<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR + CDL - Raw Log file integrity and tamper protection in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-cdl-raw-log-file-integrity-and-tamper-protection/m-p/474834#M1736</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/189593"&gt;@SaratMuddu&lt;/a&gt;&amp;nbsp;please take a look at the SOC2 compliance reports for XDR and see if it meets your need. If you're not able to retrieve the report, reach out to your Sales rep to be able to assist you with one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as the logs are considered, it is read-only from XQL. Tenants don't have access to the underlying infrastructure that hosts the data at rest.&lt;/P&gt;</description>
    <pubDate>Tue, 22 Mar 2022 01:42:21 GMT</pubDate>
    <dc:creator>bbarmanroy</dc:creator>
    <dc:date>2022-03-22T01:42:21Z</dc:date>
    <item>
      <title>Cortex XDR + CDL - Raw Log file integrity and tamper protection</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-cdl-raw-log-file-integrity-and-tamper-protection/m-p/474727#M1734</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been digging through various Cortex documentations to find explicit language around log integrity, tamper protection of logs from administrators. I am aware that RAW Logs are not accessible to tenant admins however, could you point me in the direction of any documents that explicitly state that all logs ingested by XDR and Data Lake are adequately protected from write and deletion?&amp;nbsp; If there is a setting within in Cortex, that is also acceptable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a common question that we have to address in various audits including ISO 27001. Any guidance on this topic is appreciated. Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 16:11:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-cdl-raw-log-file-integrity-and-tamper-protection/m-p/474727#M1734</guid>
      <dc:creator>SaratMuddu</dc:creator>
      <dc:date>2022-03-21T16:11:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR + CDL - Raw Log file integrity and tamper protection</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-cdl-raw-log-file-integrity-and-tamper-protection/m-p/474834#M1736</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/189593"&gt;@SaratMuddu&lt;/a&gt;&amp;nbsp;please take a look at the SOC2 compliance reports for XDR and see if it meets your need. If you're not able to retrieve the report, reach out to your Sales rep to be able to assist you with one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as the logs are considered, it is read-only from XQL. Tenants don't have access to the underlying infrastructure that hosts the data at rest.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 01:42:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-cdl-raw-log-file-integrity-and-tamper-protection/m-p/474834#M1736</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-03-22T01:42:21Z</dc:date>
    </item>
  </channel>
</rss>

