A collector token leaked — what to do
Each collector has its own token, scoped to that one box. If a collector is compromised, lost, or you can no longer reach it, you don't need to disturb the rest of the fleet — revoke just that collector.
Revoke one collector
On Collectors, open the collector and Revoke it (or use Bulk revoke offline to clear several dead ones at once). Revocation is immediate: that collector's token stops working for ingest and status right away, and it can't inspect traffic anymore.
To bring a replacement online, add a fresh collector (Collectors → Add collector) and run the installer on the host — see Install a collector. The new box enrolls with its own token and lands in pending approval.
What's not affected
Revoking a collector leaves your policy rules, identity mappings, and audit history untouched — they live in the cloud, not on the collector.
Bigger compromise
If you believe your whole workspace is compromised (not just one collector), contact Kilasec — full tenant-token rotation is handled on the Kilasec side so it can be coordinated with re-enrolling every collector without a silent outage.
→ For a collector that's merely unreachable rather than compromised, start with Collector is offline.