<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ingest Logs from Cisco ISE to Cortex XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-logs-from-cisco-ise-to-cortex-xdr/m-p/475305#M1745</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/171314"&gt;@weejh&lt;/a&gt;&amp;nbsp;I suggest to by confirming the CISCO ISE Syslog format. Cortex XDR can receive Syslog from vendors that use CEF or LEEF formatted over Syslog (TLS not supported). You may reference the &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/external-data-ingestion/about-external-data-ingestion.html#about-external-data-ingestion" target="_self"&gt;external data ingestion vendor support&lt;/A&gt; for additional details on log/data types and vendor support (E.g. custom external sources).&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Mar 2022 20:55:32 GMT</pubDate>
    <dc:creator>WSeldenIII</dc:creator>
    <dc:date>2022-03-23T20:55:32Z</dc:date>
    <item>
      <title>Ingest Logs from Cisco ISE to Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-logs-from-cisco-ise-to-cortex-xdr/m-p/474860#M1739</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone successfully ingest logs from Cisco ISE to Cortex XDR via syslog?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've activated the syslog collector of broker VM for TCP514 and format set to auto detect, following this&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/broker-vm/set-up-broker-vm/activate-the-syslog-collector" target="_self"&gt;documentation&lt;/A&gt;, and configured the Cisco ISE to forward the logs to broker VM accordingly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, when I&amp;nbsp;hover over the Syslog Collector link in the Apps field of the broker VM, the metrices of Syslog Collector is always 0 logs/s for logs received or logs sent, see screenshots for detail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any guidance if I missed anything?&lt;/P&gt;&lt;P&gt;Are there any methods to verify the syslog is ingesting to Cortex XDR properly?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="weejh_0-1647926849547.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39784iD9529412C98CCE34/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="weejh_0-1647926849547.png" alt="weejh_0-1647926849547.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 05:39:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-logs-from-cisco-ise-to-cortex-xdr/m-p/474860#M1739</guid>
      <dc:creator>weejh</dc:creator>
      <dc:date>2022-03-22T05:39:56Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Logs from Cisco ISE to Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-logs-from-cisco-ise-to-cortex-xdr/m-p/475305#M1745</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/171314"&gt;@weejh&lt;/a&gt;&amp;nbsp;I suggest to by confirming the CISCO ISE Syslog format. Cortex XDR can receive Syslog from vendors that use CEF or LEEF formatted over Syslog (TLS not supported). You may reference the &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/external-data-ingestion/about-external-data-ingestion.html#about-external-data-ingestion" target="_self"&gt;external data ingestion vendor support&lt;/A&gt; for additional details on log/data types and vendor support (E.g. custom external sources).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 20:55:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-logs-from-cisco-ise-to-cortex-xdr/m-p/475305#M1745</guid>
      <dc:creator>WSeldenIII</dc:creator>
      <dc:date>2022-03-23T20:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Logs from Cisco ISE to Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-logs-from-cisco-ise-to-cortex-xdr/m-p/475353#M1746</link>
      <description>&lt;P&gt;In case that your Cisco is not sending CEF or LEEF, you could still parse the logs so that xdr will, so to say, "understand" them.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/data-management/create-parsing-rules.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/data-management/create-parsing-rules.html&lt;/A&gt;&lt;BR /&gt;I would also check how are you sending them and how is broker vm listening to them. Meaning as WSeldenIII pointed (TLS is not supported), which port are you using ? standard 514 port for syslog ? tcp/udp (confirmed/unconfirmed). Check also that no Fw is dropping your traffic and that cisco can reach broker vm (network routes, etc...)&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 22:44:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-logs-from-cisco-ise-to-cortex-xdr/m-p/475353#M1746</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2022-03-23T22:44:35Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Logs from Cisco ISE to Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-logs-from-cisco-ise-to-cortex-xdr/m-p/475420#M1747</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the update.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, I need to confirm Cisco ISE syslog format, which I missed it earlier.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 06:57:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-logs-from-cisco-ise-to-cortex-xdr/m-p/475420#M1747</guid>
      <dc:creator>weejh</dc:creator>
      <dc:date>2022-03-24T06:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Logs from Cisco ISE to Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-logs-from-cisco-ise-to-cortex-xdr/m-p/475423#M1748</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the update.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe the Cisco ISE syslog format may not be&amp;nbsp; CEF or LEEF formatted and need to create necessary parsing rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For broker vm is configured to listen to TCP514 and firewall enabled to allow broker vm IP with TCP514.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 07:09:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-logs-from-cisco-ise-to-cortex-xdr/m-p/475423#M1748</guid>
      <dc:creator>weejh</dc:creator>
      <dc:date>2022-03-24T07:09:35Z</dc:date>
    </item>
  </channel>
</rss>

