Palo Alto Networks Certified Security Automation Engineer (PCSAE)Cortex XSOAR FundamentalsHard
A security administrator is setting up a new Cortex XSOAR instance and needs to configure logging levels for various components to ensure proper auditing and troubleshooting without overwhelming storage. Where are the primary logging configurations for the XSOAR server itself typically managed?
- AIn the `demisto.json` file on the XSOAR server.
- BVia the XSOAR Web UI settings.
- CThrough environment variables.
- DIn the `/etc/demisto/server.conf` file.
Show answer & explanationAnswer & explanation
Correct answer: D. In the `/etc/demisto/server.conf` file.
The primary logging configurations for the Cortex XSOAR server, including log levels and output destinations, are managed within the `server.conf` file, located in `/etc/demisto/`. This allows for granular control over server-side logging behavior.
Why the other options are wrong
- A. `demisto.json` is not the standard file for server logging configuration; `server.conf` is used for this purpose.
- B. While some integration logging might be configured via the UI, core server logging levels are typically not managed here.
- C. Environment variables can influence some settings, but `server.conf` is the primary and comprehensive method for logging configuration.
XSOAR Server Logging Configuration
The process of defining log levels, formats, and destinations for the main Cortex XSOAR server component.
- Managed in `/etc/demisto/server.conf`.
- Controls verbosity for auditing and troubleshooting.
- Requires server restart for changes to take effect.
Memory trick: To control the XSOAR server's 'diary', you go to its main instruction book.