<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dataset name change in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dataset-name-change/m-p/578476#M6164</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310428"&gt;@jmazzeo&lt;/a&gt;&amp;nbsp;&amp;nbsp;As I understand I cannot change it directly. I need to change it from syslog collector. What if I have many linux endpoints that each sends logs to Broker VM. Do I need to do this action manually? I mean source IP is different for each linux endpoint.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Feb 2024 13:16:07 GMT</pubDate>
    <dc:creator>JahidAliyev</dc:creator>
    <dc:date>2024-02-27T13:16:07Z</dc:date>
    <item>
      <title>Dataset name change</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dataset-name-change/m-p/578450#M6154</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have linux logs which comes as:&lt;BR /&gt;[INGEST:vendor="unknown", product="unknown", target_dataset="unknown_unknown_raw", no_hit = drop]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is collected under the dataset name called "unknown_unknown_raw". But I want to change its dataset name to something else. How can I do that?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 11:19:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dataset-name-change/m-p/578450#M6154</guid>
      <dc:creator>JahidAliyev</dc:creator>
      <dc:date>2024-02-27T11:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: Dataset name change</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dataset-name-change/m-p/578460#M6156</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/274228"&gt;@JahidAliyev&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;Are you using Broker VM Syslog to forward those logs to the console?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 12:38:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dataset-name-change/m-p/578460#M6156</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-02-27T12:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: Dataset name change</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dataset-name-change/m-p/578464#M6159</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310428"&gt;@jmazzeo&lt;/a&gt;, yes, i am using Broker VM&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 12:42:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dataset-name-change/m-p/578464#M6159</guid>
      <dc:creator>JahidAliyev</dc:creator>
      <dc:date>2024-02-27T12:42:26Z</dc:date>
    </item>
    <item>
      <title>Re: Dataset name change</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dataset-name-change/m-p/578471#M6161</link>
      <description>&lt;P&gt;Then your best option is:&lt;/P&gt;
&lt;P&gt;- Go to your Broker VM, edit the Syslog configuration, and then hardcode the vendor and product fields with the source IP of the logs. Take a look at this example in my lab:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1709038334736.png" style="width: 644px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57870i7D0FC6CC50C99116/image-dimensions/644x169/is-moderation-mode/true?v=v2" width="644" height="169" role="button" title="jmazzeo_0-1709038334736.png" alt="jmazzeo_0-1709038334736.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;- This will create a NEW dataset with the configured fields like this: vendor_product_raw&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have our doc here with more Parsing Rule info:&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Administrator-Guide/Create-Parsing-Rules" target="_blank" rel="noopener"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Administrator-Guide/Create-Parsing-Rules&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a webinar available here with some very useful basic concepts:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-webinars/cortex-customer-success-webinar-series-part-1-getting-started/ta-p/575388" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-webinars/cortex-customer-success-webinar-series-part-1-getting-started/ta-p/575388&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 12:57:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dataset-name-change/m-p/578471#M6161</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-02-27T12:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: Dataset name change</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dataset-name-change/m-p/578476#M6164</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310428"&gt;@jmazzeo&lt;/a&gt;&amp;nbsp;&amp;nbsp;As I understand I cannot change it directly. I need to change it from syslog collector. What if I have many linux endpoints that each sends logs to Broker VM. Do I need to do this action manually? I mean source IP is different for each linux endpoint.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 13:16:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dataset-name-change/m-p/578476#M6164</guid>
      <dc:creator>JahidAliyev</dc:creator>
      <dc:date>2024-02-27T13:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: Dataset name change</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dataset-name-change/m-p/578483#M6165</link>
      <description>&lt;UL&gt;
&lt;LI&gt;You can go to Settings - Data Broker - Broker VM, click on the Syslog Applet and select "Configure".&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1709040232198.png" style="width: 638px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57872i6648AB9D10108032/image-dimensions/638x303/is-moderation-mode/true?v=v2" width="638" height="303" role="button" title="jmazzeo_0-1709040232198.png" alt="jmazzeo_0-1709040232198.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;You can edit the default rule without any specific IP, and there change the Vendor and Product.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_1-1709040383726.png" style="width: 639px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57873i60AC19F5E7B24B55/image-dimensions/639x262/is-moderation-mode/true?v=v2" width="639" height="262" role="button" title="jmazzeo_1-1709040383726.png" alt="jmazzeo_1-1709040383726.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_2-1709040413932.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57874iBE1602629138F979/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jmazzeo_2-1709040413932.png" alt="jmazzeo_2-1709040413932.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The "Syslog Collector" settings works like a firewall rule, works from the top to the bottom. You can have specific rules with IPs on top, and a default one without that setting configured in the last position.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_3-1709040524130.png" style="width: 505px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57875i57599DBC29F226B5/image-dimensions/505x96/is-moderation-mode/true?v=v2" width="505" height="96" role="button" title="jmazzeo_3-1709040524130.png" alt="jmazzeo_3-1709040524130.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 13:28:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dataset-name-change/m-p/578483#M6165</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-02-27T13:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: Dataset name change</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dataset-name-change/m-p/578486#M6166</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310428"&gt;@jmazzeo&lt;/a&gt;&amp;nbsp;I understand, thank you. And, please, can you answer this:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As you know PaloAlto has recently changed their licenses for Cortex XDR. As I know before it was Data Lake license with TBs but now, it is GB/per day. How can I calculate how much GB I need to buy for fully take advantage of this. Is there any sizing method?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 13:36:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dataset-name-change/m-p/578486#M6166</guid>
      <dc:creator>JahidAliyev</dc:creator>
      <dc:date>2024-02-27T13:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: Dataset name change</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dataset-name-change/m-p/578487#M6167</link>
      <description>&lt;P&gt;Yes, there is a sizing method available. Please talk with your PANW Sales contact and they will help you with that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you found any of the previous replies as the answer to the inquiry, please mark it as the solution.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 13:38:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/dataset-name-change/m-p/578487#M6167</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-02-27T13:38:23Z</dc:date>
    </item>
  </channel>
</rss>

