<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Integrating Cortex wth QRadar in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-cortex-wth-qradar/m-p/1252101#M9247</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="message-list_1776085647.675639" aria-setsize="-1"&gt;
&lt;DIV&gt;
&lt;DIV aria-roledescription="message"&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;Hello Everyone,&lt;BR /&gt;&lt;BR /&gt;Does the installed Cortex XDR for QRadar Version1.2.0 and config it via syslog allow receive Alerts directly from Cortex XDR into QRadar?&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I found&amp;nbsp;&lt;SPAN draggable="true"&gt;&lt;A href="https://apps.xforce.ibmcloud.com/extension/d12c3794f142ee334b4bbdc83d10347f" rel="noopener noreferrer" target="_blank"&gt;https://apps.xforce.ibmcloud.com/extension/d12c3794f142ee334b4bbdc83d10347f&lt;/A&gt;&amp;nbsp;but not able to find newer version.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;BR aria-hidden="true" /&gt;Can someone know if there is other way to receive alerts directly from Cortex XDR into QRadar?&lt;BR /&gt;&lt;BR /&gt;My Goal is to have everything what will appear in Tenant visible in QRadar.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Appreciate any feedbacks.&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="message-list_1776085659.758719" aria-setsize="-1"&gt;
&lt;DIV&gt;
&lt;DIV aria-roledescription="message"&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Mon, 13 Apr 2026 13:11:15 GMT</pubDate>
    <dc:creator>Noshutdown</dc:creator>
    <dc:date>2026-04-13T13:11:15Z</dc:date>
    <item>
      <title>Integrating Cortex wth QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-cortex-wth-qradar/m-p/1252101#M9247</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="message-list_1776085647.675639" aria-setsize="-1"&gt;
&lt;DIV&gt;
&lt;DIV aria-roledescription="message"&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;Hello Everyone,&lt;BR /&gt;&lt;BR /&gt;Does the installed Cortex XDR for QRadar Version1.2.0 and config it via syslog allow receive Alerts directly from Cortex XDR into QRadar?&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I found&amp;nbsp;&lt;SPAN draggable="true"&gt;&lt;A href="https://apps.xforce.ibmcloud.com/extension/d12c3794f142ee334b4bbdc83d10347f" rel="noopener noreferrer" target="_blank"&gt;https://apps.xforce.ibmcloud.com/extension/d12c3794f142ee334b4bbdc83d10347f&lt;/A&gt;&amp;nbsp;but not able to find newer version.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;BR aria-hidden="true" /&gt;Can someone know if there is other way to receive alerts directly from Cortex XDR into QRadar?&lt;BR /&gt;&lt;BR /&gt;My Goal is to have everything what will appear in Tenant visible in QRadar.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Appreciate any feedbacks.&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="message-list_1776085659.758719" aria-setsize="-1"&gt;
&lt;DIV&gt;
&lt;DIV aria-roledescription="message"&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 13 Apr 2026 13:11:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-cortex-wth-qradar/m-p/1252101#M9247</guid>
      <dc:creator>Noshutdown</dc:creator>
      <dc:date>2026-04-13T13:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating Cortex wth QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-cortex-wth-qradar/m-p/1252105#M9249</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56546"&gt;@Noshutdown&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The Cortex XDR for QRadar extension (Version 1.2.0) and standard syslog configuration allow QRadar to receive alerts and audit logs directly from the Cortex XDR tenant. However, standard syslog integration is limited in scope and does not support forwarding raw endpoint telemetry or full EDR data.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H4 data-end="462" data-start="416" data-section-id="xfqe46"&gt;1. Integration Methods and Data Visibility:&lt;/H4&gt;
