<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XDR Analytics Data source in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-analytics-data-source/m-p/1229122#M8309</link>
    <description>&lt;P&gt;&lt;SPAN&gt;&lt;A class="relative pointer-events-auto a cursor-pointer
  
  
  
  
  underline
  " href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Analytics-Alert-Reference-by-data-source/BitLocker-key-retrieval" target="_blank" rel="noopener nofollow ugc"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Analytics-Alert-Reference-by-data-source/BitLocker-key-retrieval&lt;/A&gt;&amp;nbsp;&lt;A class="relative pointer-events-auto a cursor-pointer
  
  
  
  
  underline
  " href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Analytics-Alert-Reference-by-data-source/Exchange-mailbox-audit-bypass" target="_blank" rel="noopener nofollow ugc"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Analytics-Alert-Reference-by-data-source/Exchange-mailbox-audit-bypass&lt;/A&gt;&amp;nbsp;In the Analytics Alert reference guide- there is a reference to "AzureAD Audit Log" and "Office 365 Audit". Which Collection Integrations do I have to use to get these logs?&amp;nbsp; Looking to have full coverage over all the identity threat ITDR alerts that mentions Required data as "Office 365 Audit" and "AzureAD Audit Log". I think configuring all the options in both the Collection Integrations&amp;nbsp; "Azure Event Hub" and "Office 365" might cause some duplicates which might affect analytics. Do anyone know what config I can use to only cover the ITDR alerts with required data mentioned as "Office 365 Audit" and "AzureAD Audit Log"?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 15 May 2025 04:37:46 GMT</pubDate>
    <dc:creator>bridgetlitt</dc:creator>
    <dc:date>2025-05-15T04:37:46Z</dc:date>
    <item>
      <title>XDR Analytics Data source</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-analytics-data-source/m-p/1229122#M8309</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;A class="relative pointer-events-auto a cursor-pointer
  
  
  
  
  underline
  " href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Analytics-Alert-Reference-by-data-source/BitLocker-key-retrieval" target="_blank" rel="noopener nofollow ugc"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Analytics-Alert-Reference-by-data-source/BitLocker-key-retrieval&lt;/A&gt;&amp;nbsp;&lt;A class="relative pointer-events-auto a cursor-pointer
  
  
  
  
  underline
  " href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Analytics-Alert-Reference-by-data-source/Exchange-mailbox-audit-bypass" target="_blank" rel="noopener nofollow ugc"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Analytics-Alert-Reference-by-data-source/Exchange-mailbox-audit-bypass&lt;/A&gt;&amp;nbsp;In the Analytics Alert reference guide- there is a reference to "AzureAD Audit Log" and "Office 365 Audit". Which Collection Integrations do I have to use to get these logs?&amp;nbsp; Looking to have full coverage over all the identity threat ITDR alerts that mentions Required data as "Office 365 Audit" and "AzureAD Audit Log". I think configuring all the options in both the Collection Integrations&amp;nbsp; "Azure Event Hub" and "Office 365" might cause some duplicates which might affect analytics. Do anyone know what config I can use to only cover the ITDR alerts with required data mentioned as "Office 365 Audit" and "AzureAD Audit Log"?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 May 2025 04:37:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-analytics-data-source/m-p/1229122#M8309</guid>
      <dc:creator>bridgetlitt</dc:creator>
      <dc:date>2025-05-15T04:37:46Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Analytics Data source</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-analytics-data-source/m-p/1229514#M8320</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/710084109"&gt;@bridgetlitt&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out to us. In Office 365 log collection integration there is option to select Azure AD activity logs. Hence to avoid duplication of data Office 365 integration will be better.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 17:07:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-analytics-data-source/m-p/1229514#M8320</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2025-05-20T17:07:54Z</dc:date>
    </item>
  </channel>
</rss>

