The **Broker VM** provides a **Registry Scanner** applet that scans and secures your container image registries. It supports Docker V2 or JFrog self-hosted registries located on-premises or in private cloud networks.
**License type:** Requires a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM product that has the Cloud Posture security or the Cloud Runtime Security add-on.
**Note**
* You cannot activate the **Registry Scanner** directly on a new or existing Broker VM. You can only activate or deactivate existing Registry Scanner applets. To activate or deactivate existing applets, see **Step 4** under [Verify Registry Scanner connection](#verify-registry-scanner-connection) section.
### **Verify Registry Scanner connection**
After the registry scanner is initialized, perform the following steps to verify that the **Registry Scanner** applet is connected to the **Broker VM**:
### Prerequisite:
* To initialize registry scanning on your Broker VM, you must first add the necessary data connectors. For details, see:
* [Connect Docker Hub registry](../../vendor-specific-data-sources-and-connectors/docker/connect-docker-hub-registry)
* [Connect Docker V2 compliant container registry](../../vendor-specific-data-sources-and-connectors/docker/connect-docker-v2-compliant-container-registry)
* [Connect GitLab container registry](../../vendor-specific-data-sources-and-connectors/gitlab/connect-gitlab-container-registry)
* [Connect Harbor registry](../../vendor-specific-data-sources-and-connectors/harbor/connect-harbor-registry)
* [Connect JFrog container registry](../../vendor-specific-data-sources-and-connectors/jfrog/connect-jfrog-container-registry)
* [Connect Sonatype Nexus registry](../../vendor-specific-data-sources-and-connectors/sonatype-nexus/connect-sonatype-nexus-registry)
* When sizing your Broker VM, consider the following recommendations:
* **Disk Size:** Calculate the required disk space by multiplying the average container image size in your environment by 10. This factor accounts for simultaneous operations with a buffer.
For example, If your average image size is 500 MB, allocate at least 5 GB of disk space (500 MB \* 10 = 5000 MB = 5 GB).
* **CPU:** Allocate a minimum of 8 CPU cores.
* **Memory:** Allocate a minimum of 16 GB of RAM.
1. Go to **Settings** → **Configurations** → **Data Broker** → **Broker VMs**.
2. On either the **Brokers** or **Clusters tab**, find the Broker VM.
3. In the **APPS** column for the **Broker VM**, verify that the **Registry Scanner** app appears.
4. Select the **Registry Scanner** app to open a window displaying the following information:

* **Connection**: Shows the app's current connection status. You can also **Deactivate** the app.
To reactivate the **Registry Scanner** app, do one of the following:
* On the **Brokers** tab, locate the Broker VM, select **+Add** in the **APPS** column, and then choose **Registry Scanner**.
* On the **Clusters** tab, locate the Broker VM, select **+Add** in the **APPS** column, and then choose **Registry Scanner**.
If the **Registry Scanner** app is not listed in the drop-down menu when you click **+Add**, it means that the registry scanning was not configured for that **Broker VM**. You must first add the data connectors.
* **Resources**: Shows the percentage of **CPU**, **Memory**, and **Disk** resources used by the app.
5. To manage the Registry Scanner applet, see:
* [Manage a Docker Hub connector](../../vendor-specific-data-sources-and-connectors/docker/connect-docker-hub-registry/manage-a-docker-hub-connector)
* [Manage a Docker V2 connector](../../vendor-specific-data-sources-and-connectors/docker/connect-docker-v2-compliant-container-registry/manage-a-docker-v2-connector)
* [Manage a Gitlab Container Registry connector](../../vendor-specific-data-sources-and-connectors/gitlab/connect-gitlab-container-registry/manage-a-gitlab-container-registry-connector)
* [Manage a Harbor connector](../../vendor-specific-data-sources-and-connectors/harbor/connect-harbor-registry/manage-a-harbor-connector)
* [Manage a JFrog connector](../../vendor-specific-data-sources-and-connectors/jfrog/connect-jfrog-container-registry/manage-a-jfrog-connector)
* [Manage a Sonatype connector](../../vendor-specific-data-sources-and-connectors/sonatype-nexus/connect-sonatype-nexus-registry/manage-a-sonatype-connector)