&lt;P data-end="581" data-start="464"&gt;To achieve your goal of visibility in QRadar, you must choose the integration method based on the data type required:&lt;/P&gt;
&lt;UL data-end="1213" data-start="583"&gt;
&lt;LI data-end="761" data-start="583" data-section-id="1ltnt83"&gt;&lt;STRONG data-end="616" data-start="585"&gt;Syslog Forwarding (Direct):&lt;/STRONG&gt;&lt;BR data-end="619" data-start="616" /&gt;Supports Alerts, Agent Audit Logs, and Management Audit Logs.&lt;BR data-end="685" data-start="682" /&gt;It does &lt;STRONG data-end="702" data-start="695"&gt;not&lt;/STRONG&gt; support incidents (as a separate object) or raw telemetry.&lt;/LI&gt;
&lt;LI data-end="912" data-start="763" data-section-id="dka5vm"&gt;&lt;STRONG data-end="787" data-start="765"&gt;Public API (Pull):&lt;/STRONG&gt;&lt;BR data-end="790" data-start="787" /&gt;QRadar can use the Cortex XDR REST API to retrieve more comprehensive data, including Incidents and Extra Incident Data.&lt;/LI&gt;
&lt;LI data-end="1213" data-start="914" data-section-id="1p58j08"&gt;&lt;STRONG data-end="946" data-start="916"&gt;Event Forwarding (Egress):&lt;/STRONG&gt;&lt;BR data-end="949" data-start="946" /&gt;To see "everything" (raw telemetry/EDR logs), you must use the Event Forwarding feature, which streams raw logs to cloud storage (e.g., AWS S3, Google Cloud Storage), where QRadar can then ingest them.&lt;BR data-end="1155" data-start="1152" /&gt;This typically requires a Cortex XDR Pro per TB license.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-end="1256" data-start="1220" data-section-id="1t6x7bx"&gt;2. Extension Version and Support:&lt;/H4&gt;
&lt;P data-end="1455" data-start="1258"&gt;The "Cortex XDR for QRadar" extension is listed on the IBM X-Force App Exchange, but the standard Technical Assistance Center (TAC) does not maintain the versioning details or the installer itself.&lt;/P&gt;
&lt;UL data-end="1605" data-start="1457"&gt;
&lt;LI data-end="1605" data-start="1457" data-section-id="1by4xtr"&gt;&lt;STRONG data-end="1481" data-start="1459"&gt;Dedicated Support:&lt;/STRONG&gt;&lt;BR data-end="1484" data-start="1481" /&gt;For the latest version, download links, or specialized parsing assistance, contact:&lt;BR data-end="1572" data-start="1569" /&gt;&lt;STRONG data-end="1605" data-start="1574"&gt;&lt;A class="decorated-link cursor-pointer" rel="noopener" data-end="1603" data-start="1576" target="_blank"&gt;qradar@paloaltonetworks.com&lt;BR /&gt;&lt;BR /&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-end="1664" data-start="1612" data-section-id="1ybqzar"&gt;3. Syslog Format Compatibility (Cortex XDR 5.0+):&lt;/H4&gt;
&lt;P data-end="1774" data-start="1666"&gt;If you are running Cortex XDR 5.0 or newer, be aware of a significant architectural change regarding syslog:&lt;/P&gt;
&lt;UL data-end="2094" data-start="1776"&gt;
&lt;LI data-end="1894" data-start="1776" data-section-id="1nympk7"&gt;&lt;STRONG data-end="1802" data-start="1778"&gt;Missing Incident ID:&lt;/STRONG&gt;&lt;BR data-end="1805" data-start="1802" /&gt;The incident (Case ID) field is no longer included in the "Alert Standard" CEF payload.&lt;/LI&gt;
