<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Parsing rule and data model Rule in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/parsing-rule-and-data-model-rule/m-p/1261468#M457</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="3"&gt;&lt;STRONG data-index-in-node="0" data-path-to-node="3"&gt;Hi Everyone,&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-path-to-node="4"&gt;We are currently ingesting syslog data from our Aruba switches into Cortex XSIAM/XDR using the &lt;STRONG data-index-in-node="95" data-path-to-node="4"&gt;HPE Switch&lt;/STRONG&gt; content pack, but the logs are not automatically normalizing into XDM fields.&lt;/P&gt;
&lt;P data-path-to-node="5"&gt;In our environment, when we query other datasets like &lt;STRONG data-index-in-node="54" data-path-to-node="5"&gt;Office 365, Zscaler, or AWS&lt;/STRONG&gt;, the logs are automatically parsed and normalized into &lt;CODE data-index-in-node="137" data-path-to-node="5"&gt;xdm.*&lt;/CODE&gt; fields upon querying. We are expecting the same behavior for &lt;CODE data-index-in-node="204" data-path-to-node="5"&gt;hpe_switch_raw&lt;/CODE&gt;, but it is currently showing only raw unparsed logs.&lt;/P&gt;
&lt;P data-path-to-node="6"&gt;Here are the details of our setup:&lt;/P&gt;
&lt;UL data-path-to-node="7"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="7,0,0"&gt;&lt;STRONG data-index-in-node="0" data-path-to-node="7,0,0"&gt;Ingestion Path:&lt;/STRONG&gt; Aruba Switch Syslog → Broker VM (UDP 514) → XSIAM&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="7,1,0"&gt;&lt;STRONG data-index-in-node="0" data-path-to-node="7,1,0"&gt;Syslog Target Settings:&lt;/STRONG&gt; &lt;CODE data-index-in-node="24" data-path-to-node="7,1,0"&gt;vendor = HPE&lt;/CODE&gt;, &lt;CODE data-index-in-node="38" data-path-to-node="7,1,0"&gt;product = Switch&lt;/CODE&gt;, Format: &lt;CODE data-index-in-node="64" data-path-to-node="7,1,0"&gt;auto-detect&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="7,2,0"&gt;&lt;STRONG data-index-in-node="0" data-path-to-node="7,2,0"&gt;Default Ingestion Rule Generated:&lt;/STRONG&gt; &lt;CODE data-index-in-node="34" data-path-to-node="7,2,0"&gt;[INGEST:vendor="HPE", product="Switch", target_dataset="hpe_switch_raw", no_hit=drop]&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="7,3,0"&gt;&lt;STRONG data-index-in-node="0" data-path-to-node="7,3,0"&gt;Issue:&lt;/STRONG&gt; The dataset &lt;CODE data-index-in-node="19" data-path-to-node="7,3,0"&gt;hpe_switch_raw&lt;/CODE&gt; is successfully created and logs are being ingested. However, when querying the dataset, only basic metadata fields appear (&lt;CODE data-index-in-node="158" data-path-to-node="7,3,0"&gt;_time&lt;/CODE&gt;, &lt;CODE data-index-in-node="165" data-path-to-node="7,3,0"&gt;_vendor&lt;/CODE&gt;, &lt;CODE data-index-in-node="174" data-path-to-node="7,3,0"&gt;_product&lt;/CODE&gt;, &lt;CODE data-index-in-node="184" data-path-to-node="7,3,0"&gt;_raw_log&lt;/CODE&gt;, &lt;CODE data-index-in-node="194" data-path-to-node="7,3,0"&gt;_broker_ip_address&lt;/CODE&gt;, etc.). The data normalization into &lt;CODE data-index-in-node="249" data-path-to-node="7,3,0"&gt;xdm.*&lt;/CODE&gt; fields is not happening automatically like it does for our other log sources.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-path-to-node="8"&gt;&lt;STRONG data-index-in-node="0" data-path-to-node="8"&gt;Sample Raw Logs:&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="code-block ng-tns-c1862742614-73 ng-animate-disabled ng-trigger ng-trigger-codeBlockRevealAnimation" data-ved="0CAAQhtANahgKEwjMsqKE6ZeWAxUAAAAAHQAAAAAQigE" data-hveid="0"&gt;
&lt;DIV class="formatted-code-block-internal-container ng-tns-c1862742614-73"&gt;
&lt;DIV class="animated-opacity ng-tns-c1862742614-73"&gt;
&lt;DIV class="code-block-decoration header-formatted gds-emphasized-body-m ng-tns-c1862742614-73 ng-star-inserted"&gt;&lt;SPAN class="ng-tns-c1862742614-73"&gt;Plaintext&lt;/SPAN&gt;
&lt;DIV class="buttons ng-tns-c1862742614-73 ng-star-inserted"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;PRE class="ng-tns-c1862742614-73"&gt;&lt;CODE class="code-container formatted ng-tns-c1862742614-73" role="text" data-test-id="code-content"&gt;&amp;lt;46&amp;gt;Jul 27 15:52:26 172.17.15.8 00435 ports: ST1-CMDR: port 1/44 is Blocked by STP
&amp;lt;46&amp;gt;Jul 27 15:52:32 172.17.156.8 00076 ports: ST1-CMDR: port 1/44 is now on-line
