<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR - Solutions for log collection without an official integration in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-solutions-for-log-collection-without-an-official/m-p/997545#M7569</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/80707"&gt;@mgreer&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;XDR can't connect to an unsupported API to retrieve the events. You can create a HTTP Custom collector and send the logs to the tenant using the API and saving them in the configured dataset.&lt;/P&gt;
&lt;P&gt;More info here:&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Set-up-an-HTTP-Log-Collector-to-Receive-Logs" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Set-up-an-HTTP-Log-Collector-to-Receive-Logs&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Keep in mind that this will only store the events and no stitching or correlation with the alerts will be done. If you want to correlate events &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Create-a-correlation-rule" target="_self"&gt;you can do it manually&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
    <pubDate>Tue, 10 Dec 2024 20:52:18 GMT</pubDate>
    <dc:creator>jmazzeo</dc:creator>
    <dc:date>2024-12-10T20:52:18Z</dc:date>
    <item>
      <title>Cortex XDR - Solutions for log collection without an official integration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-solutions-for-log-collection-without-an-official/m-p/997030#M7554</link>
      <description>&lt;P&gt;Has anyone found a good approach for collecting logs from an API when there isn't an official Cortex XDR integration?&amp;nbsp; For example, Automox has released a Splunk and DataDog app, but the custom collection in Cortex XDR isn't a good fit.&amp;nbsp; We use the Broker VM for syslog, but most SaaS apps don't support syslog of course.&lt;BR /&gt;&lt;BR /&gt;What are people using to get "unsupported" logs into Cortex (without upgrading to XSIAM)?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 21:28:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-solutions-for-log-collection-without-an-official/m-p/997030#M7554</guid>
      <dc:creator>mgreer</dc:creator>
      <dc:date>2024-12-06T21:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR - Solutions for log collection without an official integration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-solutions-for-log-collection-without-an-official/m-p/997545#M7569</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/80707"&gt;@mgreer&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;XDR can't connect to an unsupported API to retrieve the events. You can create a HTTP Custom collector and send the logs to the tenant using the API and saving them in the configured dataset.&lt;/P&gt;
&lt;P&gt;More info here:&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Set-up-an-HTTP-Log-Collector-to-Receive-Logs" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Set-up-an-HTTP-Log-Collector-to-Receive-Logs&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Keep in mind that this will only store the events and no stitching or correlation with the alerts will be done. If you want to correlate events &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Create-a-correlation-rule" target="_self"&gt;you can do it manually&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 20:52:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-solutions-for-log-collection-without-an-official/m-p/997545#M7569</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-12-10T20:52:18Z</dc:date>
    </item>
  </channel>
</rss>

