<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cortex XDR XQL &amp;quot;xdr_event_log&amp;quot; &amp;quot;var/log/secure&amp;quot; and &amp;quot;var/log/wtmp&amp;quot; in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-xql-quot-xdr-event-log-quot-quot-var-log-secure-quot/m-p/582385#M6455</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/263514"&gt;@frank.f.lu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"var/log/wtmp" contains the historical data regarding user login and logout events. For more details please refer linux documentation.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Apr 2024 15:59:56 GMT</pubDate>
    <dc:creator>nsinghvirk</dc:creator>
    <dc:date>2024-04-02T15:59:56Z</dc:date>
    <item>
      <title>cortex XDR XQL "xdr_event_log" "var/log/secure" and "var/log/wtmp"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-xql-quot-xdr-event-log-quot-quot-var-log-secure-quot/m-p/581793#M6414</link>
      <description>&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dear all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone know the log source for&amp;nbsp;action_evtlog_provider_name = "var/log/wtmp"? As I know, wtmp is last log as follow:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="frankflu_0-1711511236457.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58674iB99556370CC8D267/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="frankflu_0-1711511236457.png" alt="frankflu_0-1711511236457.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;However, I find that the result is not only wtmp log but also secure successful log in cortex XDR:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="frankflu_1-1711511470023.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58675i81C9C1AAA05AB773/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="frankflu_1-1711511470023.png" alt="frankflu_1-1711511470023.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So does anyone know the real log source for "var/log/wtmp" or the&amp;nbsp;mechanism? Thanks a lot!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 03:54:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-xql-quot-xdr-event-log-quot-quot-var-log-secure-quot/m-p/581793#M6414</guid>
      <dc:creator>frank.f.lu</dc:creator>
      <dc:date>2024-03-27T03:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: cortex XDR XQL "xdr_event_log" "var/log/secure" and "var/log/wtmp"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-xql-quot-xdr-event-log-quot-quot-var-log-secure-quot/m-p/582385#M6455</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/263514"&gt;@frank.f.lu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"var/log/wtmp" contains the historical data regarding user login and logout events. For more details please refer linux documentation.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2024 15:59:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-xql-quot-xdr-event-log-quot-quot-var-log-secure-quot/m-p/582385#M6455</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2024-04-02T15:59:56Z</dc:date>
    </item>
  </channel>
</rss>

