- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-27-2024 03:19 AM
Hello,
I have linux logs which comes as:
[INGEST:vendor="unknown", product="unknown", target_dataset="unknown_unknown_raw", no_hit = drop]
It is collected under the dataset name called "unknown_unknown_raw". But I want to change its dataset name to something else. How can I do that?
02-27-2024 04:56 AM - edited 02-27-2024 04:57 AM
Then your best option is:
- Go to your Broker VM, edit the Syslog configuration, and then hardcode the vendor and product fields with the source IP of the logs. Take a look at this example in my lab:
- This will create a NEW dataset with the configured fields like this: vendor_product_raw
We have our doc here with more Parsing Rule info: https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Administrator-Guide/Create-Pars...
There is a webinar available here with some very useful basic concepts: https://live.paloaltonetworks.com/t5/cortex-xdr-webinars/cortex-customer-success-webinar-series-part...
02-27-2024 05:28 AM
02-27-2024 05:36 AM
@jmazzeo I understand, thank you. And, please, can you answer this:
As you know PaloAlto has recently changed their licenses for Cortex XDR. As I know before it was Data Lake license with TBs but now, it is GB/per day. How can I calculate how much GB I need to buy for fully take advantage of this. Is there any sizing method?
02-27-2024 04:38 AM
Hi @JahidAliyev, thanks for reaching us using the Live Community.
Are you using Broker VM Syslog to forward those logs to the console?
02-27-2024 04:42 AM
Hi @jmazzeo, yes, i am using Broker VM
02-27-2024 04:56 AM - edited 02-27-2024 04:57 AM
Then your best option is:
- Go to your Broker VM, edit the Syslog configuration, and then hardcode the vendor and product fields with the source IP of the logs. Take a look at this example in my lab:
- This will create a NEW dataset with the configured fields like this: vendor_product_raw
We have our doc here with more Parsing Rule info: https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Administrator-Guide/Create-Pars...
There is a webinar available here with some very useful basic concepts: https://live.paloaltonetworks.com/t5/cortex-xdr-webinars/cortex-customer-success-webinar-series-part...
02-27-2024 05:16 AM
@jmazzeo As I understand I cannot change it directly. I need to change it from syslog collector. What if I have many linux endpoints that each sends logs to Broker VM. Do I need to do this action manually? I mean source IP is different for each linux endpoint.
02-27-2024 05:28 AM
02-27-2024 05:36 AM
@jmazzeo I understand, thank you. And, please, can you answer this:
As you know PaloAlto has recently changed their licenses for Cortex XDR. As I know before it was Data Lake license with TBs but now, it is GB/per day. How can I calculate how much GB I need to buy for fully take advantage of this. Is there any sizing method?
02-27-2024 05:38 AM
Yes, there is a sizing method available. Please talk with your PANW Sales contact and they will help you with that.
If you found any of the previous replies as the answer to the inquiry, please mark it as the solution.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!