Open Live Terminal ↗
Learn more about remotely connecting to a Cortex XSIAM Broker VM.
Cortex XSIAM enables you to connect remotely to a Broker VM directly from Cortex XSIAM.
- In Cortex XSIAM, select Settings → Configurations → Data Broker → Broker VMs table.
- Locate the Broker VM you want to connect to, right-click and select Open Live Terminal. Cortex XSIAM opens a CLI window where you can perform the following commands:
Logs
Broker VM logs are located in /data/logs/folder and contain the applet name in the file name. Example 19. Folder /data/logs/[applet name], containing container_ctrl_[applet name].log
Administration commands
Broker VM supports the commands listed in the following table. All the commands are located in the /home/admin/sbin folder.
Applet Names
- CSV Collector:
file_collector - Database Collector:
db_collector - Files and Folders Collector:
log_collector - FTP Collector:
ftp_collector - Kafka Collector:
kafka_collector - Local Agent Settings:
tms_proxy - NetFlow Collector:
netflow_collector - Network Mapper:
network_mapper - Syslog Collector:
anubis - Windows Event Collector:
wec
Services
- Upgrade:
zenith_upgrade - Frontend service:
webui - Sync with Cortex XSIAM:
cloud_sync - Internal messaging service (RabbitMQ):
rabbitmq-server - Upload metrics to Cortex XSIAM:
metrics_uploader - Prometheus node exporter:
node_exporter - Backend service:
backend
The following table displays the available commands in alphabetical order:
| Command | Description | Example |
|---|---|---|
applets_restart |
Restarts one or more applets. | sudo ./sbin/applets_restart wec |
applets_start |
Start one or more applets. | sudo ./sbin/applets_start wec |
applets_status |
Check the status of one or more applets. | sudo ./sbin/applets_status wec |
applets_stop |
Stop one or more applets. | sudo ./sbin/applets_stop wec |
restart_routes |
Invoke a restart of the routing service after updating your static network route configuration file, /etc/network/routes. The /etc/network/routes configuration file is a standard routes configuration file and can be edited directly. The admin user that you logged in with, when using the remote terminal or via SSH, has read/write permissions to this file. |
sudo ./sbin/restart_routes |
services_restart |
Restarts one or more services. OS services are not supported. | sudo ./sbin/services_restart cloud_sync |
services_start |
Start one or more services. | sudo ./sbin/services_start cloud_sync |
services_status |
Check the status of one or more services. | sudo ./sbin/services_status cloud_sync |
services_stop |
Stop one or more services. | sudo ./sbin/services_restart cloud_sync |
set_ui_password.sh |
Change the password of the Broker VM Web UI. Run the command, enter the new password followed by Ctrl+D. | sudo ./sbin/set_ui_password.sh |
squid_tail |
Display the Proxy applet Squid log file in real-time. | sudo ./sbin/squid_tail |
Note
You can either restart_routes or reboot the Broker VM for the changes in the /etc/network/routes file to take affect.