&lt;LI data-end="2094" data-start="1896" data-section-id="car78a"&gt;If your QRadar correlation rules rely on this field, you may need to use the &lt;STRONG data-end="1993" data-start="1975"&gt;"Alert Legacy"&lt;/STRONG&gt; log format.&lt;BR data-end="2008" data-start="2005" /&gt;Note that this format uses a CSV structure and may require custom parsing in QRadar.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-end="2139" data-start="2101" data-section-id="8zrnbs"&gt;4. Recommended Configuration Steps:&lt;/H4&gt;
&lt;P data-end="2187" data-start="2141"&gt;To configure standard direct alert forwarding:&lt;/P&gt;
&lt;OL data-end="2778" data-start="2189"&gt;
&lt;LI data-end="2349" data-start="2189" data-section-id="1if8mzl"&gt;&lt;STRONG data-end="2222" data-start="2192"&gt;Configure Syslog Receiver:&lt;/STRONG&gt;&lt;BR data-end="2225" data-start="2222" /&gt;Navigate to:&lt;BR data-end="2243" data-start="2240" /&gt;&lt;CODE data-end="2312" data-start="2246"&gt;Settings → Configurations → Integrations → External Applications&lt;/CODE&gt;&lt;BR data-end="2315" data-start="2312" /&gt;Add your QRadar server details.&lt;/LI&gt;
&lt;LI data-end="2480" data-start="2351" data-section-id="1pkyyv5"&gt;&lt;STRONG data-end="2387" data-start="2354"&gt;Notification Forwarding Rule:&lt;/STRONG&gt;&lt;BR data-end="2390" data-start="2387" /&gt;Navigate to:&lt;BR data-end="2408" data-start="2405" /&gt;&lt;CODE data-end="2480" data-start="2411"&gt;Settings → Configurations → Notifications → Notification Forwarding&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI data-end="2601" data-start="2482" data-section-id="19xbbn9"&gt;&lt;STRONG data-end="2504" data-start="2485"&gt;Data Selection:&lt;/STRONG&gt;&lt;BR data-end="2507" data-start="2504" /&gt;Create a rule selecting &lt;STRONG data-end="2544" data-start="2534"&gt;Alerts&lt;/STRONG&gt; and/or &lt;STRONG data-end="2566" data-start="2552"&gt;Audit Logs&lt;/STRONG&gt; to be sent to the QRadar receiver.&lt;/LI&gt;
&lt;LI data-end="2778" data-start="2603" data-section-id="ytft87"&gt;&lt;STRONG data-end="2621" data-start="2606"&gt;Log Format:&lt;/STRONG&gt;&lt;BR data-end="2624" data-start="2621" /&gt;For out-of-the-box parsing in SIEMs, ensure the &lt;STRONG data-end="2702" data-start="2675"&gt;"Use Legacy Log Format"&lt;/STRONG&gt; checkbox is &lt;STRONG data-end="2728" data-start="2715"&gt;unchecked&lt;/STRONG&gt;, which defaults to &lt;STRONG data-end="2777" data-start="2748"&gt;Common Event Format (CEF)&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2026 13:47:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-cortex-wth-qradar/m-p/1252105#M9249</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-04-13T13:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating Cortex wth QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-cortex-wth-qradar/m-p/1252461#M9261</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in case of&amp;nbsp;&lt;SPAN&gt;Cortex XDR&amp;nbsp;cloud and QRadar inside private network such forward hard to be done.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;using&amp;nbsp;&lt;SPAN&gt;Universal Cloud REST API protocol&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;here the workflow files&lt;/SPAN&gt;&lt;BR /&gt;&lt;A class="relative pointer-events-auto a cursor-pointer
  
  
  
  
  underline" href="https://github.com/iceMBD/Workflow-Palo-Alto-Cortex-XDR-Integration-for-IBM-QRadar/tree/main" rel="noopener nofollow ugc" target="_blank"&gt;https://github.com/iceMBD/Workflow-Palo-Alto-Cortex-XDR-Integration-for-IBM-QRadar/tree/main&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2026 20:39:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-cortex-wth-qradar/m-p/1252461#M9261</guid>
      <dc:creator>m.abulamddi</dc:creator>
      <dc:date>2026-04-17T20:39:47Z</dc:date>
    </item>
  </channel>
</rss>

