<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: prophaze waf Log Ingestion in Cortex XDR Management Console in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prophaze-waf-log-ingestion-in-cortex-xdr-management-console/m-p/579301#M6254</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/262549"&gt;@RajeshPremSingh&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To ingest &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/External-Data-Ingestion-Vendor-Support" target="_self"&gt;third party logs&lt;/A&gt; in the Cortex XDR tenant you need the Cortex XDR Pro Per-GB license.&lt;/P&gt;
&lt;P&gt;If the P&lt;SPAN&gt;rophaze Waf supports sending logs to a syslog server, the procedure is the following:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Install a &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Broker-VM-Overview" target="_self"&gt;Broker VM&lt;/A&gt; instance in your environment.&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Enable the &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Activate-the-Syslog-Collector" target="_self"&gt;Syslog applet&lt;/A&gt; in the Broker VM. Configure the vendor and product for the upcoming raw logs.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Create a &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Create-Parsing-Rules" target="_self"&gt;custom parsing&lt;/A&gt; rule to convert the raw data into readable fields by the XDR console that can be used to stitch logs to alerts. This also requires Pro Per-GB license.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Please let me know if this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Mar 2024 13:25:56 GMT</pubDate>
    <dc:creator>jmazzeo</dc:creator>
    <dc:date>2024-03-05T13:25:56Z</dc:date>
    <item>
      <title>prophaze waf Log Ingestion in Cortex XDR Management Console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prophaze-waf-log-ingestion-in-cortex-xdr-management-console/m-p/579256#M6245</link>
      <description>&lt;DIV id="bodyDisplay" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;I kindly request how to ingest&amp;nbsp;prophaze waf Logs in the cortex console. If possible, could you guide how to proceed with this integration? Additionally, please share any related documents or resources that could be helpful in this process.&lt;BR /&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Cortex Data Lake" id="Cortex_Data_Lake"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-rating-metoo lia-component-me-too lia-component-message-view-widget-me-too"&gt;
&lt;DIV class="RatingDisplay lia-component-ratings-widget-rating-display"&gt;
&lt;DIV id="ratingenumerationdisplay" class="lia-rating-enumeration-system-forum_topic_metoo lia-rating-enumeration rating-enum-567392-forum_topic_metoo"&gt;
&lt;DIV class="lia-button-group-left"&gt;&lt;SPAN class="lia-button-wrapper lia-button-wrapper-secondary"&gt;&lt;A id="link_11" class="lia-button lia-button-secondary lia-rating-image lia-rating-image-selected lia-rating-image-active lia-js-data-ratingValue-0 lia-link-ticket-post-action" title="Click here if you had a similar experience" role="button" href="https://live.paloaltonetworks.com/t5/forums/v5/forumtopicpage.externalratingdisplay.ratingenumerationdisplay.link:rating/rating-enum/0/rating-system/forum_topic_metoo/message-uid/567392?t:ac=board-id/Analytics_Discussions/thread-id/5628&amp;amp;t:cp=ratings/contributionpage" target="_blank" rel="nofollow noopener" data-lia-action-token="6mQywsxcJrUU9hY44JkDvZtXfcLExJFevg6Zn9FavHwcMgxVozxjWN4JG7Z2seAG"&gt;Me too&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="producttaglist" class="lia-product-tag-list lia-component-product-snippet lia-component-message-view-widget-product-snippet"&gt;
&lt;DIV class="lia-product-list-wrapper"&gt;
&lt;UL class="lia-product-list lia-product-list-clipped"&gt;
&lt;LI class="lia-product-item"&gt;
&lt;DIV id="productcard" class="lia-product-card-container lia-product-card-container-column lia-product-card-container-fit-parent"&gt;
&lt;DIV class="lia-product-card-thumbnail"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 18 Apr 2024 18:37:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prophaze-waf-log-ingestion-in-cortex-xdr-management-console/m-p/579256#M6245</guid>
      <dc:creator>RajeshPremSingh</dc:creator>
      <dc:date>2024-04-18T18:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: prophaze waf Log Ingestion in Cortex XDR Management Console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prophaze-waf-log-ingestion-in-cortex-xdr-management-console/m-p/579301#M6254</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/262549"&gt;@RajeshPremSingh&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To ingest &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/External-Data-Ingestion-Vendor-Support" target="_self"&gt;third party logs&lt;/A&gt; in the Cortex XDR tenant you need the Cortex XDR Pro Per-GB license.&lt;/P&gt;
&lt;P&gt;If the P&lt;SPAN&gt;rophaze Waf supports sending logs to a syslog server, the procedure is the following:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Install a &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Broker-VM-Overview" target="_self"&gt;Broker VM&lt;/A&gt; instance in your environment.&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Enable the &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Activate-the-Syslog-Collector" target="_self"&gt;Syslog applet&lt;/A&gt; in the Broker VM. Configure the vendor and product for the upcoming raw logs.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Create a &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Create-Parsing-Rules" target="_self"&gt;custom parsing&lt;/A&gt; rule to convert the raw data into readable fields by the XDR console that can be used to stitch logs to alerts. This also requires Pro Per-GB license.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Please let me know if this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 13:25:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prophaze-waf-log-ingestion-in-cortex-xdr-management-console/m-p/579301#M6254</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-03-05T13:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: prophaze waf Log Ingestion in Cortex XDR Management Console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prophaze-waf-log-ingestion-in-cortex-xdr-management-console/m-p/579317#M6256</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310428"&gt;@jmazzeo&lt;/a&gt;&amp;nbsp; possible to do API?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 16:11:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prophaze-waf-log-ingestion-in-cortex-xdr-management-console/m-p/579317#M6256</guid>
      <dc:creator>RajeshPremSingh</dc:creator>
