<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR integration with IBM QRadar in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-integration-with-ibm-qradar/m-p/520980#M3134</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/223431"&gt;@MithunKT&lt;/a&gt;&amp;nbsp;you can forward all alert logs via email and have QRadar pick them up and parse it, if that works.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alternately, you can also leverage XDR API's to &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-api/cortex-xdr-apis/incident-management/get-alerts" target="_blank"&gt;retrieve all alerts&lt;/A&gt;, but you might run into throttling issues if the number of alerts are very high.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 11 Nov 2022 06:24:13 GMT</pubDate>
    <dc:creator>bbarmanroy</dc:creator>
    <dc:date>2022-11-11T06:24:13Z</dc:date>
    <item>
      <title>Cortex XDR integration with IBM QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-integration-with-ibm-qradar/m-p/520978#M3133</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi All,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;We have a requirement to get cortex XDR Data(Alerts, agent audit logs) into IBM Qradar. Following the documentation, we took the approach of configuring syslog server in &lt;STRONG&gt;external applications&lt;/STRONG&gt;, new configuration in &lt;STRONG&gt;notifications, &lt;/STRONG&gt;and adding&lt;STRONG&gt; Cortex DSM app extension &lt;/STRONG&gt;in QRadar&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Due to security concerns, our QRadar team does not wish to make our syslog server's private IP address public.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A public IP is required in order to add a Syslog server to External Applications, according to the XDR documentation. We lack a public IP, hence we are unable to use this strategy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a result, I was searching for a different way to send XDR alerts to the Qradar Syslog Server (perhaps using an API). If anyone has any alternative suggestions, I'd appreciate it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks in Advance.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Nov 2022 05:17:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-integration-with-ibm-qradar/m-p/520978#M3133</guid>
      <dc:creator>MithunKT</dc:creator>
      <dc:date>2022-11-11T05:17:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR integration with IBM QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-integration-with-ibm-qradar/m-p/520980#M3134</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/223431"&gt;@MithunKT&lt;/a&gt;&amp;nbsp;you can forward all alert logs via email and have QRadar pick them up and parse it, if that works.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alternately, you can also leverage XDR API's to &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-api/cortex-xdr-apis/incident-management/get-alerts" target="_blank"&gt;retrieve all alerts&lt;/A&gt;, but you might run into throttling issues if the number of alerts are very high.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Nov 2022 06:24:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-integration-with-ibm-qradar/m-p/520980#M3134</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-11-11T06:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR integration with IBM QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-integration-with-ibm-qradar/m-p/521050#M3136</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/223431"&gt;@MithunKT&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm assuming the QRadar data gateway is not an option? Typically this is what I encounter on customer that have QRadar.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Nov 2022 20:42:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-integration-with-ibm-qradar/m-p/521050#M3136</guid>
      <dc:creator>jcandelaria</dc:creator>
      <dc:date>2022-11-11T20:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR integration with IBM QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-integration-with-ibm-qradar/m-p/539190#M4173</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/223431" target="_blank"&gt;@MithunKT&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;,&lt;BR /&gt;From my experience with Qradar SIEM this could be solved by deploying seprate &lt;STRONG&gt;disconnected log collector&lt;/STRONG&gt; with public IP for these type of sources.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://www.ibm.com/docs/en/qradar-common?topic=disconnected-log-collector" target="_blank"&gt;Disconnected Log Collector - IBM Documentation&lt;/A&gt;&lt;BR /&gt;Maybe it will help&amp;nbsp;&lt;BR /&gt;Kind Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 12:11:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-integration-with-ibm-qradar/m-p/539190#M4173</guid>
      <dc:creator>SevcikMichal</dc:creator>
      <dc:date>2023-04-18T12:11:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR integration with IBM QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-integration-with-ibm-qradar/m-p/1252462#M9262</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;that true,&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;public IP Cortex sent to private syslog will not be option here, due to&amp;nbsp;&amp;nbsp;lack a public IP of QRadar.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I used&amp;nbsp;Universal Cloud REST API protocol&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;here the workflow files&lt;BR /&gt;&lt;A class="relative pointer-events-auto a cursor-pointer
  
  
  
  
  underline" href="https://github.com/iceMBD/Workflow-Palo-Alto-Cortex-XDR-Integration-for-IBM-QRadar/tree/main" rel="noopener nofollow ugc" target="_blank"&gt;https://github.com/iceMBD/Workflow-Palo-Alto-Cortex-XDR-Integration-for-IBM-QRadar/tree/main&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2026 20:46:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-integration-with-ibm-qradar/m-p/1252462#M9262</guid>
      <dc:creator>m.abulamddi</dc:creator>
      <dc:date>2026-04-17T20:46:27Z</dc:date>
    </item>
  </channel>
</rss>

