File and folders collector

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

File and folders collector

L0 Member

Hi community,

I have questions about setting up file and folder collector.I do not understand what the inclusion of logs of this collector gives us.How can I view all files of any formats that are in the folder?What is the vendor and product responsible for?I ask you to bring an example, in the official guide it is written very briefly

Cortex XDR  

1 REPLY 1

L3 Networker

Hi Ulkar, 

 

What this collector is gives us ?

Actually this is directly related what you want to collect and analyses. This collector might read, application logs or network device logs, OS logs etc. changes based on your scenario. 

You cannot view remotely formats but you can filter remotely what you want to collect. 

You can use wildcard in "Include" part. (like *.json)

 

Product and Vendor is generally helping for automatic parsing or keeping data in specific dataset. 

If you write Vendor = X and Product = Y 

Your collected data will be in X_Y_raw dataset.

 

I hope that helps

  • 999 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!