XDR Collectors installation resource for Windows and Linux
Cortex XDR Collectors installation resource for Windows and Linux.
The following table provides important information about the XDR Collectors installation for Windows and Linux.
Installation folder
Windows:
%PROGRAMFILES%\Palo Alto Networks\XDR CollectorLinux:
/opt/paloaltonetworks/xdr-collector
The default installation path for the XDR Collector. Contains all Program Core files and executables.
Windows
Service name:
XDR CollectorProcess name:
xdrcollectorsvc.exe
Linux
Service name:
xcdProcess name:
xdr-collector.service
Logs
Windows:
%PROGRAMDATA%\XDR Collector\logsLinux:
/opt/paloaltonetworks/xdr-collector/logs
Windows: Contains the XDR Collector application Log, the Filebeat application log, and the Winlogbeat application log. Indicates information, warnings, and errors related to the XDR Collector application.
Linux: Contains the XDR Collector application Log as well as the Filebeat application log. Indicates information, warnings, and errors related to the XDR Collector application.
Contains the XDR Collector application Log as well as the Filebeat application log. Indicates information, warnings, and errors related to the XDR Collector application.
Windows
scouter.logfilebeatwinlogbeat
Linux
scouter.logfilebeat
Configuration
Windows:
%PROGRAMFILES%\Palo Alto Networks\XDR Collector\configLinux:
/opt/paloaltonetworks/xdr-collector/config
Contains the XML configuration file of the XDR Collector for both Windows and Linux.
Any change in this XML configuration file is saved to the XDR Collector database and the settings are taken from this file.
For both Windows and Linux, the file name is XDR_Collector.xml.
Persistence
Windows:
%PROGRAMDATA%\XDR Collector\OSPersistenceLinux:
/etc/panw/OSPersistence/
Contains the Operating System persistence file for the XDR Collector, which issued as part of the registration process.
For both Windows and Linux, the file name is .scouter.json.
Last updated
Was this helpful?
