- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-06-2023 04:42 AM - edited 09-12-2023 11:25 PM
We are currently integrating the Cortex XDR incident logs with the Splunk tool. Currently, the incident logs are visible in the Splunk tool, but certain essential fields required for conducting an XDR log investigation are not available in the existing logs. These necessary fields include File Name, File Path, File Hash, Command Line, Grand Parent Name, Parent Name, Grand Parent Command Line, Parent Command Line, IOC value, and a few others.
09-12-2023 12:51 AM
Thank you for writing to live community!
Would suggest and recommend before posting details/query could you remove/redact the specifics/info related to your org. Regarding this request could you confirm about ingestion of Incidents to Splunk are you doing using api or you are referring to Notifications configured for Log Alert Type as Alerts using syslog server.
Hope this helps!
Please mark the response as "Accept as Solution" if it answers your query.
09-12-2023 12:51 AM
Thank you for writing to live community!
Would suggest and recommend before posting details/query could you remove/redact the specifics/info related to your org. Regarding this request could you confirm about ingestion of Incidents to Splunk are you doing using api or you are referring to Notifications configured for Log Alert Type as Alerts using syslog server.
Hope this helps!
Please mark the response as "Accept as Solution" if it answers your query.
09-13-2023 10:34 PM
Hi@PiyushKohli,
We have configure the API integration.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!