- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-06-2022 01:33 PM
Hello!
Has anyone started ingesting Duo admin or authentication logs into Cortex XDR?
Duo provides a log sync utility but it doesn't support an API key like the HTTP Custom Collector would require and it doesn't write logs to disk (design decision) so the XDR filebeat collector can't pick them up. I'm hoping there's an easier way than Duo log sync > some intermediate collector > Cortex XDR Custom Collector.
Thanks for any ideas!
06-06-2022 02:54 PM
Hi Mgreer,
Cortex XDR does not natively support ingesting Duo admin/auth logs, however, the Duo log sync utility does support sending via CEF. You can deploy the Broker VM and enable the Syslog Collector applet (https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/external-data-ingestion/add...) and configure to receive CEF logs. Cortex XDR will automatically create a data set for you and you can then search logs, as well as create BIOCs, IOCs, and correlation rules.
06-06-2022 02:54 PM
Hi Mgreer,
Cortex XDR does not natively support ingesting Duo admin/auth logs, however, the Duo log sync utility does support sending via CEF. You can deploy the Broker VM and enable the Syslog Collector applet (https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/external-data-ingestion/add...) and configure to receive CEF logs. Cortex XDR will automatically create a data set for you and you can then search logs, as well as create BIOCs, IOCs, and correlation rules.
06-06-2022 04:43 PM
You are correct, CEF is an option but there seems to be a significant difference between the CEF and JSON data:
I can start with CEF though and go from there. Maybe Duo is on the roadmap for a native integration.
Thanks!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!