<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Integrating multiple Cortex XDR with QRadar in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-multiple-cortex-xdr-with-qradar/m-p/381535#M505</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/106832"&gt;@Edmund66&lt;/a&gt;-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know if your approach does not work at which time I'd like to gather a little more info to take to Product Management.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Jan 2021 13:54:08 GMT</pubDate>
    <dc:creator>dfalcon</dc:creator>
    <dc:date>2021-01-22T13:54:08Z</dc:date>
    <item>
      <title>Integrating multiple Cortex XDR with QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-multiple-cortex-xdr-with-qradar/m-p/381454#M504</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thought I would give livecommunity a shot on this. We have been looking into integrating several Cortex XDR instances into a single QRadar instance but have come across an issue where it does not seem to let us change the syslog identifier name on any of them. This leads to a problem distinguishing the different XDR tenants from each other as they are all showing up with&amp;nbsp;cortexxdr as the identifier.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All the XDR forwarding will be done over Syslog TLS.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Normally, when configuring syslog for other services we are able to change this, but that does not seem to be the case for XDR. But then again, we have not worked that much with XDR so hoping someone might have found a way of solving this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone had any luck implementing multiple XDR instances into their SIEM tool through syslog?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: Think we may have found a way of doing this, without involving a new server with rsyslog or similar. Will feedback if it works.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 12:42:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-multiple-cortex-xdr-with-qradar/m-p/381454#M504</guid>
      <dc:creator>Edmund66</dc:creator>
      <dc:date>2021-01-22T12:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating multiple Cortex XDR with QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-multiple-cortex-xdr-with-qradar/m-p/381535#M505</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/106832"&gt;@Edmund66&lt;/a&gt;-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know if your approach does not work at which time I'd like to gather a little more info to take to Product Management.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 13:54:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-multiple-cortex-xdr-with-qradar/m-p/381535#M505</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2021-01-22T13:54:08Z</dc:date>
    </item>
  </channel>
</rss>

