<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Integrate the BVM server with SIEM in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrate-the-bvm-server-with-siem/m-p/554975#M5022</link>
    <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider fz b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;We need to change rsyslog.conf file. Please let us know if this file can be changed and is it recommended to integrate the BVM server with the SIEM?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 24 Aug 2023 03:58:19 GMT</pubDate>
    <dc:creator>RamyashreeMada</dc:creator>
    <dc:date>2023-08-24T03:58:19Z</dc:date>
    <item>
      <title>Integrate the BVM server with SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrate-the-bvm-server-with-siem/m-p/554975#M5022</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider fz b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;We need to change rsyslog.conf file. Please let us know if this file can be changed and is it recommended to integrate the BVM server with the SIEM?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 03:58:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrate-the-bvm-server-with-siem/m-p/554975#M5022</guid>
      <dc:creator>RamyashreeMada</dc:creator>
      <dc:date>2023-08-24T03:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate the BVM server with SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrate-the-bvm-server-with-siem/m-p/555060#M5029</link>
      <description>&lt;P&gt;Hello Ramyashree,&lt;/P&gt;
&lt;P&gt;Please confirm, are you looking to&amp;nbsp;&lt;SPAN&gt;forward Cortex Agent logs from Broker VM to SIEM systems?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 12:56:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrate-the-bvm-server-with-siem/m-p/555060#M5029</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2023-08-24T12:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate the BVM server with SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrate-the-bvm-server-with-siem/m-p/555073#M5032</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206335"&gt;@RamyashreeMada&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to livecommunity!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The broker VM is a hardened security appliance managed by Palo Alto Networks only. There is no mechanism to configure the internal files and processes on the broker VM and as a result, it can be integrated only to Cortex XDR instance only.&amp;nbsp; The broker VM can collect logs into Cortex XDR and can be used for syslog collection within the surface of the Cortex XDR solution only. As a result, you cannot integrate it directly to a SIEM.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rather the practice recommendation would be to ingest logs into Cortex XDR using the broker VM syslog and collect the alerts and events from the Cortex XDR to SIEM solution via various possible and infrastructually supported means.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this answers your query.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please feel free to mark the response as "Accept as Solution" if it helps&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 14:25:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrate-the-bvm-server-with-siem/m-p/555073#M5032</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-08-24T14:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate the BVM server with SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrate-the-bvm-server-with-siem/m-p/555234#M5034</link>
      <description>&lt;P&gt;yes,&amp;nbsp;&lt;SPAN&gt;looking to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;forward Cortex Agent logs from Broker VM to SIEM systems&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 06:36:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrate-the-bvm-server-with-siem/m-p/555234#M5034</guid>
      <dc:creator>RamyashreeMada</dc:creator>
      <dc:date>2023-08-25T06:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate the BVM server with SIEM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrate-the-bvm-server-with-siem/m-p/555236#M5035</link>
      <description>&lt;P&gt;Thank you for confirming.&lt;/P&gt;
&lt;P&gt;This is not possible. You cannot forward agent logs to SIEM using the broker VM.&lt;/P&gt;
&lt;P&gt;You can only forward notifications.&lt;BR /&gt;&lt;SPAN&gt;For more details, please refer:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Integrate-a-Syslog-Receiver" target="_blank" rel="noopener nofollow noreferrer"&gt;Integrate A Syslog Reciever&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 07:12:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrate-the-bvm-server-with-siem/m-p/555236#M5035</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2023-08-25T07:12:40Z</dc:date>
    </item>
  </channel>
</rss>

