Broker VM Log ingestion and forwarding

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Broker VM Log ingestion and forwarding

L1 Bithead

Hi,

 

My query is can we forward one broker VM logs to another broker VM.

 

Use case is I have BVM A and BVM 2,

       1. I want to ingest logs into BVM A from Agents or other log sources.

       2. Then forward logs from BVM A to BVM B.

       3. BVM B will send logs to XDR or XSIAM tenant.

 

I found one way which is by rsyslog or any other syslogs as intermediate between two broker VMs.

 

Anyone have any other method, or any suggestions or best practices to do fullfill mentioned use case.

 

Cortex XDR Cortex XSIAM 

3 REPLIES 3

L5 Sessionator

Hi @P.Ghule, thanks for reaching us using the Live Community.

 

Yes, you can proxy the communication between the two Broker VMs.

You can use the Proxy Server configuration in the Broker VM right-click Configurations menu.

More information in this link, going to Initial Setup - How to configure Broker VM Settings - Proxy Server

 

 

If this post answers your question, please mark it as the solution.

JM

Hi @Jmazzezo , Thanks for the solution It looks relevant to my query.

 

Please tell me by doing this, raw logs from Broker A will be send to tenant or it will redirect to Broker B and B will store it to cloud tenant.

 

You are right @P.Ghule, this is the doc note:

 

You can configure another Broker VM as a proxy server for this Broker VM by selecting the HTTP type. When selecting HTTP to route Broker VM communication, you need to add the IP Address and Port number (set when activating the Agent Proxy) for another Broker VM registered in your tenant. This designates the other Broker VM as a proxy for this Broker VM.

JM
  • 449 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!