<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XDR Cortex Event Forwarding into AWS S3 bucket in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-cortex-event-forwarding-into-aws-s3-bucket/m-p/514823#M2811</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/142551"&gt;@neelrohit&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I checked and at the moment, we do not have a license, but we are looking into getting one.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We need to know if it is possible to export the raw data from the endpoints to AWS S3 and not only to GCP.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks again for the response!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 14 Sep 2022 13:58:48 GMT</pubDate>
    <dc:creator>MBD-hunter</dc:creator>
    <dc:date>2022-09-14T13:58:48Z</dc:date>
    <item>
      <title>XDR Cortex Event Forwarding into AWS S3 bucket</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-cortex-event-forwarding-into-aws-s3-bucket/m-p/514247#M2772</link>
      <description>&lt;P&gt;Hi!&lt;BR /&gt;I am looking for a way to&amp;nbsp;&lt;SPAN&gt;export raw endpoint data from Cortex XDR to AWS S3 bucket,&lt;VAR class="" data-product="admin-pro-only"&gt;&lt;/VAR&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I saw in the &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/data-management/event-forwarding" target="_self"&gt;Event Forwarding option&lt;/A&gt;&amp;nbsp;&lt;SPAN&gt;that it's possible to export these logs into&amp;nbsp;Google Cloud Platform (GCP) bucket, &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;so I look for a similar option just into AWS S3 bucket.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Has anyone else figured something out to achieve this?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 10:09:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-cortex-event-forwarding-into-aws-s3-bucket/m-p/514247#M2772</guid>
      <dc:creator>MBD-hunter</dc:creator>
      <dc:date>2022-09-08T10:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Cortex Event Forwarding into AWS S3 bucket</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-cortex-event-forwarding-into-aws-s3-bucket/m-p/514255#M2776</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/235210"&gt;@MBD-hunter&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out to Live Community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The event forwarding from Cortex XDR to external destinations is possible only with an add-on license for&amp;nbsp;&lt;SPAN&gt;Event Forwarding.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Please ensure you have the add-on license for the same and if not kindly discuss with your sales representatives for getting the feature set enabled for configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 11:14:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-cortex-event-forwarding-into-aws-s3-bucket/m-p/514255#M2776</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2022-09-08T11:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Cortex Event Forwarding into AWS S3 bucket</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-cortex-event-forwarding-into-aws-s3-bucket/m-p/514284#M2777</link>
      <description>&lt;P&gt;Hi!&lt;BR /&gt;Thanks, I will check.&lt;BR /&gt;But if I have the right license I will be able to forward the data to AWS as well?&amp;nbsp;&lt;BR /&gt;Because in &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/data-management/event-forwarding" target="_self"&gt;the docs&lt;/A&gt;&amp;nbsp;(step 3) it looks like it is only possible to GCP...&lt;/P&gt;
&lt;P&gt;"To retrieve the data, access GCP Cloud Storage through the Service Account.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Destination&amp;nbsp;section displays the details of the Google Cloud Platform (GCP) bucket where your data is stored for 14 days. The data is compressed and saved as a line-delimited JSON gzip file."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/142551"&gt;@neelrohit&lt;/a&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 14:58:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-cortex-event-forwarding-into-aws-s3-bucket/m-p/514284#M2777</guid>
      <dc:creator>MBD-hunter</dc:creator>
      <dc:date>2022-09-08T14:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Cortex Event Forwarding into AWS S3 bucket</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-cortex-event-forwarding-into-aws-s3-bucket/m-p/514823#M2811</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/142551"&gt;@neelrohit&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I checked and at the moment, we do not have a license, but we are looking into getting one.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We need to know if it is possible to export the raw data from the endpoints to AWS S3 and not only to GCP.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks again for the response!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2022 13:58:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-cortex-event-forwarding-into-aws-s3-bucket/m-p/514823#M2811</guid>
      <dc:creator>MBD-hunter</dc:creator>
      <dc:date>2022-09-14T13:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Cortex Event Forwarding into AWS S3 bucket</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-cortex-event-forwarding-into-aws-s3-bucket/m-p/514825#M2812</link>
      <description>&lt;P&gt;MBD-Hunter,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The bucket is maintained by Palo Alto, not the customer.&amp;nbsp; Buckets are only hosted in GCP.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2022 14:15:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-cortex-event-forwarding-into-aws-s3-bucket/m-p/514825#M2812</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2022-09-14T14:15:50Z</dc:date>
    </item>
  </channel>
</rss>