      <dc:date>2024-03-05T16:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: prophaze waf Log Ingestion in Cortex XDR Management Console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prophaze-waf-log-ingestion-in-cortex-xdr-management-console/m-p/579327#M6258</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/262549"&gt;@RajeshPremSingh&lt;/a&gt;, not posible to ingest using API, only for the &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/External-Data-Ingestion-Vendor-Support" target="_self"&gt;third party supported vendors.&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 17:35:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prophaze-waf-log-ingestion-in-cortex-xdr-management-console/m-p/579327#M6258</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-03-05T17:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: prophaze waf Log Ingestion in Cortex XDR Management Console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prophaze-waf-log-ingestion-in-cortex-xdr-management-console/m-p/579395#M6260</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A id="link_29" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310428" target="_self" aria-label="View Profile of jmazzeo"&gt;&lt;SPAN class=""&gt;Jmazzeo&lt;/SPAN&gt;&lt;/A&gt;,&lt;/P&gt;
&lt;P&gt;I am Sreenadh, team member of Rajesh. could you please help with &lt;SPAN&gt;Create a&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Create-Parsing-Rules" target="_self" rel="nofollow noopener noreferrer"&gt;custom parsing&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;rule to convert the raw data into readable fields by the XDR console.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 05:37:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prophaze-waf-log-ingestion-in-cortex-xdr-management-console/m-p/579395#M6260</guid>
      <dc:creator>PoojalaSreenadh</dc:creator>
      <dc:date>2024-03-06T05:37:58Z</dc:date>
    </item>
    <item>
      <title>Re: prophaze waf Log Ingestion in Cortex XDR Management Console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prophaze-waf-log-ingestion-in-cortex-xdr-management-console/m-p/579455#M6273</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/286040"&gt;@PoojalaSreenadh&lt;/a&gt;, I'll recommend you to watch this Webinar Series about Parsing rules and correlation.&lt;/P&gt;
&lt;P&gt;This is the first one with the Parsing basics and how they work:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-webinars/cortex-customer-success-webinar-series-part-1-getting-started/ta-p/575388" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-webinars/cortex-customer-success-webinar-series-part-1-getting-started/ta-p/575388&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also we have a full Youtube playlist about custom logs parsing from scratch:&amp;nbsp;&lt;A href="https://youtube.com/playlist?list=PLD6FJ8WNiIqXct0oWOxUfr0gDGOQLECGS&amp;amp;feature=shared" target="_blank"&gt;https://youtube.com/playlist?list=PLD6FJ8WNiIqXct0oWOxUfr0gDGOQLECGS&amp;amp;feature=shared&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 12:35:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prophaze-waf-log-ingestion-in-cortex-xdr-management-console/m-p/579455#M6273</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-03-06T12:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: prophaze waf Log Ingestion in Cortex XDR Management Console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prophaze-waf-log-ingestion-in-cortex-xdr-management-console/m-p/579516#M6278</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310428"&gt;@jmazzeo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the valuable information, we will go through the following videos and if additional information is required we connect with you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 20:15:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prophaze-waf-log-ingestion-in-cortex-xdr-management-console/m-p/579516#M6278</guid>
      <dc:creator>PoojalaSreenadh</dc:creator>
      <dc:date>2024-03-06T20:15:40Z</dc:date>
    </item>
    <item>
      <title>Re: prophaze waf Log Ingestion in Cortex XDR Management Console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prophaze-waf-log-ingestion-in-cortex-xdr-management-console/m-p/579760#M6294</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310428"&gt;@jmazzeo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is there any possible way to ingest logs or alerts from prophase WAF through&amp;nbsp;&lt;SPAN&gt;HTTP log collector to receive logs?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2024 05:12:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prophaze-waf-log-ingestion-in-cortex-xdr-management-console/m-p/579760#M6294</guid>
      <dc:creator>PoojalaSreenadh</dc:creator>
      <dc:date>2024-03-08T05:12:03Z</dc:date>
    </item>
    <item>
      <title>Re: prophaze waf Log Ingestion in Cortex XDR Management Console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prophaze-waf-log-ingestion-in-cortex-xdr-management-console/m-p/579787#M6295</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/286040"&gt;@PoojalaSreenadh&lt;/a&gt;, yes, you can setup a HTTP collector to ingest logs in Raw, JSON, CEF, or LEEF formats.&lt;/P&gt;
&lt;P&gt;Here is the official doc:&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Set-up-an-HTTP-Log-Collector-to-Receive-Logs" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Set-up-an-HTTP-Log-Collector-to-Receive-Logs&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And at the top of that doc you can see all the supported additional log ingestion methods:&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Additional-Log-Ingestion-Methods" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Additional-Log-Ingestion-Methods&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2024 13:10:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prophaze-waf-log-ingestion-in-cortex-xdr-management-console/m-p/579787#M6295</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-03-08T13:10:17Z</dc:date>
    </item>
    <item>
      <title>Re: prophaze waf Log Ingestion in Cortex XDR Management Console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prophaze-waf-log-ingestion-in-cortex-xdr-management-console/m-p/579789#M6296</link>
      <description>&lt;P&gt;Hi&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310428"&gt;@jmazzeo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the quick reply. we can go through it and let you know if any queries.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2024 13:19:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prophaze-waf-log-ingestion-in-cortex-xdr-management-console/m-p/579789#M6296</guid>
      <dc:creator>PoojalaSreenadh</dc:creator>
      <dc:date>2024-03-08T13:19:56Z</dc:date>
    </item>
  </channel>
</rss>

