<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XSIAM | Palo Alto in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam-palo-alto/m-p/556493#M10</link>
    <description>&lt;P&gt;Hi Communnity&lt;/P&gt;
&lt;P&gt;,&lt;/P&gt;
&lt;P&gt;I would like to know few things about Cortex XSIAM solution:&lt;/P&gt;
&lt;P&gt;1. Auto Discovery feature: If any new log source is added, can the solution notify?&lt;BR /&gt;2. How the asset risk score is calculated?&lt;BR /&gt;3. In XSIAM, full raw logs of XDR/SIEM will be available or only parsed data?&lt;BR /&gt;4. Upgradation of XDR/SOAR/TIP/SIEM will be done all at once or one at a time?&lt;BR /&gt;5. How do the solution mimnimizes log delay? How often do we observe delays?&lt;BR /&gt;6. Where are the DC and DR placed?&lt;BR /&gt;7. Do we have any feature in XSIAM for forensics?&lt;BR /&gt;8. How does the licensing work? How much EPS is supported without slowness?&lt;BR /&gt;9. Need to know the exact flow of data.&lt;BR /&gt;10. How many conectors are available? (API). In case if connector is not available, how much time does it take for integration?&lt;BR /&gt;11. Any OOTB use cases/policies available?&lt;/P&gt;</description>
    <pubDate>Tue, 05 Sep 2023 11:43:55 GMT</pubDate>
    <dc:creator>hrishikeshkale</dc:creator>
    <dc:date>2023-09-05T11:43:55Z</dc:date>
    <item>
      <title>Cortex XSIAM | Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam-palo-alto/m-p/556493#M10</link>
      <description>&lt;P&gt;Hi Communnity&lt;/P&gt;
&lt;P&gt;,&lt;/P&gt;
&lt;P&gt;I would like to know few things about Cortex XSIAM solution:&lt;/P&gt;
&lt;P&gt;1. Auto Discovery feature: If any new log source is added, can the solution notify?&lt;BR /&gt;2. How the asset risk score is calculated?&lt;BR /&gt;3. In XSIAM, full raw logs of XDR/SIEM will be available or only parsed data?&lt;BR /&gt;4. Upgradation of XDR/SOAR/TIP/SIEM will be done all at once or one at a time?&lt;BR /&gt;5. How do the solution mimnimizes log delay? How often do we observe delays?&lt;BR /&gt;6. Where are the DC and DR placed?&lt;BR /&gt;7. Do we have any feature in XSIAM for forensics?&lt;BR /&gt;8. How does the licensing work? How much EPS is supported without slowness?&lt;BR /&gt;9. Need to know the exact flow of data.&lt;BR /&gt;10. How many conectors are available? (API). In case if connector is not available, how much time does it take for integration?&lt;BR /&gt;11. Any OOTB use cases/policies available?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 11:43:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam-palo-alto/m-p/556493#M10</guid>
      <dc:creator>hrishikeshkale</dc:creator>
      <dc:date>2023-09-05T11:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XSIAM | Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam-palo-alto/m-p/556539#M11</link>
      <description>&lt;P&gt;Hello Hrishikeshkale,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) No, it is up to the administrator onboarding the logs to complete the process by properly parsing them to a dataset and then modeling the data as needed (either via marketplace content, or custom modeling rules)&lt;/P&gt;
&lt;P&gt;2) Asset risk score is a summation of all alert scores involving an asset for the last seven days&lt;/P&gt;
&lt;P&gt;3) Full raw logs are available for EDR data as well as any logs brought in as RAW format (syslog, json, etc.), other sources are currently only available in their parsed form&lt;/P&gt;
&lt;P&gt;4) I believe you are referring to server-side upgrades of XSIAM itself?&amp;nbsp; If so, there is no separation of "modules" within the product, XSIAM is a single solution incorporating components of other Cortex products.&amp;nbsp; XSIAM upgrades are released quarterly, typically, and applied over the weekend when released.&lt;/P&gt;
&lt;P&gt;5) XSIAM is a SaaS solution, resources are managed by Palo Alto Networks engineering teams, delays are not typical, however, there is log source monitoring available within the product.&lt;/P&gt;
&lt;P&gt;6) Please contact your account team for detailed product architecture information&lt;/P&gt;
&lt;P&gt;7) The forensics license add-on is available for the XDR agent, contact your account team for detailed information&lt;/P&gt;
&lt;P&gt;8.Please contact your account team for licensing information and see #5 above&lt;/P&gt;
&lt;P&gt;9) I cannot answer this without much more detailed information, please contact your account team to discuss your scenario(s)&lt;/P&gt;
&lt;P&gt;10) Our in-product Marketplace has hundreds of content packs available including integrations to various 3rd party products and parsing/modeling rules for data retrieved from these solutions, please contact your account team for a detailed discussion of your integration needs and available out of the box content&lt;/P&gt;
&lt;P&gt;11) This cannot be answered without a more detailed discussion of your needs/use cases, please contact your account team&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 14:05:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam-palo-alto/m-p/556539#M11</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2023-09-05T14:05:31Z</dc:date>
    </item>
  </channel>
</rss>

