This information is for Palo Alto Networks Telemetry Pipeline, which is a standalone
product separate from Palo Alto Networks Cortex XCOR.
This feature isn’t available to all Palo Alto Networks Telemetry Pipeline users.
For more information, contact Cortex XCOR Support.
Add a Fluent Bit agent
Requires Fluent Bit v2.1.8 or later.To add a Fluent Bit agent to a fleet:
- YAML configuration
- Classic configuration
YAML configuration is only supported in Palo Alto Networks Telemetry
Pipeline v2.25.0 or later, and requires Fluent Bit v3.2 or later. Additionally, to use YAML
configuration files for individual agents in a fleet, the
fleet_config_legacy_format
parameter in that fleet’s configuration file must be set to false.- If necessary, install a new Fluent Bit agent.
-
Update the
customssection in the configuration file for that agent.Replace the following values:HOST: Your Cortex XCOR hostname. If you don’t know your hostname, ask a Palo Alto Networks representative for this value.KEY: The API token you use to authenticate with Palo Alto Networks Telemetry Pipeline.NAME: The name of the fleet to which your agent will be added.SECONDS: How often, in seconds, this agent should check for configuration updates. If unspecified, defaults to15.NANOSECONDS: How often, in nanoseconds, this agent should check for configuration updates. If unspecified, defaults to0.
-
Run the following command:
Replace
CONFIGwith the name of the configuration file you updated in the previous step.
Add a Core Agent
Requires Core Agent v23.4.5 or later.To add an instance of Core Agent to a fleet:
- YAML configuration
- Classic configuration
YAML configuration is only supported in Palo Alto Networks Telemetry Pipeline v2.25.0 or later,
and requires Core Agent v25.1.1 or later. Additionally, to use YAML
configuration files for individual agents in a fleet, the
fleet_config_legacy_format
parameter in that fleet’s configuration file must be set to false.- If necessary, install a new instance of Core Agent.
-
Update the
customssection in the configuration file for that agent.Replace the following values:HOST: Your Cortex XCOR hostname. If you don’t know your hostname, ask a Palo Alto Networks representative for this value.KEY: The API token you use to authenticate with Palo Alto Networks Telemetry Pipeline.NAME: The name of the fleet to which your agent will be added.SECONDS: How often, in seconds, this agent should check for configuration updates. If unspecified, defaults to15.NANOSECONDS: How often, in nanoseconds, this agent should check for configuration updates. If unspecified, defaults to0.
-
Run the following command:
Replace
CONFIGwith the name of the configuration file you updated in the previous step.