nerdexam
Palo_Alto_Networks

XSIAM-ENGINEER · Question #25

An application which ingests custom application logs is hosted in an on-premises virtual environment on an Ubuntu server, and it logs locally to a .csv file. Which set of actions will allow the…

The correct answer is A. Install a Broker VM in the environment, and configure the CSV Collector to collect the files of. The correct approach is to install a Broker VM in the environment and configure its CSV Collector applet to ingest the .csv log files directly from the Ubuntu server. This enables secure ingestion of custom application logs into Cortex XSIAM without modifying the application or…

Data Ingestion and Log Management

Question

An application which ingests custom application logs is hosted in an on-premises virtual environment on an Ubuntu server, and it logs locally to a .csv file. Which set of actions will allow the ingestion of the .csv logs into Cortex XSIAM directly from the server?

Options

  • AInstall a Broker VM in the environment, and configure the CSV Collector to collect the files of
  • BInstall a Cortex XDR agent on the Ubuntu server, and configure the agent to collect the files of
  • CInstall a Broker VM in the environment, and migrate the application to the Broker VM.
  • DInstall XDR Collector on the Ubuntu server, and configure the agent to collect the files of interest.

How the community answered

(46 responses)
  • A
    76% (35)
  • B
    7% (3)
  • C
    4% (2)
  • D
    13% (6)

Explanation

The correct approach is to install a Broker VM in the environment and configure its CSV Collector applet to ingest the .csv log files directly from the Ubuntu server. This enables secure ingestion of custom application logs into Cortex XSIAM without modifying the application or requiring an XDR agent on the server.

Topics

#log ingestion#Broker VM#CSV Collector#on-premises integration

Community Discussion

No community discussion yet for this question.

Full XSIAM-ENGINEER Practice