<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CDL and Rapid7 InsightIDR, new API method? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cdl-and-rapid7-insightidr-new-api-method/m-p/530109#M3577</link>
    <description>&lt;P&gt;I am trying to figure this out as well. I have another security vendors leveraging CDL API to gather logs but Rapid7IDR fails at this.&lt;/P&gt;</description>
    <pubDate>Tue, 07 Feb 2023 13:04:01 GMT</pubDate>
    <dc:creator>JackSenesap</dc:creator>
    <dc:date>2023-02-07T13:04:01Z</dc:date>
    <item>
      <title>CDL and Rapid7 InsightIDR, new API method?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cdl-and-rapid7-insightidr-new-api-method/m-p/529786#M3548</link>
      <description>&lt;P&gt;Is anyone using the "new API method" R7 references?&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.rapid7.com/insightidr/palo-alto-cortex-data-lake/#New-API-Collection-Method-now-available-as-of-January-2023" target="_blank"&gt;https://docs.rapid7.com/insightidr/palo-alto-cortex-data-lake/#New-API-Collection-Method-now-available-as-of-January-2023&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 15:04:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cdl-and-rapid7-insightidr-new-api-method/m-p/529786#M3548</guid>
      <dc:creator>Ssady1</dc:creator>
      <dc:date>2023-02-03T15:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: CDL and Rapid7 InsightIDR, new API method?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cdl-and-rapid7-insightidr-new-api-method/m-p/530098#M3576</link>
      <description>&lt;P&gt;Hi Ssady1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe this document is not 100% correct.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is no method to get logs from CDL via API.&amp;nbsp; (You need to use syslog)&lt;/P&gt;
&lt;P&gt;But if you have XDR Pro per TB license, You can reach out the data in CDL via XDR. If you dont have XDR Pro per TB license, You can only reach out endpoint related data which is in CDL via API. But still from XDR perspective this is not new API or method.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this is new method on the R7 side, I believe this question should be asked to r7 community.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope that helps&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 11:02:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cdl-and-rapid7-insightidr-new-api-method/m-p/530098#M3576</guid>
      <dc:creator>etugriceri</dc:creator>
      <dc:date>2023-02-07T11:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: CDL and Rapid7 InsightIDR, new API method?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cdl-and-rapid7-insightidr-new-api-method/m-p/530109#M3577</link>
      <description>&lt;P&gt;I am trying to figure this out as well. I have another security vendors leveraging CDL API to gather logs but Rapid7IDR fails at this.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 13:04:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cdl-and-rapid7-insightidr-new-api-method/m-p/530109#M3577</guid>
      <dc:creator>JackSenesap</dc:creator>
      <dc:date>2023-02-07T13:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: CDL and Rapid7 InsightIDR, new API method?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cdl-and-rapid7-insightidr-new-api-method/m-p/530148#M3583</link>
      <description>&lt;P&gt;If you would like to continuously get data from API, You should have enough Compute Unit. Otherwise, data'll not be completely fetched after consuming all free CU.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can check from settings how much you have and how your usage.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 16:39:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cdl-and-rapid7-insightidr-new-api-method/m-p/530148#M3583</guid>
      <dc:creator>etugriceri</dc:creator>
      <dc:date>2023-02-07T16:39:49Z</dc:date>
    </item>
  </channel>
</rss>

