<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forward the Miter ID field by Syslog in CEF format, is it possible? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forward-the-miter-id-field-by-syslog-in-cef-format-is-it/m-p/415613#M823</link>
    <description>&lt;P&gt;In short, via Syslog then it will not be possible to obtain Miter ID information?&lt;/P&gt;</description>
    <pubDate>Mon, 28 Jun 2021 14:08:13 GMT</pubDate>
    <dc:creator>rodrigoduarte</dc:creator>
    <dc:date>2021-06-28T14:08:13Z</dc:date>
    <item>
      <title>Forward the Miter ID field by Syslog in CEF format, is it possible?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forward-the-miter-id-field-by-syslog-in-cef-format-is-it/m-p/415332#M817</link>
      <description>&lt;P&gt;Hello new friends.&lt;/P&gt;&lt;P&gt;I have a receiver receiving events via Syslog in CEF format, but I can't include the Miter ID field.&lt;/P&gt;&lt;P&gt;Any suggestion ?&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jun 2021 04:05:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forward-the-miter-id-field-by-syslog-in-cef-format-is-it/m-p/415332#M817</guid>
      <dc:creator>rodrigoduarte</dc:creator>
      <dc:date>2021-06-26T04:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: Forward the Miter ID field by Syslog in CEF format, is it possible?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forward-the-miter-id-field-by-syslog-in-cef-format-is-it/m-p/415410#M820</link>
      <description>&lt;P&gt;Hi Rodrigoduarte,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you saying that you cant create this filter? then select the syslog server you set-up?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jcandelaria_0-1624764857262.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34604i1C44F7DC1FF797AD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jcandelaria_0-1624764857262.png" alt="jcandelaria_0-1624764857262.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Jun 2021 03:34:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forward-the-miter-id-field-by-syslog-in-cef-format-is-it/m-p/415410#M820</guid>
      <dc:creator>jcandelaria</dc:creator>
      <dc:date>2021-06-27T03:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: Forward the Miter ID field by Syslog in CEF format, is it possible?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forward-the-miter-id-field-by-syslog-in-cef-format-is-it/m-p/415467#M821</link>
      <description>&lt;P&gt;Could you give me a basic procedure to apply this filter via Syslog? I'm not the tool administrator, I work with SIEM.&lt;BR /&gt;The Cortex administrator said that it was not possible to forward the Miter ID field and I am 80% sure it is possible.&lt;/P&gt;</description>
      <pubDate>Sun, 27 Jun 2021 18:59:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forward-the-miter-id-field-by-syslog-in-cef-format-is-it/m-p/415467#M821</guid>
      <dc:creator>rodrigoduarte</dc:creator>
      <dc:date>2021-06-27T18:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: Forward the Miter ID field by Syslog in CEF format, is it possible?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forward-the-miter-id-field-by-syslog-in-cef-format-is-it/m-p/415608#M822</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Rodrigoduarte,&lt;BR /&gt;&lt;BR /&gt;Its not possible to configure XDR syslog forwarding fields. Scope of Alerts, syslog server and log type (Alerts, Agent Audit logs, Management Audit logs) are just configurable.&amp;nbsp;&lt;BR /&gt;Below URL is about to XDR log formats&amp;nbsp;that the Cortex Data Lake app can forward logs to external syslog server or email.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/logs/cortex-xdr-log-notification-formats/agent-logs-format-syslog-export-logging-service" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/logs/cortex-xdr-log-notification-formats/agent-logs-format-syslog-export-logging-service&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 14:02:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forward-the-miter-id-field-by-syslog-in-cef-format-is-it/m-p/415608#M822</guid>
      <dc:creator>etugriceri</dc:creator>
      <dc:date>2021-06-28T14:02:52Z</dc:date>
    </item>
    <item>
      <title>Re: Forward the Miter ID field by Syslog in CEF format, is it possible?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forward-the-miter-id-field-by-syslog-in-cef-format-is-it/m-p/415613#M823</link>
      <description>&lt;P&gt;In short, via Syslog then it will not be possible to obtain Miter ID information?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 14:08:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forward-the-miter-id-field-by-syslog-in-cef-format-is-it/m-p/415613#M823</guid>
      <dc:creator>rodrigoduarte</dc:creator>
      <dc:date>2021-06-28T14:08:13Z</dc:date>
    </item>
    <item>
      <title>Re: Forward the Miter ID field by Syslog in CEF format, is it possible?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forward-the-miter-id-field-by-syslog-in-cef-format-is-it/m-p/415629#M824</link>
      <description>&lt;P&gt;thats correct. There is no field which is related with MITRE in syslog payload but still you can get that information via Email alert or via API.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;related fields in email =&amp;nbsp;mitre_tactic_ids,&amp;nbsp;mitre_technique_ids,&amp;nbsp;mitre_tactic_id_and_name&lt;BR /&gt;for the API =mitre_tactics_ids_and_names, mitre_techniques_ids_and_names&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for the api details, you can check below.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-api/cortex-xdr-apis/incident-management/get-extra-incident-data.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-api/cortex-xdr-apis/incident-management/get-extra-incident-data.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 15:20:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forward-the-miter-id-field-by-syslog-in-cef-format-is-it/m-p/415629#M824</guid>
      <dc:creator>etugriceri</dc:creator>
      <dc:date>2021-06-28T15:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: Forward the Miter ID field by Syslog in CEF format, is it possible?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forward-the-miter-id-field-by-syslog-in-cef-format-is-it/m-p/415744#M827</link>
      <description>&lt;P&gt;Hi Rodrigoduarte&lt;/P&gt;&lt;P&gt;Yes, if you are looking for the mitre id inside the syslog alert itself, its not included as specified by link posted by Etugriceri&lt;/P&gt;&lt;P&gt;Feature request can be requested on this.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 21:25:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forward-the-miter-id-field-by-syslog-in-cef-format-is-it/m-p/415744#M827</guid>
      <dc:creator>jcandelaria</dc:creator>
      <dc:date>2021-06-28T21:25:32Z</dc:date>
    </item>
  </channel>
</rss>

