<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Amazon WAF Log Ingestion in Cortex XDR Management Console in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/amazon-waf-log-ingestion-in-cortex-xdr-management-console/m-p/568120#M5647</link>
    <description>&lt;P&gt;Hi Nsinghvirk,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the information. We have another query: How can a Palo Alto firewall integrate with Cortex XDR?&lt;/P&gt;
&lt;P&gt;One method involves forwarding Palo Alto firewall logs to the Cortex data lake. Are there any other possible methods?&lt;/P&gt;</description>
    <pubDate>Sat, 02 Dec 2023 04:50:02 GMT</pubDate>
    <dc:creator>Vinothkumar_SBA</dc:creator>
    <dc:date>2023-12-02T04:50:02Z</dc:date>
    <item>
      <title>Amazon WAF Log Ingestion in Cortex XDR Management Console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/amazon-waf-log-ingestion-in-cortex-xdr-management-console/m-p/567392#M5628</link>
      <description>&lt;P&gt;Dear Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I kindly request confirmation regarding the feasibility of integrating Cortex XDR with Amazon WAF logs. If possible, could you provide guidance on how to proceed with this integration? Additionally, please share any related documents or resources that could be helpful in this process.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 13:55:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/amazon-waf-log-ingestion-in-cortex-xdr-management-console/m-p/567392#M5628</guid>
      <dc:creator>Vinothkumar_SBA</dc:creator>
      <dc:date>2023-11-28T13:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: Amazon WAF Log Ingestion in Cortex XDR Management Console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/amazon-waf-log-ingestion-in-cortex-xdr-management-console/m-p/567759#M5635</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/243138"&gt;@Vinothkumar_SBA&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;One of the way by which you can ingest logs from any third party firewall is through syslog collector applet on broker vm. Syslog collector allow you to ingest logs in any of these logs format&amp;nbsp;&lt;SPAN class="guilabel"&gt;CEF&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="guilabel"&gt;LEEF&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="guilabel"&gt;CISCO&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="guilabel"&gt;CORELIGHT&lt;/SPAN&gt;&lt;SPAN&gt;, or&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="guilabel"&gt;RAW. Please follow below guide to activate and config syslog collector to ingest firewall logs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="guilabel"&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Activate-the-Syslog-Collector" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Activate-the-Syslog-Collector&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="guilabel"&gt;One more possible solution is through Cloudwatch integration. XDR provide direct integration to Cloudwatch. Hence if you can forward WAF logs to Cloudwatch, those logs can be ingested to XDR. Below is the documentation for Cloudwatch integration.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Ingest-Logs-from-Amazon-CloudWatch" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Ingest-Logs-from-Amazon-CloudWatch&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 12:27:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/amazon-waf-log-ingestion-in-cortex-xdr-management-console/m-p/567759#M5635</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2023-11-30T12:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: Amazon WAF Log Ingestion in Cortex XDR Management Console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/amazon-waf-log-ingestion-in-cortex-xdr-management-console/m-p/568120#M5647</link>
      <description>&lt;P&gt;Hi Nsinghvirk,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the information. We have another query: How can a Palo Alto firewall integrate with Cortex XDR?&lt;/P&gt;
&lt;P&gt;One method involves forwarding Palo Alto firewall logs to the Cortex data lake. Are there any other possible methods?&lt;/P&gt;</description>
      <pubDate>Sat, 02 Dec 2023 04:50:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/amazon-waf-log-ingestion-in-cortex-xdr-management-console/m-p/568120#M5647</guid>
      <dc:creator>Vinothkumar_SBA</dc:creator>
      <dc:date>2023-12-02T04:50:02Z</dc:date>
    </item>
  </channel>
</rss>

