<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR Incident integration splunk tool in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-integration-splunk-tool/m-p/557513#M5129</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/243138"&gt;@Vinothkumar_SBA&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;Would suggest and recommend before posting details/query could you remove/redact the specifics/info related to your org. Regarding this request could you confirm about ingestion of Incidents to Splunk are you doing using api or you are referring to Notifications configured for Log Alert Type as Alerts using syslog server.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV dir="ltr"&gt;Above logs is related to "XDR Analytics" therefore for this sort of Alert Sources&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Analytics-Log-Format" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Analytics-Log-Format&amp;amp;source=gmail&amp;amp;ust=1694589859525000&amp;amp;usg=AOvVaw3Gl15O9EpJKlL_KTAJNhP_"&gt;here&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;are the default fields if selected all would be received. The table in the URL shared earlier describes each field. Hope this will help and clarify for the fields to be received per Analytics Log format or different Alert Sources Log format &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Alert-Notification-Format" target="_self"&gt;here&lt;/A&gt;.&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;In case of analytics alerts you may receive file details like full_path and md5 however for other fields like commandline, actor_process(Parent_Process), action_process(Child_Process) it may vary and could be present based on Alert Sources.&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 12 Sep 2023 07:51:03 GMT</pubDate>
    <dc:creator>PiyushKohli</dc:creator>
    <dc:date>2023-09-12T07:51:03Z</dc:date>
    <item>
      <title>Cortex XDR Incident integration splunk tool</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-integration-splunk-tool/m-p/556735#M5116</link>
      <description>&lt;P&gt;We are currently integrating the Cortex XDR incident logs with the Splunk tool. Currently, the incident logs are visible in the Splunk tool, but certain essential fields required for conducting an XDR log investigation are not available in the existing logs. These necessary fields include File Name, File Path, File Hash, Command Line, Grand Parent Name, Parent Name, Grand Parent Command Line, Parent Command Line, IOC value, and a few others.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 06:25:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-integration-splunk-tool/m-p/556735#M5116</guid>
      <dc:creator>Vinothkumar_SBA</dc:creator>
      <dc:date>2023-09-13T06:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Incident integration splunk tool</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-integration-splunk-tool/m-p/557513#M5129</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/243138"&gt;@Vinothkumar_SBA&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;Would suggest and recommend before posting details/query could you remove/redact the specifics/info related to your org. Regarding this request could you confirm about ingestion of Incidents to Splunk are you doing using api or you are referring to Notifications configured for Log Alert Type as Alerts using syslog server.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV dir="ltr"&gt;Above logs is related to "XDR Analytics" therefore for this sort of Alert Sources&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Analytics-Log-Format" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Analytics-Log-Format&amp;amp;source=gmail&amp;amp;ust=1694589859525000&amp;amp;usg=AOvVaw3Gl15O9EpJKlL_KTAJNhP_"&gt;here&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;are the default fields if selected all would be received. The table in the URL shared earlier describes each field. Hope this will help and clarify for the fields to be received per Analytics Log format or different Alert Sources Log format &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Alert-Notification-Format" target="_self"&gt;here&lt;/A&gt;.&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;In case of analytics alerts you may receive file details like full_path and md5 however for other fields like commandline, actor_process(Parent_Process), action_process(Child_Process) it may vary and could be present based on Alert Sources.&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 12 Sep 2023 07:51:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-integration-splunk-tool/m-p/557513#M5129</guid>
      <dc:creator>PiyushKohli</dc:creator>
      <dc:date>2023-09-12T07:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Incident integration splunk tool</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-integration-splunk-tool/m-p/557856#M5148</link>
      <description>&lt;P&gt;Hi@PiyushKohli,&lt;/P&gt;
&lt;P&gt;We have configure the API integration.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 05:34:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-integration-splunk-tool/m-p/557856#M5148</guid>
      <dc:creator>Vinothkumar_SBA</dc:creator>
      <dc:date>2023-09-14T05:34:43Z</dc:date>
    </item>
  </channel>
</rss>

