<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Http logs collector example not working in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/http-logs-collector-example-not-working/m-p/485996#M1952</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/218900"&gt;@MMenachem&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's what I tried :&lt;/P&gt;&lt;P&gt;&lt;U&gt;Set up a HTTP Collector&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_0-1652157321280.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40913i7C667DB92E36D31A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_0-1652157321280.png" alt="bbarmanroy_0-1652157321280.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was able to send some data with Postman (see my configuration below)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_1-1652157372885.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40914i6A967BA8D7857A05/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_1-1652157372885.png" alt="bbarmanroy_1-1652157372885.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_2-1652157427375.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40915iDCED7DA9EB4526CD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_2-1652157427375.png" alt="bbarmanroy_2-1652157427375.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And using native curl (also generated from Postman):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_3-1652157539022.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40916iB571B3279E627053/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_3-1652157539022.png" alt="bbarmanroy_3-1652157539022.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And with Powershell native requests (also generated from Postman):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_4-1652157601050.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40917i7DA0526C50D16516/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_4-1652157601050.png" alt="bbarmanroy_4-1652157601050.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's the data when queried from XQL:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_5-1652157649057.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40918i275E0445B07B4CF5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_5-1652157649057.png" alt="bbarmanroy_5-1652157649057.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I recommend you to review your configuration - I'd start with Postman and then build your use cases from there.&amp;nbsp;The example curl command in the tenant is for Linux - the curl provided in Windows is actually a powershell cmdlet alias.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 10 May 2022 04:45:16 GMT</pubDate>
    <dc:creator>bbarmanroy</dc:creator>
    <dc:date>2022-05-10T04:45:16Z</dc:date>
    <item>
      <title>Http logs collector example not working</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/http-logs-collector-example-not-working/m-p/485620#M1946</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;hope this is the right place to ask this question&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We were given a temp user to play around with the Cortex XDR and we are trying to insert some dummy data into it.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I am trying to insert data using an Http logs collector, following&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/external-data-ingestion/additional-log-ingestion-methods-for-cortex-xdr/set-up-an-http-log-collector-to-receive-logs#set-up-an-http-log-collector-to-receive-logs" target="_blank" rel="noopener"&gt;this guide&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;unfortunately,&amp;nbsp;the example&amp;nbsp;in the guide seems to be incorrect.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I created a custom collector of HTTP type and got an API key.&lt;/DIV&gt;&lt;DIV&gt;the comparison&amp;nbsp;is "gzip" and the log format is "JSON" (but also tried RAW and CEF)&lt;/DIV&gt;&lt;DIV&gt;the API URL is:&amp;nbsp;&lt;STRONG&gt;&lt;A href="https://api-nl.xdr.us.paloaltonetworks.com/logs/v1/event" target="_blank" rel="noopener"&gt;https://api-nl.xdr.us.paloaltonetworks.com/logs/v1/event&lt;/A&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;DIV&gt;when pressing "View Example" I'm given the following&amp;nbsp;code:&lt;BR /&gt;&lt;STRONG&gt;curl -X POST&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://api-nl.xdr.us.paloaltonetworks.com/logs/v1/event" target="_blank" rel="noopener"&gt;https://api-nl.xdr.us.paloaltonetworks.com/logs/v1/event&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-H 'Authorization: {api_key}' -H 'Content-Type: text/plain' -d '{"example1": "test", "timestamp": 1609100113039}&lt;BR /&gt;{"example2": [12321,546456,45687,1]}'&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;1.The given CURL is not valid on windows. need to change all single quote to double quotes&lt;/DIV&gt;&lt;DIV&gt;2. when fixing this and sending this CURL&lt;/DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;curl -X POST&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://api-nl.xdr.us.paloaltonetworks.com/logs/v1/event" target="_blank" rel="noopener"&gt;https://api-nl.xdr.us.paloaltonetworks.com/logs/v1/event&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-H "Authorization:{api_key}" -H "Content-Type:text/plain" -d "{"example1": "test", "timestamp": 1609100113039}\n{"example2": [12321,546456,45687,1]}" -v&lt;BR /&gt;&lt;/STRONG&gt;(the "{api_key}" is replaced by the actual key)&lt;BR /&gt;I'm getting&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;error code 500&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and message:&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;" {"error":"error processing request, error: failed to process the request"}&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;Full log:&lt;BR /&gt;C:\Users\AmirD&amp;gt;curl -X POST&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://api-nl.xdr.us.paloaltonetworks.com/logs/v1/event" target="_blank" rel="noopener"&gt;https://api-nl.xdr.us.paloaltonetworks.com/logs/v1/event&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-H "Authorization:&lt;STRONG&gt;{api_key}&lt;/STRONG&gt;" -H "Content-Type:text/plain" -d "{"example1": "test", "timestamp": 1609100113039}\n{"example2": [12321,546456,45687,1]}" -v&lt;BR /&gt;Note: Unnecessary use of -X or --request, POST is already inferred.