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-path-to-node="10"&gt;&lt;STRONG data-index-in-node="0" data-path-to-node="10"&gt;What We Observed:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL start="1" data-path-to-node="11"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="11,0,0"&gt;The HPE Switch Content Pack includes a Data Modeling Rule (DMR) with &lt;CODE data-index-in-node="69" data-path-to-node="11,0,0"&gt;regextract&lt;/CODE&gt; logic.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="11,1,0"&gt;When testing the &lt;CODE data-index-in-node="17" data-path-to-node="11,1,0"&gt;regextract&lt;/CODE&gt; logic directly in an XQL query, the fields extract correctly.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="11,2,0"&gt;However, out of the box, when we simply query &lt;CODE data-index-in-node="46" data-path-to-node="11,2,0"&gt;dataset = hpe_switch_raw&lt;/CODE&gt;, the logs remain unparsed in the &lt;CODE data-index-in-node="104" data-path-to-node="11,2,0"&gt;_raw_log&lt;/CODE&gt; field without default XDM normalization.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-path-to-node="12"&gt;&lt;STRONG data-index-in-node="0" data-path-to-node="12"&gt;Questions:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL start="1" data-path-to-node="13"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="13,0,0"&gt;Is the default Data Modeling Rule (DMR) sufficient to get parsed/normalized fields automatically when querying the dataset, or do we need to write a custom Ingestion Parsing Rule (PR) for HPE/Aruba switches?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="13,1,0"&gt;Could the leading Syslog Priority Tag (&lt;CODE data-index-in-node="39" data-path-to-node="13,1,0"&gt;&amp;lt;46&amp;gt;&lt;/CODE&gt;) in the raw log be breaking the Content Pack DMR regex matching?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="13,2,0"&gt;What is the best practice to get this dataset fully parsed and normalized out of the box like AWS, Zscaler, and Office 365?&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-path-to-node="14"&gt;Thanks in advance for your guidance!&lt;/P&gt;</description>
    <pubDate>Tue, 11 Aug 2026 10:59:48 GMT</pubDate>
    <dc:creator>Praveen0108</dc:creator>
    <dc:date>2026-08-11T10:59:48Z</dc:date>
    <item>
      <title>Parsing rule and data model Rule</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/parsing-rule-and-data-model-rule/m-p/1261468#M457</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="3"&gt;&lt;STRONG data-index-in-node="0" data-path-to-node="3"&gt;Hi Everyone,&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-path-to-node="4"&gt;We are currently ingesting syslog data from our Aruba switches into Cortex XSIAM/XDR using the &lt;STRONG data-index-in-node="95" data-path-to-node="4"&gt;HPE Switch&lt;/STRONG&gt; content pack, but the logs are not automatically normalizing into XDM fields.&lt;/P&gt;
&lt;P data-path-to-node="5"&gt;In our environment, when we query other datasets like &lt;STRONG data-index-in-node="54" data-path-to-node="5"&gt;Office 365, Zscaler, or AWS&lt;/STRONG&gt;, the logs are automatically parsed and normalized into &lt;CODE data-index-in-node="137" data-path-to-node="5"&gt;xdm.*&lt;/CODE&gt; fields upon querying. We are expecting the same behavior for &lt;CODE data-index-in-node="204" data-path-to-node="5"&gt;hpe_switch_raw&lt;/CODE&gt;, but it is currently showing only raw unparsed logs.&lt;/P&gt;
&lt;P data-path-to-node="6"&gt;Here are the details of our setup:&lt;/P&gt;
&lt;UL data-path-to-node="7"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="7,0,0"&gt;&lt;STRONG data-index-in-node="0" data-path-to-node="7,0,0"&gt;Ingestion Path:&lt;/STRONG&gt; Aruba Switch Syslog → Broker VM (UDP 514) → XSIAM&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="7,1,0"&gt;&lt;STRONG data-index-in-node="0" data-path-to-node="7,1,0"&gt;Syslog Target Settings:&lt;/STRONG&gt; &lt;CODE data-index-in-node="24" data-path-to-node="7,1,0"&gt;vendor = HPE&lt;/CODE&gt;, &lt;CODE data-index-in-node="38" data-path-to-node="7,1,0"&gt;product = Switch&lt;/CODE&gt;, Format: &lt;CODE data-index-in-node="64" data-path-to-node="7,1,0"&gt;auto-detect&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="7,2,0"&gt;&lt;STRONG data-index-in-node="0" data-path-to-node="7,2,0"&gt;Default Ingestion Rule Generated:&lt;/STRONG&gt; &lt;CODE data-index-in-node="34" data-path-to-node="7,2,0"&gt;[INGEST:vendor="HPE", product="Switch", target_dataset="hpe_switch_raw", no_hit=drop]&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="7,3,0"&gt;&lt;STRONG