<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic There is no alert severity in the SIEM logs. in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/there-is-no-alert-severity-in-the-siem-logs/m-p/598841#M7226</link>
    <description>&lt;P&gt;Hi. We send Cortex XDR syslog to SIEM. When I check Notification (Settings - Configurations - Notifications) settings, Severity field is available. But on SIEM logs,&amp;nbsp;there is not severity of alert.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Aristooo_0-1727340402852.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62418i283C74A2264E5C5A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Aristooo_0-1727340402852.png" alt="Aristooo_0-1727340402852.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 26 Sep 2024 08:53:11 GMT</pubDate>
    <dc:creator>Aristooo</dc:creator>
    <dc:date>2024-09-26T08:53:11Z</dc:date>
    <item>
      <title>There is no alert severity in the SIEM logs.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/there-is-no-alert-severity-in-the-siem-logs/m-p/598841#M7226</link>
      <description>&lt;P&gt;Hi. We send Cortex XDR syslog to SIEM. When I check Notification (Settings - Configurations - Notifications) settings, Severity field is available. But on SIEM logs,&amp;nbsp;there is not severity of alert.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Aristooo_0-1727340402852.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62418i283C74A2264E5C5A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Aristooo_0-1727340402852.png" alt="Aristooo_0-1727340402852.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 08:53:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/there-is-no-alert-severity-in-the-siem-logs/m-p/598841#M7226</guid>
      <dc:creator>Aristooo</dc:creator>
      <dc:date>2024-09-26T08:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: There is no alert severity in the SIEM logs.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/there-is-no-alert-severity-in-the-siem-logs/m-p/598874#M7233</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/891267549"&gt;@Aristooo&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The severity field is sent with the &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Integrate-a-syslog-receiver" target="_self"&gt;forwarding integration using syslog&lt;/A&gt;. You can check our documentation with the message format &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Log-format-for-IOC-and-BIOC-alerts" target="_self"&gt;here&lt;/A&gt;, maybe your SIEM is not parsing that field with the correct format.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 15:46:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/there-is-no-alert-severity-in-the-siem-logs/m-p/598874#M7233</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-09-26T15:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: There is no alert severity in the SIEM logs.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/there-is-no-alert-severity-in-the-siem-logs/m-p/600658#M7333</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310428"&gt;@jmazzeo&lt;/a&gt;, thank you for your response. Sorry I forgot to reply your comment.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I checked the link you sent and saw that the alert severity in CEF is represented by numbers. It's the same in the logs we forwarded as well. Thank you very much.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;HEADER/Vendor=&lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;"Palo Alto Networks"&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN class="hljs-keyword"&gt;as&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;a constant&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="hljs-type"&gt;string&lt;/SPAN&gt;&lt;SPAN&gt;)HEADER/Device Product=&lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;"Cortex XDR"&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN class="hljs-keyword"&gt;as&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;a constant&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="hljs-type"&gt;string&lt;/SPAN&gt;&lt;SPAN&gt;)HEADER/Product Version= Cortex XDR version (&lt;/SPAN&gt;&lt;SPAN class="hljs-number"&gt;2.0&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN class="hljs-number"&gt;2.1&lt;/SPAN&gt;&lt;SPAN&gt;....)HEADER/Severity=(&lt;/SPAN&gt;&lt;SPAN class="hljs-type"&gt;integer&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN class="hljs-number"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;- Unknown,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="hljs-number"&gt;6&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;- Low,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="hljs-number"&gt;8&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;- Medium,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="hljs-number"&gt;9&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;- High)HEADER/Device&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="hljs-keyword"&gt;Event&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="hljs-keyword"&gt;Class&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;ID=alert sourceHEADER/name =alert name&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 05:27:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/there-is-no-alert-severity-in-the-siem-logs/m-p/600658#M7333</guid>
      <dc:creator>Aristooo</dc:creator>
      <dc:date>2024-10-15T05:27:50Z</dc:date>
    </item>
  </channel>
</rss>

