="1471"&gt;filebeat.log&lt;/CODE&gt; and &lt;CODE data-end="1506" data-start="1490"&gt;winlogbeat.log&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1535" data-start="1512"&gt;&lt;SPAN&gt;3. Look for errors like:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1557" data-start="1541"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1557" data-start="1541"&gt;&lt;SPAN&gt;- File not found&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1582" data-start="1563"&gt;&lt;SPAN&gt;- Permission denied&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1649" data-start="1588"&gt;&lt;SPAN&gt;- Network errors (cannot reach broker or distribution server)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1649" data-start="1588"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0px;" data-end="1649" data-start="1588"&gt;&lt;SPAN&gt;Please help out other users and “Accept as Solution” if a post helps solve your problem !&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/blogs/how-and-why-to-accept-solutions/ba-p/553827" target="_blank"&gt;Read more about how and why to accept solutions.&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2026 10:36:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/xdrc-connection-error/m-p/1250551#M380</guid>
      <dc:creator>Vinothkumar_SBA</dc:creator>
      <dc:date>2026-03-19T10:36:06Z</dc:date>
    </item>
  </channel>
</rss>

