Cortex XSOAR keeps a detailed list of logs that are automatically generated when activities take place in the environment, such as when issues arise or for verifying system information. These logs can be used to help your organisation troubleshoot any issues or oddities that might occur within your Cortex XSOAR application.
By default, logs are stored in the following location:
There are four kinds of logs that are generated here automatically:
Note: to locate issues efficiently, you can filter with the “error” field.
Logs can also be batched into bundles.
To retrieve logs, multiple files can be bundled together into a single zip file which can then be forwarded to the right support personnel to debug and troubleshoot. Any time you create a bundle, these will also appear in the same location where your logs are stored (/var/log/demisto/).
To go about creating your log bundle follow these steps:
First, head to Settings > About > Troubleshooting
There, click on Download logs.
When you do so, your bundle will contain the follow types of logs:
And there you have it. By following the steps listed above you should have no issues accessing your XSOAR logs.
Metron Labs is a Palo Alto Networks XSOAR Development partner. Metron builds certified XSOAR application/integration, publish it in Cortex Marketplace, and maintain the integration for upgrades as well. In addition, Metron designs custom XSOAR playbooks.
If you are considering a XSOAR Development Partner that focuses building a certified XSOAR application and maintaining your XSOAR playbooks, please send a note to firstname.lastname@example.org