<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Parsing and Mapping 3rd party log source logs in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/parsing-and-mapping-3rd-party-log-source-logs/m-p/1233729#M8537</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We’re in the process of ingesting logs from multiple third-party systems into Cortex XDR, but the current documentation on user-defined parsing rules and dataset mapping isn’t clear enough. Is it possible to get a detailed step-by step plan on how to properly:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;Define and register a new dataset (&lt;EM&gt;dell_powerprotect_data_manager&lt;/EM&gt;).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Write and apply parsing rules to extract fields from raw syslog entries (currently landing in &lt;EM&gt;unknown_unknown_raw&lt;/EM&gt;).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Map parsed events into their dedicated dataset.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;At the moment, there is a parsing rule set (photo attached) and in the query builder, I've run a query with a target_dataset parameter which moved logs from &lt;EM&gt;unknown_unknown_raw&lt;/EM&gt; logs to a custom &lt;EM&gt;dell_powerprotect_data_manager&lt;/EM&gt; dataset. When a query "&lt;EM&gt;dataset =&amp;nbsp;dell_powerprotect_data_manager | sort desc _time"&lt;/EM&gt;&amp;nbsp;completed, the mapped logs are shown, BUT there is a problem that these logs are only those who appeared on XDR until the date/time when the query with 'target_dataset' was run and no new logs are being moved from&amp;nbsp;unknown_unknown_raw to&amp;nbsp;dell_powerprotect_data_manager. &lt;STRONG&gt;What would be the solution &lt;FONT color="#FF0000"&gt;to make those logs move in real time between these two datasets&lt;/FONT&gt;?&lt;/STRONG&gt; I've heard that there is a possibility to create some sort of preset that move logs in real time to preferred dataset?? Also, do I only need to use the [INGEST] section when setting up the rule or do I also need to use [COLLECT/CONST/RULE] sections?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PARSING RULE.png" style="width: 822px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68429iC329385B4081713D/image-size/large?v=v2&amp;amp;px=999" role="button" title="PARSING RULE.png" alt="PARSING RULE.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jul 2025 11:18:33 GMT</pubDate>
    <dc:creator>paIoaItonetworks</dc:creator>
    <dc:date>2025-07-10T11:18:33Z</dc:date>
    <item>
      <title>Parsing and Mapping 3rd party log source logs</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/parsing-and-mapping-3rd-party-log-source-logs/m-p/1233729#M8537</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We’re in the process of ingesting logs from multiple third-party systems into Cortex XDR, but the current documentation on user-defined parsing rules and dataset mapping isn’t clear enough. Is it possible to get a detailed step-by step plan on how to properly:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;Define and register a new dataset (&lt;EM&gt;dell_powerprotect_data_manager&lt;/EM&gt;).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Write and apply parsing rules to extract fields from raw syslog entries (currently landing in &lt;EM&gt;unknown_unknown_raw&lt;/EM&gt;).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Map parsed events into their dedicated dataset.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;At the moment, there is a parsing rule set (photo attached) and in the query builder, I've run a query with a target_dataset parameter which moved logs from &lt;EM&gt;unknown_unknown_raw&lt;/EM&gt; logs to a custom &lt;EM&gt;dell_powerprotect_data_manager&lt;/EM&gt; dataset. When a query "&lt;EM&gt;dataset =&amp;nbsp;dell_powerprotect_data_manager | sort desc _time"&lt;/EM&gt;&amp;nbsp;completed, the mapped logs are shown, BUT there is a problem that these logs are only those who appeared on XDR until the date/time when the query with 'target_dataset' was run and no new logs are being moved from&amp;nbsp;unknown_unknown_raw to&amp;nbsp;dell_powerprotect_data_manager. &lt;STRONG&gt;What would be the solution &lt;FONT color="#FF0000"&gt;to make those logs move in real time between these two datasets&lt;/FONT&gt;?&lt;/STRONG&gt; I've heard that there is a possibility to create some sort of preset that move logs in real time to preferred dataset?? Also, do I only need to use the [INGEST] section when setting up the rule or do I also need to use [COLLECT/CONST/RULE] sections?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PARSING RULE.png" style="width: 822px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68429iC329385B4081713D/image-size/large?v=v2&amp;amp;px=999" role="button" title="PARSING RULE.png" alt="PARSING RULE.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 11:18:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/parsing-and-mapping-3rd-party-log-source-logs/m-p/1233729#M8537</guid>
      <dc:creator>paIoaItonetworks</dc:creator>
      <dc:date>2025-07-10T11:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing and Mapping 3rd party log source logs</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/parsing-and-mapping-3rd-party-log-source-logs/m-p/1233732#M8538</link>
      <description>&lt;P&gt;Hi !&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At XQL query builder, you can set the run of your query that populates your custom dataset with the periodicity you want, so the dataset will be updated with the frequency you need. And you can set the query to overwrite the dataset or to append data at the end.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per your second question, you can use just the INGEST (for the dataset) and RULE (for the logic).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KR,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luis&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 14:18:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/parsing-and-mapping-3rd-party-log-source-logs/m-p/1233732#M8538</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2025-07-10T14:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing and Mapping 3rd party log source logs</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/parsing-and-mapping-3rd-party-log-source-logs/m-p/1233745#M8539</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/955812681"&gt;@paIoaItonetworks&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm assuming you're using vm broker because it's landing in&amp;nbsp;&lt;EM&gt;unknown_unknown_raw, so in order to adjust that&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;BR /&gt;&lt;BR /&gt;go to Configurations - &amp;gt;&amp;nbsp;&lt;/EM&gt;&lt;SPAN&gt;Data Broker -&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Broker VMs and then you could assign a custom port ( if you're receiving more than one category on the same port ) , then assign a vendor and product&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AElzedy_0-1752165711257.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68431iA51481C42321CBDA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AElzedy_0-1752165711257.png" alt="AElzedy_0-1752165711257.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 16:45:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/parsing-and-mapping-3rd-party-log-source-logs/m-p/1233745#M8539</guid>
      <dc:creator>A.Elzedy</dc:creator>
      <dc:date>2025-07-10T16:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing and Mapping 3rd party log source logs</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/parsing-and-mapping-3rd-party-log-source-logs/m-p/1233803#M8541</link>
      <description>&lt;P&gt;Is it also possible to somehow delete default parsing rules to which my custom datasets were saved? I can delete newly created datasets from dataset management, but default parsing rules are read-only, therefore I can't modify/delete them. I'd like to delete them and freshly reconfigure the parsing rule.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="paIoaItonetworks_0-1752221474506.png" style="width: 1153px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68443iA4EFD129D5A1A369/image-dimensions/1153x82?v=v2" width="1153" height="82" role="button" title="paIoaItonetworks_0-1752221474506.png" alt="paIoaItonetworks_0-1752221474506.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2025 08:12:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/parsing-and-mapping-3rd-party-log-source-logs/m-p/1233803#M8541</guid>
      <dc:creator>paIoaItonetworks</dc:creator>
      <dc:date>2025-07-11T08:12:52Z</dc:date>
    </item>
  </channel>
</rss>

