<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic [Cortex XDR ]  Does Broker VM support tandem log dumping? Can you dump to more than 2 external storage systems at the same time (3rd party SIEM...) in Endpoint (Traps) Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/cortex-xdr-does-broker-vm-support-tandem-log-dumping-can-you/m-p/589679#M1152</link>
    <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;
&lt;P&gt;I have encountered two Broker VM log collection and dumping problems want to ask, and then please help you help, the problem is as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.&amp;nbsp;Can Broker VM tandem dump logs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;Description:&amp;nbsp;As shown in the figure below, a customer wants to collect external syslogs through the syslog collector function of Broker VM A, but instead of uploading the collected logs to Cortex Data Lake directly, the customer will dump them to another Broker VM B, which will upload the logs to the Data Lake, Is this part supported and is it possible? How to configure it?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SLin576639_0-1718603034022.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60382i6917BACBF9CDD43F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="SLin576639_0-1718603034022.png" alt="SLin576639_0-1718603034022.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.&amp;nbsp;Can you dump to more than 2 external storage systems at the same time (3rd party SIEM...)&lt;/P&gt;
&lt;P&gt;In addition to collecting external syslog information through the syslog collector function, can Broker VM dump these logs? For example, in the figure below, after collecting syslog information through Broker VM syslog collector =&amp;gt; When uploading the data to Data Lake, is it possible to export the data to other storage systems (e.g. third-party SIEM system, Syslog Receiver, Database) for saving?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SLin576639_1-1718603270171.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60383iB4BDE23EF1B0E4F8/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="SLin576639_1-1718603270171.png" alt="SLin576639_1-1718603270171.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you in advance for your help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Jun 2024 05:48:56 GMT</pubDate>
    <dc:creator>S.Lin576639</dc:creator>
    <dc:date>2024-06-17T05:48:56Z</dc:date>
    <item>
      <title>[Cortex XDR ]  Does Broker VM support tandem log dumping? Can you dump to more than 2 external storage systems at the same time (3rd party SIEM...)</title>
      <link>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/cortex-xdr-does-broker-vm-support-tandem-log-dumping-can-you/m-p/589679#M1152</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;
&lt;P&gt;I have encountered two Broker VM log collection and dumping problems want to ask, and then please help you help, the problem is as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.&amp;nbsp;Can Broker VM tandem dump logs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;Description:&amp;nbsp;As shown in the figure below, a customer wants to collect external syslogs through the syslog collector function of Broker VM A, but instead of uploading the collected logs to Cortex Data Lake directly, the customer will dump them to another Broker VM B, which will upload the logs to the Data Lake, Is this part supported and is it possible? How to configure it?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SLin576639_0-1718603034022.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60382i6917BACBF9CDD43F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="SLin576639_0-1718603034022.png" alt="SLin576639_0-1718603034022.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.&amp;nbsp;Can you dump to more than 2 external storage systems at the same time (3rd party SIEM...)&lt;/P&gt;
&lt;P&gt;In addition to collecting external syslog information through the syslog collector function, can Broker VM dump these logs? For example, in the figure below, after collecting syslog information through Broker VM syslog collector =&amp;gt; When uploading the data to Data Lake, is it possible to export the data to other storage systems (e.g. third-party SIEM system, Syslog Receiver, Database) for saving?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SLin576639_1-1718603270171.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60383iB4BDE23EF1B0E4F8/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="SLin576639_1-1718603270171.png" alt="SLin576639_1-1718603270171.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you in advance for your help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 05:48:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/cortex-xdr-does-broker-vm-support-tandem-log-dumping-can-you/m-p/589679#M1152</guid>
      <dc:creator>S.Lin576639</dc:creator>
      <dc:date>2024-06-17T05:48:56Z</dc:date>
    </item>
  </channel>
</rss>

