<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Email_data dataset empty in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/email-data-dataset-empty/m-p/590040#M6836</link>
    <description>&lt;P&gt;Hi all, have been digging into our Cortex tenant and noticed that the email_data dataset has no data. Our emails come from Microsoft Exchange online. To get data to this dataset is it just having a compliance mailbox set up in exchange? We already have a connector to M365 and I can see data in the dataset&amp;nbsp;msft_o365_exchange_online_raw but we haven't set up a compliance mailbox yet so I am assuming this may be the reason email_data is empty. Can anyone confirm?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance for any help.&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jun 2024 23:30:36 GMT</pubDate>
    <dc:creator>RMaudsley</dc:creator>
    <dc:date>2024-06-20T23:30:36Z</dc:date>
    <item>
      <title>Email_data dataset empty</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/email-data-dataset-empty/m-p/590040#M6836</link>
      <description>&lt;P&gt;Hi all, have been digging into our Cortex tenant and noticed that the email_data dataset has no data. Our emails come from Microsoft Exchange online. To get data to this dataset is it just having a compliance mailbox set up in exchange? We already have a connector to M365 and I can see data in the dataset&amp;nbsp;msft_o365_exchange_online_raw but we haven't set up a compliance mailbox yet so I am assuming this may be the reason email_data is empty. Can anyone confirm?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance for any help.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2024 23:30:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/email-data-dataset-empty/m-p/590040#M6836</guid>
      <dc:creator>RMaudsley</dc:creator>
      <dc:date>2024-06-20T23:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: Email_data dataset empty</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/email-data-dataset-empty/m-p/590083#M6837</link>
      <description>&lt;P&gt;Hi, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The O365 emails goes to the "msft_o365_emails_raw" dataset, please check that one if you have something there. The "email_data" dataset is an internal default dataset.&lt;/P&gt;
&lt;P&gt;You can take a look at &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Ingest-Logs-from-Microsoft-Office-365" target="_self"&gt;this doc&lt;/A&gt; for more details about the Office 365 integration, including the steps required on the Microsoft side.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2024 12:25:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/email-data-dataset-empty/m-p/590083#M6837</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-06-21T12:25:03Z</dc:date>
    </item>
  </channel>
</rss>