&lt;BR /&gt;* &amp;nbsp; Trying 35.222.81.194:443...&lt;BR /&gt;* Connected to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://api-nl.xdr.us.paloaltonetworks.com/" target="_blank" rel="noopener"&gt;api-nl.xdr.us.paloaltonetworks.com&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(35.222.81.194) port 443 (#0)&lt;BR /&gt;* schannel: disabled automatic use of client certificate&lt;BR /&gt;* schannel: ALPN, offering http/1.1&lt;BR /&gt;* schannel: ALPN, server accepted to use http/1.1&lt;BR /&gt;&amp;gt; POST /logs/v1/event HTTP/1.1&lt;BR /&gt;&amp;gt; Host:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://api-nl.xdr.us.paloaltonetworks.com/" target="_blank" rel="noopener"&gt;api-nl.xdr.us.paloaltonetworks.com&lt;/A&gt;&lt;BR /&gt;&amp;gt; User-Agent: curl/7.79.1&lt;BR /&gt;&amp;gt; Accept: */*&lt;BR /&gt;&amp;gt; Authorization:Mjp5cmYzVHVFUk5sOWJvSnR3SlR0TWppakxNQ21mUmMxM0F6dG12VlVzbEFSNUdVSmFVRzUyQVl0MFRjMzhxcGJvUnc3WFhxYkdoNUxFMHpWSlp1Sm5GenRaWjVCTER4RHQ4Q1VDUzJ0ZDA4akVZWVBlWkJKRVIwUFNFWmtQcDlCNQ==&lt;BR /&gt;&amp;gt; Content-Type:text/plain&lt;BR /&gt;&amp;gt; Content-Length: 78&lt;BR /&gt;&amp;gt;&lt;BR /&gt;* Mark bundle as not supporting multiuse&lt;BR /&gt;&amp;lt; HTTP/1.1 500 Internal Server Error&lt;BR /&gt;&amp;lt; Date: Sun, 08 May 2022 14:31:04 GMT&lt;BR /&gt;&amp;lt; Content-Type: application/json; charset=UTF-8&lt;BR /&gt;&amp;lt; Content-Length: 74&lt;BR /&gt;&amp;lt; Connection: keep-alive&lt;BR /&gt;&amp;lt; Strict-Transport-Security: max-age=15724800; includeSubDomains&lt;BR /&gt;&amp;lt;&lt;BR /&gt;{"error":"error processing request, error: failed to process the request"}* Connection #0 to host&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://api-nl.xdr.us.paloaltonetworks.com/" target="_blank" rel="noopener"&gt;api-nl.xdr.us.paloaltonetworks.com&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;left intact&lt;BR /&gt;&lt;BR /&gt;Also tried sending a request from POSTMAN - same result.&lt;BR /&gt;tried to send content type as&amp;nbsp;&lt;SPAN&gt;&lt;U&gt;text/plain&lt;/U&gt; and as&amp;nbsp;&lt;U&gt;application/json&lt;/U&gt;&lt;/SPAN&gt;&amp;nbsp;- no luck.&lt;BR /&gt;tried to change the HTTP collector to CEF format and send the following text:&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;"CEF:0|NL|NLMOT|1.0.0.0|Executable Code was Detected|Advanced exploit detected|100|src=192.168.255.110 spt=46117 dst=172.25.212.204 dpt=80"&lt;/STRONG&gt;&amp;nbsp; but no luck&lt;BR /&gt;&lt;BR /&gt;What am I doing wrong? who can assist us with this error?&lt;BR /&gt;&lt;BR /&gt;thanks&lt;FONT color="#888888"&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 08 May 2022 14:51:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/http-logs-collector-example-not-working/m-p/485620#M1946</guid>
      <dc:creator>MMenachem</dc:creator>
      <dc:date>2022-05-08T14:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: Http logs collector example not working</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/http-logs-collector-example-not-working/m-p/485996#M1952</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/218900"&gt;@MMenachem&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's what I tried :&lt;/P&gt;&lt;P&gt;&lt;U&gt;Set up a HTTP Collector&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_0-1652157321280.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40913i7C667DB92E36D31A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_0-1652157321280.png" alt="bbarmanroy_0-1652157321280.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was able to send some data with Postman (see my configuration below)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_1-1652157372885.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40914i6A967BA8D7857A05/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_1-1652157372885.png" alt="bbarmanroy_1-1652157372885.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_2-1652157427375.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40915iDCED7DA9EB4526CD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_2-1652157427375.png" alt="bbarmanroy_2-1652157427375.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And using native curl (also generated from Postman):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_3-1652157539022.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40916iB571B3279E627053/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_3-1652157539022.png" alt="bbarmanroy_3-1652157539022.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And with Powershell native requests (also generated from Postman):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_4-1652157601050.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40917i7DA0526C50D16516/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_4-1652157601050.png" alt="bbarmanroy_4-1652157601050.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's the data when queried from XQL:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_5-1652157649057.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40918i275E0445B07B4CF5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_5-1652157649057.png" alt="bbarmanroy_5-1652157649057.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I recommend you to review your configuration - I'd start with Postman and then build your use cases from there.&amp;nbsp;The example curl command in the tenant is for Linux - the curl provided in Windows is actually a powershell cmdlet alias.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 04:45:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/http-logs-collector-example-not-working/m-p/485996#M1952</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-05-10T04:45:16Z</dc:date>
    </item>
  </channel>
</rss>

