> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-endpoints/retrieve-support-file-password.md).

# Retrieve support file password

From Cortex XDR agent, the Tech Support File (TSF) is generated by the Cytool command `log collect` in a zip format that is protected by an encrypted password. The TSF file is archived inside another file which includes a metadata file that contains a token. This token is used to retrieve the password to unzip the TSF file.

There are two methods to retrieve the TSF file password:

<details>

<summary>Retrieve the password from the endpoint, using the server Tokens and Passwords option.</summary>

1. Go to **Inventory →** **Endpoints** → **All Endpoints.**
2. At the top of the page, click the key icon <img src="/files/SqBuvTNvi3HHDoH3a1zP" alt="Screenshot_2025-08-04_at_15_40_52.png" data-size="line"> (**Tokens and Passwords**) and select **Retrieve Support File Password**.
3. In the **Retrieve Support File Password** dialog box, in the **Encrypted Password** field, paste the token that you copied from the metadata file located in the saved file when running the Cytool log collect command.
4. Click the copy button to copy the password displayed and then click **Ok**. Use the password to unzip the TSF file.

</details>

<details>

<summary>Retrieve the password for the TSF file from the server Action Center.</summary>

1. Go to **Action Center → All Actions.**
2. Right-click the action and select **Retrieve Support File Password**.
3. In the **Retrieve Support File Password** dialog box, in the **Encrypted Password** field, paste the token that you copied from the metadata file located in the download file.
4. Click the copy button to copy the password displayed and then click **Ok**. Use the password to unzip the TSF file.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-endpoints/retrieve-support-file-password.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
