XDR_DATA logs ingestion to splunk
I am thinking of a way to bring in xdr_data dataset logs which we see in xdr query builder to splunk.
As of now i am ingesting the alert and incident data from cortex xdr into splunk.
Can anyone suggest, how i can achieve this?