<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Procedures for Integrating SLS and Cortex XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/procedures-for-integrating-sls-and-cortex-xdr/m-p/1252015#M9245</link>
    <description>&lt;P&gt;Hi, &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/241098"&gt;@susekar&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your comment.&lt;BR /&gt;I can't find the “Strata Logging Service” section under “Collection Integrations” in the XDR management console. Do you know why that might be?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;</description>
    <pubDate>Fri, 10 Apr 2026 06:04:53 GMT</pubDate>
    <dc:creator>D.Watanabe454116</dc:creator>
    <dc:date>2026-04-10T06:04:53Z</dc:date>
    <item>
      <title>Procedures for Integrating SLS and Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/procedures-for-integrating-sls-and-cortex-xdr/m-p/1251940#M9243</link>
      <description>&lt;P&gt;Hello.&lt;BR /&gt;This is my first time using Cortex XDR and SLS. I understand the procedure for integrating PA and SLS, but I’m not quite sure how to integrate SLS and XDR. I haven’t been able to find any instructions on any website. Could someone please help me?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 10:09:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/procedures-for-integrating-sls-and-cortex-xdr/m-p/1251940#M9243</guid>
      <dc:creator>D.Watanabe454116</dc:creator>
      <dc:date>2026-04-09T10:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: Procedures for Integrating SLS and Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/procedures-for-integrating-sls-and-cortex-xdr/m-p/1251970#M9244</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1615570263"&gt;@D.Watanabe454116&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="flex flex-col text-sm pb-25"&gt;
&lt;SECTION class="text-token-text-primary w-full focus:outline-none [--shadow-height:45px] has-data-writing-block:pointer-events-none has-data-writing-block:-mt-(--shadow-height) has-data-writing-block:pt-(--shadow-height) [&amp;amp;:has([data-writing-block])&amp;gt;*]:pointer-events-auto scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" data-turn="assistant" data-scroll-anchor="true" data-testid="conversation-turn-16" data-turn-id="request-WEB:358a5213-a90e-4527-a384-1953c1b320a4-7"&gt;
&lt;DIV class="text-base my-auto mx-auto pb-10 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)"&gt;
&lt;DIV class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn"&gt;
&lt;DIV class="flex max-w-full flex-col gap-4 grow"&gt;
&lt;DIV class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal outline-none keyboard-focused:focus-ring [.text-message+&amp;amp;]:mt-1" dir="auto" tabindex="0" data-turn-start-message="true" data-message-model-slug="gpt-5-3" data-message-id="3a1b46f8-a765-47bf-b893-ad564b8d3910" data-message-author-role="assistant"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden"&gt;
&lt;DIV class="markdown prose dark:prose-invert w-full wrap-break-word light markdown-new-styling"&gt;
&lt;P data-end="127" data-start="67"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="408" data-start="129"&gt;Integrating Strata Logging Service (SLS) with Cortex XDR allows the XDR platform to ingest and correlate detection data from Palo Alto Networks products (like NGFW or Prisma Access) that are already logging to an existing SLS instance (formerly known as Cortex Data Lake or CDL).&lt;/P&gt;
&lt;H4 data-end="436" data-start="415" data-section-id="5j00zn"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 data-end="436" data-start="415" data-section-id="5j00zn"&gt;&lt;SPAN&gt;&lt;STRONG data-end="436" data-start="419"&gt;Prerequisites:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P data-end="513" data-start="437"&gt;Before beginning the integration, ensure the following requirements are met:&lt;/P&gt;
&lt;UL data-end="948" data-start="515"&gt;
&lt;LI data-end="588" data-start="515" data-section-id="7wd3m5"&gt;&lt;STRONG data-end="531" data-start="517"&gt;Licensing:&lt;/STRONG&gt; You must have a Cortex XDR Pro per GB license enabled.&lt;/LI&gt;
&lt;LI data-end="694" data-start="589" data-section-id="551lnu"&gt;&lt;STRONG data-end="607" data-start="591"&gt;Permissions:&lt;/STRONG&gt; You must hold Super User permissions for your Customer Support Portal (CSP) account.&lt;/LI&gt;
&lt;LI data-end="948" data-start="695" data-section-id="3ukv5v"&gt;&lt;STRONG data-end="720" data-start="697"&gt;Regional Alignment:&lt;/STRONG&gt; The Cortex XDR tenant and the SLS/CDL instance must be provisioned in the exact same geographical region (e.g., both in US or both in EU). A region mismatch will prevent the SLS instance from being visible in the XDR console.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-end="980" data-start="955" data-section-id="1c94fy1"&gt;&lt;SPAN&gt;&lt;STRONG data-end="980" data-start="959"&gt;Integration Steps:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P data-end="1082" data-start="981"&gt;To configure the connection between SLS and Cortex XDR, follow these steps in the management console:&lt;/P&gt;
&lt;OL data-end="1602" data-start="1084"&gt;
&lt;LI data-end="1134" data-start="1084" data-section-id="1nrk23k"&gt;Log in to your Cortex XDR Management Console.&lt;/LI&gt;
&lt;LI data-end="1364" data-start="1135" data-section-id="12j9ma2"&gt;Navigate to:&lt;BR data-end="1153" data-start="1150" /&gt;&lt;STRONG data-end="1229" data-start="1156"&gt;Settings → Configurations → Data Collection → Collection Integrations&lt;/STRONG&gt;
&lt;UL data-end="1364" data-start="1235"&gt;
