<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Exporting events from Cortex XDR in Strata Logging Service Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/strata-logging-service/exporting-events-from-cortex-xdr/m-p/563367#M12</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I have been doing some searching on if I can get XDR endpoint logs like processes and etc into a third party SIEM.&lt;BR /&gt;&lt;BR /&gt;Based on the XDR API there is no way to export events (You can technically run XQL queries using the API but this would get logged on XDR)&lt;BR /&gt;&lt;BR /&gt;It also looks like you cannot actually forward XDR data from the data lake to a syslog server and then to your SIEM.&lt;BR /&gt;&lt;BR /&gt;So if I am not wrong there is no way to export endpoint events from XDR to a third party SIEM.&lt;BR /&gt;&lt;BR /&gt;Can I get a confirmation on this and that I am not missing anything?&lt;BR /&gt;&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Thu, 18 Apr 2024 18:36:51 GMT</pubDate>
    <dc:creator>AvesterFahimipour</dc:creator>
    <dc:date>2024-04-18T18:36:51Z</dc:date>
    <item>
      <title>Exporting events from Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/strata-logging-service/exporting-events-from-cortex-xdr/m-p/563367#M12</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I have been doing some searching on if I can get XDR endpoint logs like processes and etc into a third party SIEM.&lt;BR /&gt;&lt;BR /&gt;Based on the XDR API there is no way to export events (You can technically run XQL queries using the API but this would get logged on XDR)&lt;BR /&gt;&lt;BR /&gt;It also looks like you cannot actually forward XDR data from the data lake to a syslog server and then to your SIEM.&lt;BR /&gt;&lt;BR /&gt;So if I am not wrong there is no way to export endpoint events from XDR to a third party SIEM.&lt;BR /&gt;&lt;BR /&gt;Can I get a confirmation on this and that I am not missing anything?&lt;BR /&gt;&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 18:36:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-logging-service/exporting-events-from-cortex-xdr/m-p/563367#M12</guid>
      <dc:creator>AvesterFahimipour</dc:creator>
      <dc:date>2024-04-18T18:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: Exporting events from Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/strata-logging-service/exporting-events-from-cortex-xdr/m-p/563375#M13</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/325593"&gt;@AvesterFahimipour&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cortex XDR agent based logs are aggregated and stored in XDR data layer itself. Infact with that being said, we are anyways deprecating the concept of different data lakes for third party source data and all of the logs will be streamed by XDR.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Coming back to the use case of attempting forwarding of raw events from Cortex XDR, inorder to achieve this action, customers need to have Cortex XDR Event forwarding license. This license comes in two parts:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;EP Forwarding: For Endpoint data collected by Cortex XDR agents&lt;/LI&gt;
&lt;LI&gt;GB forwarding: For third party data.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;The Event Forwarding license allows you to forward data into available GCP buckets where your data is stored for 14 days. The data is compressed and saved as a line-delimited JSON gzip file.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more details you can review here: &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-Event-Forwarding" target="_blank" rel="noopener"&gt;Manage Event Forwarding&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Once, you have the license, the event forwarding option is listed under Data Management on the Configuration page of Cortex XDR.  &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-10-27 at 9.35.20 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54718i02FB49D351BD4318/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2023-10-27 at 9.35.20 PM.png" alt="Screenshot 2023-10-27 at 9.35.20 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps! Please mark the response as "Accept as Solution" if it answers your query&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 13:37:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-logging-service/exporting-events-from-cortex-xdr/m-p/563375#M13</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-10-27T13:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: Exporting events from Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/strata-logging-service/exporting-events-from-cortex-xdr/m-p/563511#M14</link>
      <description>&lt;P&gt;One more question:&lt;BR /&gt;How do we get the event forwarding license, I cannot find it anywhere.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 11:50:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-logging-service/exporting-events-from-cortex-xdr/m-p/563511#M14</guid>
      <dc:creator>AvesterFahimipour</dc:creator>
      <dc:date>2023-10-30T11:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: Exporting events from Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/strata-logging-service/exporting-events-from-cortex-xdr/m-p/563513#M15</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/325593"&gt;@AvesterFahimipour&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please check your license page if you have already procured it. The license window should refer to an entitlement as shown in the screenshot below for Endpoint agent event forwarding.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If not, you might want to reach out to your sales engineer or the local accounts team for procurement.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-10-30 at 7.53.07 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54736iFC43FABF027441F5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2023-10-30 at 7.53.07 PM.png" alt="Screenshot 2023-10-30 at 7.53.07 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 11:56:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-logging-service/exporting-events-from-cortex-xdr/m-p/563513#M15</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-10-30T11:56:15Z</dc:date>
    </item>
  </channel>
</rss>

