<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Integrating Log Audit Management XDR / XSOAR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-log-audit-management-xdr-xsoar/m-p/1234027#M8548</link>
    <description>&lt;P&gt;Hi A.Faruq,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is possible to integrate and send Audit Management logs to a SIEM, like Elastic search or other, There is no native integration, but there is a possibility to do such by:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1- Create a new syslog server configuration. Please follow the doc below, and ensure you are following the prerequisites:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Integrate-a-syslog-receiver" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Integrate-a-syslog-receiver&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;2- Configure a new notification forwarding selecting the scope as Management Audit Logs which is what you want to send to your Elastic instance. In this step, the syslog server where you send the Management Audit Logs is the one you have created in the previous step. Please check the doc:&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Cloud-Documentation/Configure-notification-forwarding#" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Cloud-Documentation/Configure-notification-forwarding#&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KR,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luis&lt;/P&gt;</description>
    <pubDate>Tue, 15 Jul 2025 11:35:21 GMT</pubDate>
    <dc:creator>eluis</dc:creator>
    <dc:date>2025-07-15T11:35:21Z</dc:date>
    <item>
      <title>Integrating Log Audit Management XDR / XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-log-audit-management-xdr-xsoar/m-p/1233871#M8545</link>
      <description>&lt;P&gt;Dear Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any documentation about how to integrate Audit Management XDR and XSOAR for a SIEM like Elastic? I need a centralized log audit for monitoring.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2025 01:50:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-log-audit-management-xdr-xsoar/m-p/1233871#M8545</guid>
      <dc:creator>A.Faruq</dc:creator>
      <dc:date>2025-07-14T01:50:14Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating Log Audit Management XDR / XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-log-audit-management-xdr-xsoar/m-p/1234027#M8548</link>
      <description>&lt;P&gt;Hi A.Faruq,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is possible to integrate and send Audit Management logs to a SIEM, like Elastic search or other, There is no native integration, but there is a possibility to do such by:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1- Create a new syslog server configuration. Please follow the doc below, and ensure you are following the prerequisites:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Integrate-a-syslog-receiver" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Integrate-a-syslog-receiver&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;2- Configure a new notification forwarding selecting the scope as Management Audit Logs which is what you want to send to your Elastic instance. In this step, the syslog server where you send the Management Audit Logs is the one you have created in the previous step. Please check the doc:&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Cloud-Documentation/Configure-notification-forwarding#" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Cloud-Documentation/Configure-notification-forwarding#&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KR,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luis&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2025 11:35:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-log-audit-management-xdr-xsoar/m-p/1234027#M8548</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2025-07-15T11:35:21Z</dc:date>
    </item>
  </channel>
</rss>