data-index-in-node="0" data-path-to-node="7,3,0"&gt;Issue:&lt;/STRONG&gt; The dataset &lt;CODE data-index-in-node="19" data-path-to-node="7,3,0"&gt;hpe_switch_raw&lt;/CODE&gt; is successfully created and logs are being ingested. However, when querying the dataset, only basic metadata fields appear (&lt;CODE data-index-in-node="158" data-path-to-node="7,3,0"&gt;_time&lt;/CODE&gt;, &lt;CODE data-index-in-node="165" data-path-to-node="7,3,0"&gt;_vendor&lt;/CODE&gt;, &lt;CODE data-index-in-node="174" data-path-to-node="7,3,0"&gt;_product&lt;/CODE&gt;, &lt;CODE data-index-in-node="184" data-path-to-node="7,3,0"&gt;_raw_log&lt;/CODE&gt;, &lt;CODE data-index-in-node="194" data-path-to-node="7,3,0"&gt;_broker_ip_address&lt;/CODE&gt;, etc.). The data normalization into &lt;CODE data-index-in-node="249" data-path-to-node="7,3,0"&gt;xdm.*&lt;/CODE&gt; fields is not happening automatically like it does for our other log sources.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-path-to-node="8"&gt;&lt;STRONG data-index-in-node="0" data-path-to-node="8"&gt;Sample Raw Logs:&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="code-block ng-tns-c1862742614-73 ng-animate-disabled ng-trigger ng-trigger-codeBlockRevealAnimation" data-ved="0CAAQhtANahgKEwjMsqKE6ZeWAxUAAAAAHQAAAAAQigE" data-hveid="0"&gt;
&lt;DIV class="formatted-code-block-internal-container ng-tns-c1862742614-73"&gt;
&lt;DIV class="animated-opacity ng-tns-c1862742614-73"&gt;
&lt;DIV class="code-block-decoration header-formatted gds-emphasized-body-m ng-tns-c1862742614-73 ng-star-inserted"&gt;&lt;SPAN class="ng-tns-c1862742614-73"&gt;Plaintext&lt;/SPAN&gt;
&lt;DIV class="buttons ng-tns-c1862742614-73 ng-star-inserted"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;PRE class="ng-tns-c1862742614-73"&gt;&lt;CODE class="code-container formatted ng-tns-c1862742614-73" role="text" data-test-id="code-content"&gt;&amp;lt;46&amp;gt;Jul 27 15:52:26 172.17.15.8 00435 ports: ST1-CMDR: port 1/44 is Blocked by STP
&amp;lt;46&amp;gt;Jul 27 15:52:32 172.17.156.8 00076 ports: ST1-CMDR: port 1/44 is now on-line
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-path-to-node="10"&gt;&lt;STRONG data-index-in-node="0" data-path-to-node="10"&gt;What We Observed:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL start="1" data-path-to-node="11"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="11,0,0"&gt;The HPE Switch Content Pack includes a Data Modeling Rule (DMR) with &lt;CODE data-index-in-node="69" data-path-to-node="11,0,0"&gt;regextract&lt;/CODE&gt; logic.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="11,1,0"&gt;When testing the &lt;CODE data-index-in-node="17" data-path-to-node="11,1,0"&gt;regextract&lt;/CODE&gt; logic directly in an XQL query, the fields extract correctly.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="11,2,0"&gt;However, out of the box, when we simply query &lt;CODE data-index-in-node="46" data-path-to-node="11,2,0"&gt;dataset = hpe_switch_raw&lt;/CODE&gt;, the logs remain unparsed in the &lt;CODE data-index-in-node="104" data-path-to-node="11,2,0"&gt;_raw_log&lt;/CODE&gt; field without default XDM normalization.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-path-to-node="12"&gt;&lt;STRONG data-index-in-node="0" data-path-to-node="12"&gt;Questions:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL start="1" data-path-to-node="13"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="13,0,0"&gt;Is the default Data Modeling Rule (DMR) sufficient to get parsed/normalized fields automatically when querying the dataset, or do we need to write a custom Ingestion Parsing Rule (PR) for HPE/Aruba switches?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="13,1,0"&gt;Could the leading Syslog Priority Tag (&lt;CODE data-index-in-node="39" data-path-to-node="13,1,0"&gt;&amp;lt;46&amp;gt;&lt;/CODE&gt;) in the raw log be breaking the Content Pack DMR regex matching?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="13,2,0"&gt;What is the best practice to get this dataset fully parsed and normalized out of the box like AWS, Zscaler, and Office 365?&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-path-to-node="14"&gt;Thanks in advance for your guidance!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2026 10:59:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/parsing-rule-and-data-model-rule/m-p/1261468#M457</guid>
      <dc:creator>Praveen0108</dc:creator>
      <dc:date>2026-08-11T10:59:48Z</dc:date>
    </item>
  </channel>
</rss>

