<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XDR data lake and related questions in Strata Logging Service Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/strata-logging-service/xdr-data-lake-and-related-questions/m-p/583352#M37</link>
    <description>&lt;P&gt;Hello People , anyone please ?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Apr 2024 10:16:06 GMT</pubDate>
    <dc:creator>FWPalolearner</dc:creator>
    <dc:date>2024-04-11T10:16:06Z</dc:date>
    <item>
      <title>XDR data lake and related questions</title>
      <link>https://live.paloaltonetworks.com/t5/strata-logging-service/xdr-data-lake-and-related-questions/m-p/583271#M36</link>
      <description>&lt;P&gt;Hello people ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have started working on PANW XDR&amp;nbsp; study and currently i am in initial stages on my study .&lt;/P&gt;
&lt;P&gt;1)Is PANW XDR uses its native inbuild data lake ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am confused with Architecture diagram which says Data lake&amp;nbsp; and Data layer . Are these two different things ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) I consider Datalake as big pool data ( flat or any other form) where all the PANW products ( firewalls /SASE/Prisma) ingest the logs .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am i right in my understanding .?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3)Another point is about 3rd Party external integrations ; can Cortex XDR ingest logs from any vendor like fortigate FW , Cisco router, Juniper switch , Crowdstrike edr , Armis . ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4) If answer to question 3 is yes , can XDR also run response actions on these 3rd parties ? like blocking an IP on fortigate or isolating a machine having crowdstrike antivirus disabled ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If Cortex XDR can ingest 3rd party data in native datalake , can we consider Cortex XDR as Open XDR ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;5) What is the difference between XDR and XSOAR because XDR can also provide a response action . Is the response limited or XDR has limited number of playbooks ? I studied that XSOAR is for more mature environments (SOCs) . so i am confused why customer buy XSOAR if XDR is giving all the options .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;6) About Cortex data lake , can cortex data lake ingest logs from fortigate , etc ? or cortex data lake is only for PANW products ?&amp;nbsp; at least this is what documentation says .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 18:34:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-logging-service/xdr-data-lake-and-related-questions/m-p/583271#M36</guid>
      <dc:creator>FWPalolearner</dc:creator>
      <dc:date>2024-04-18T18:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: XDR data lake and related questions</title>
      <link>https://live.paloaltonetworks.com/t5/strata-logging-service/xdr-data-lake-and-related-questions/m-p/583352#M37</link>
      <description>&lt;P&gt;Hello People , anyone please ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 10:16:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-logging-service/xdr-data-lake-and-related-questions/m-p/583352#M37</guid>
      <dc:creator>FWPalolearner</dc:creator>
      <dc:date>2024-04-11T10:16:06Z</dc:date>
    </item>
  </channel>
</rss>

