<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR Firewall configuration query. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-firewall-configuration-query/m-p/548221#M111948</link>
    <description>&lt;P&gt;Thank you for your support! We have one more query. Could you kindly confirm the log retention period for all the forwarded logs to the XDR cloud?&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jul 2023 08:57:28 GMT</pubDate>
    <dc:creator>Vinothkumar_SBA</dc:creator>
    <dc:date>2023-07-05T08:57:28Z</dc:date>
    <item>
      <title>Cortex XDR Firewall configuration query.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-firewall-configuration-query/m-p/547833#M111882</link>
      <description>&lt;P&gt;We have configured the Check Point firewall version (R81.10), but it is not supported for native log ingestion. However, we have checked the official Palo Alto documentation for this link: &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Ingest-Logs-from-a-Syslog-Receiver" target="_new" rel="nofollow noopener noreferrer"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Ingest-Logs...&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-It states that log ingestion and data require a Cortex XDR Pro per GB license.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-We have purchased a TB license.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-I will need to confirm whether it is possible to ingest CEF logs from Check Point software version R81.10.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 05:43:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-firewall-configuration-query/m-p/547833#M111882</guid>
      <dc:creator>Vinothkumar_SBA</dc:creator>
      <dc:date>2023-06-30T05:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Firewall configuration query.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-firewall-configuration-query/m-p/548197#M111945</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/243138"&gt;@Vinothkumar_SBA&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The short answer is - Yes, you can ingest Check Point logs to XDR with XDR Pro per TB license.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Palo Alto are making some changes to Cortex XDR licenses and "per TB" will be replaced with "per GB". The difference is that per TB was measuring the ingested data for a month, while the new license "per GB" will measure daily.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What this means is that you previously purchased license for the amount of TB you expect to ingest montly, from now on you will purchase license for the amount of GB you expect to ingest daily.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"per TB" should be automatically migrated to "per GB", but it will continue to serve exact same purpose. It looks like in some of the XDR documentation they have already replace the TB with GB.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This information should have already be provide to you over the email you are using for Palo Alto Customer Support Portal. If not you may want to reach to your sale engineer or account manager for more details.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2023 07:36:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-firewall-configuration-query/m-p/548197#M111945</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-07-05T07:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Firewall configuration query.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-firewall-configuration-query/m-p/548221#M111948</link>
      <description>&lt;P&gt;Thank you for your support! We have one more query. Could you kindly confirm the log retention period for all the forwarded logs to the XDR cloud?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2023 08:57:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-firewall-configuration-query/m-p/548221#M111948</guid>
      <dc:creator>Vinothkumar_SBA</dc:creator>
      <dc:date>2023-07-05T08:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Firewall configuration query.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-firewall-configuration-query/m-p/548246#M111955</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/243138"&gt;@Vinothkumar_SBA&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is no change for the retention after license migration from "per TB" to "per GB".&lt;/P&gt;
&lt;P&gt;As explained here - &lt;A href="https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-firewall-configuration-query/td-p/547833" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-firewall-configuration-query/td-p/547833&lt;/A&gt;&amp;nbsp; "per GB/TB" license are &lt;U&gt;ingestion only&lt;/U&gt;, meaning they don't effect retention periond.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Which means you should have (by default) 30days of hot retention for ingested data and 180 days of hot retention for alerts and incidents (created by XDR). If you need extend that you need to order license add-ons, details for which you can see in the link above.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2023 13:20:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cortex-xdr-firewall-configuration-query/m-p/548246#M111955</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-07-05T13:20:22Z</dc:date>
    </item>
  </channel>
</rss>

