Activate Database Collector
Learn more about activating a Broker VM with a Database Collector applet.
Note
This data source is only available in your tenant if the tenant was activated before October 1, 2025 with an active Cortex XDR Pro per GB license.
The Broker VM provides a Database Collector applet that enables you to collect data from a client relational database directly to your log repository for query and visualization purposes. After you activate the Database Collector applet on a Broker VM in your network, you can collect records as datasets by defining the following:
Database connection details, where the connection type can be MySQL, PostgreSQL, MSSQL, and Oracle. Cortex XDR uses Open Database Connectivity (ODBC) to access the databases.
Settings related to the query details for collecting the data from the database to monitor and upload to Cortex XDR.
Prerequisite
Kerberos authentication for MSSQL:
DNS resolution: The Broker VM must resolve and reach the Active Directory. Domain controllers serve as the Kerberos KDC. Configure DNS on the Broker VM so it can locate the domain.
Network access to the KDC: The Broker VM must have open network connectivity to reach the Active Directory domain controllers for Kerberos authentication.
Time synchronization: The Broker VM's clock must be tightly synchronized with the Active Directory domain. Kerberos security protocols strictly reject authentication requests if there is a significant clock difference.
Service Principal Name (SPN): The target SQL Server instance must have a valid SPN registered within Active Directory.
How to activate the Database Collector
Select Settings → Configurations → Data Broker → Broker VMs.
Do one of the following:
On the Brokers tab, find the Broker VM, and in the APPS column, left-click Add → DB Collector.
On the Clusters tab, find the Broker VM, and in the APPS column, left-click Add → DB Collector.
Configure your Database Collector settings.
(Optional) Click Add Connection to define another database connection to collect data from another client relational database.
(Optional) Other available options.
As needed, you can return to your Database Collector settings to manage your connections. Here are the actions available to you:
Edit the connection name by hovering over the default Collection name, and selecting the edit icon to edit the text.
Edit the query name by hovering over the default Query name, and selecting the edit icon to edit the text.
Disable/Enable a query by hovering over the top area of the query section, on the opposite side of the query name, and selecting the applicable button.
Delete a connection by hovering over the top area of the connection section, on the opposite side of the connection name, and selecting the delete icon. You can only delete a connection when you have more than one connection configured. Otherwise, this icon is not displayed.
Delete a query by hovering over the top area of the query section, on the opposite side of the query name, and selecting the delete icon. You can only delete a query when you have more than one query configured. Otherwise, this icon is not displayed.
Activate the Database Collector applet.
After a successful activation, the APPS field displays DB with a green dot indicating a successful connection.
(Optional) To view metrics about the Database Collector, left-click the DB connection in the APPS field for your Broker VM.
Cortex XDR displays Resources, including the amount of CPU, Memory, and Disk space the applet is using.
Manage the Database Collector.
After you activate the Database Collector, you can make additional changes as needed. To modify a configuration, left-click the DB connection in the APPS column to display the Database Collector settings, and select:
Configure to redefine the Database Collector configurations.
Deactivate to disable the Database Collector.
Last updated
Was this helpful?
