Activate CSV Collector
Learn more about activating the Broker VM with a CSV Collector applet.
Note
This data source is only available in your tenant if the tenant was activated before October 1, 2025 with an active Cortex XDR Pro per GB license.
The Broker VM provides a CSV Collector applet that enables you to monitor and collect CSV (comma-separated values) log files from a shared Windows directory directly to your log repository for query and visualization purposes. After you activate the CSV Collector applet on a Broker VM in your network, you can ingest CSV files as datasets by defining the list of folders mounted to the Broker VM and setting the list of CSV files to monitor and upload to Cortex XDR using a username and password.
Prerequisite
Ensure that you share the applicable CSV files.
Know the complete file path for the Windows directory.
How to activate the CSV Collector
Select Settings → Configurations → Data Broker → Broker VMs.
Do one of the following:
On the Brokers tab, find the Broker VM, and in the APPS column, left-click Add → CSV Collector.
On the Clusters tab, find the Broker VM, and in the APPS column, left-click Add → CSV Collector.
Configure your CSV Collector by defining the list of folders mounted to the Broker VM and specifying the list of CSV files to monitor and upload to Cortex XDR. You must also specify a username and password.
(Optional) To view metrics about the CSV Collector, left-click the CSV connection in the APPS field for your Broker VM.
Cortex XDR displays Resources, including the amount of CPU, Memory, and Disk space the applet is using.
Manage the CSV Collector.
After you activate the CSV Collector, you can make additional changes as needed. To modify a configuration, left-click the CSV connection in the APPS column to display the CSV settings, and select:
Configure to redefine the CSV Collector configurations.
Deactivate to disable the CSV Collector.
Last updated
Was this helpful?