&lt;LI data-end="1364" data-start="1235" data-section-id="1vla6hl"&gt;Note: In some newer tenants migrated to Cloud Logging Collection, the path may be &lt;STRONG data-end="1353" data-start="1319"&gt;Data Collection → Data Sources&lt;/STRONG&gt; instead.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI data-end="1443" data-start="1365" data-section-id="51nuys"&gt;Locate the &lt;STRONG data-end="1405" data-start="1379"&gt;Strata Logging Service&lt;/STRONG&gt; section and click &lt;STRONG data-end="1440" data-start="1424"&gt;Add Instance&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI data-end="1479" data-start="1444" data-section-id="11ric5f"&gt;Select &lt;STRONG data-end="1476" data-start="1454"&gt;Data Lake Instance&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI data-end="1573" data-start="1480" data-section-id="56jgx9"&gt;Select the existing Strata Logging Service instances you wish to connect to this tenant.&lt;/LI&gt;
&lt;LI data-end="1602" data-start="1574" data-section-id="82adiz"&gt;Save the configuration.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H3 data-end="1629" data-start="1609" data-section-id="127xt8f"&gt;&lt;SPAN&gt;&lt;STRONG data-end="1629" data-start="1613"&gt;Verification:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P data-end="1692" data-start="1630"&gt;Once configured, you can verify the status of the integration:&lt;/P&gt;
&lt;UL data-end="2090" data-start="1694"&gt;
&lt;LI data-end="1848" data-start="1694" data-section-id="1k6kvnc"&gt;&lt;STRONG data-end="1720" data-start="1696"&gt;Visual Confirmation:&lt;/STRONG&gt; A green check mark will appear underneath the Strata Logging Service configuration once events begin to flow into the tenant.&lt;/LI&gt;
&lt;LI data-end="1957" data-start="1849" data-section-id="sbh8qi"&gt;&lt;STRONG data-end="1869" data-start="1851"&gt;Querying Data:&lt;/STRONG&gt; You can use XQL Search to confirm data presence by querying the &lt;STRONG data-end="1946" data-start="1934"&gt;xdr_data&lt;/STRONG&gt; dataset.&lt;/LI&gt;
&lt;LI data-end="2090" data-start="1958" data-section-id="tx127g"&gt;&lt;STRONG data-end="1977" data-start="1960"&gt;Firewall CLI:&lt;/STRONG&gt; On the firewall side, you can use the following command to confirm the connection status to the logging service:&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="w-full overflow-x-hidden overflow-y-auto pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼ5 ͼj" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;request logging-service-forwarding status&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&lt;STRONG style="color: inherit; font-family: 'TT Hoves', DecimalMedium, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 18px;" data-end="2178" data-start="2152"&gt;(Support and Assistance)&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;UL data-end="2580" data-start="2180"&gt;
&lt;LI data-end="2304" data-start="2180" data-section-id="1wnfasn"&gt;&lt;STRONG data-end="2210" data-start="2182"&gt;Technical Support (TAC):&lt;/STRONG&gt; Assists with "break/fix" issues where an existing configuration is not working as expected.&lt;/LI&gt;
&lt;LI data-end="2471" data-start="2305" data-section-id="11u0b8i"&gt;&lt;STRONG data-end="2347" data-start="2307"&gt;Sales Engineer (SE) or Account Team:&lt;/STRONG&gt; Contact for guidance on new implementations, architectural designs, or complex multi-tenant/multi-account configurations.&lt;/LI&gt;
&lt;LI data-end="2580" data-start="2472" data-section-id="zxdbr4"&gt;&lt;STRONG data-end="2500" data-start="2474"&gt;Professional Services:&lt;/STRONG&gt; Recommended for in-depth setup assistance or creating specific parsing rules.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-end="2625" data-start="2587" data-section-id="1qb7qv4"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 data-end="2625" data-start="2587" data-section-id="1qb7qv4"&gt;&lt;SPAN&gt;&lt;STRONG data-end="2625" data-start="2591"&gt;Important Note for New Tenants:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P data-is-only-node="" data-is-last-node="" data-end="2910" data-start="2626"&gt;If you are using a new tenant, Cortex XDR now supports direct integration (via the Cloud Logging Collection Service or CLCS) where firewalls and Panorama send logs directly to Cortex XDR without requiring a separate manual SLS/CDL setup. This is often the default for new activations.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="z-0 flex min-h-[46px] justify-start"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;/DIV&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;like&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 15:22:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/procedures-for-integrating-sls-and-cortex-xdr/m-p/1251970#M9244</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-04-09T15:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: Procedures for Integrating SLS and Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/procedures-for-integrating-sls-and-cortex-xdr/m-p/1252015#M9245</link>
      <description>&lt;P&gt;Hi, &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/241098"&gt;@susekar&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your comment.&lt;BR /&gt;I can't find the “Strata Logging Service” section under “Collection Integrations” in the XDR management console. Do you know why that might be?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2026 06:04:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/procedures-for-integrating-sls-and-cortex-xdr/m-p/1252015#M9245</guid>
      <dc:creator>D.Watanabe454116</dc:creator>
      <dc:date>2026-04-10T06:04:53Z</dc:date>
    </item>
  </channel>
</rss>

