Open Live Terminal

Learn more about remotely connecting to a Cortex XSIAM Broker VM.

Cortex XSIAM enables you to connect remotely to a Broker VM directly from Cortex XSIAM.

1. In Cortex XSIAM, select Settings → Configurations → Data Broker → Broker VMs table.
2. Locate the Broker VM you want to connect to, right-click and select Open Live Terminal. Cortex XSIAM opens a CLI window where you can perform the following commands:

#### Logs

Broker VM logs are located in `/data/logs/folder` and contain the applet name in the file name. Example 19. Folder `/data/logs/[applet name]`, containing `container_ctrl_[applet name].log`

#### Administration commands

Broker VM supports the commands listed in the following table. All the commands are located in the `/home/admin/sbin` folder.

#### Applet Names

* CSV Collector: `file_collector`
* Database Collector: `db_collector`
* Files and Folders Collector: `log_collector`
* FTP Collector: `ftp_collector`
* Kafka Collector: `kafka_collector`
* Local Agent Settings: `tms_proxy`
* NetFlow Collector: `netflow_collector`
* Network Mapper: `network_mapper`
* Syslog Collector: `anubis`
* Windows Event Collector: `wec`

#### Services

* Upgrade: `zenith_upgrade`
* Frontend service: `webui`
* Sync with Cortex XSIAM: `cloud_sync`
* Internal messaging service (RabbitMQ): `rabbitmq-server`
* Upload metrics to Cortex XSIAM: `metrics_uploader`
* Prometheus node exporter: `node_exporter`
* Backend service: `backend`

The following table displays the available commands in alphabetical order:

| Command | Description | Example |
| -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------- |
| `applets_restart` | Restarts one or more applets. | `sudo ./sbin/applets_restart wec` |
| `applets_start` | Start one or more applets. | `sudo ./sbin/applets_start wec` |
| `applets_status` | Check the status of one or more applets. | `sudo ./sbin/applets_status wec` |
| `applets_stop` | Stop one or more applets. | `sudo ./sbin/applets_stop wec` |
| `restart_routes` | Invoke a restart of the routing service after updating your static network route configuration file, `/etc/network/routes`. The `/etc/network/routes` configuration file is a standard routes configuration file and can be edited directly. The admin user that you logged in with, when using the remote terminal or via SSH, has read/write permissions to this file. | `sudo ./sbin/restart_routes` |
| `services_restart` | Restarts one or more services. OS services are not supported. | `sudo ./sbin/services_restart cloud_sync` |
| `services_start` | Start one or more services. | `sudo ./sbin/services_start cloud_sync` |
| `services_status` | Check the status of one or more services. | `sudo ./sbin/services_status cloud_sync` |
| `services_stop` | Stop one or more services. | `sudo ./sbin/services_restart cloud_sync` |
| `set_ui_password.sh` | Change the password of the Broker VM Web UI. Run the command, enter the new password followed by Ctrl+D. | `sudo ./sbin/set_ui_password.sh` |
| `squid_tail` | Display the Proxy applet Squid log file in real-time. | `sudo ./sbin/squid_tail` |

#### Note

You can either `restart_routes` or reboot the Broker VM for the changes in the `/etc/network/routes` file to take affect.