Duo admin/auth logs in Cortex XDR

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Duo admin/auth logs in Cortex XDR

L0 Member

Hello!

 

Has anyone started ingesting Duo admin or authentication logs into Cortex XDR?

Duo provides a log sync utility but it doesn't support an API key like the HTTP Custom Collector would require and it doesn't write logs to disk (design decision) so the XDR filebeat collector can't pick them up.  I'm hoping there's an easier way than Duo log sync > some intermediate collector > Cortex XDR Custom Collector.

 

Thanks for any ideas!

1 ACCEPTED SOLUTION

Accepted Solutions

L3 Networker

Hi Mgreer,

 

Cortex XDR does not natively support ingesting Duo admin/auth logs, however, the Duo log sync utility does support sending via CEF.  You can deploy the Broker VM and enable the Syslog Collector applet (https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/external-data-ingestion/add...) and configure to receive CEF logs.  Cortex XDR will automatically create a data set for you and you can then search logs, as well as create BIOCs, IOCs, and correlation rules. 

View solution in original post

2 REPLIES 2

L3 Networker

Hi Mgreer,

 

Cortex XDR does not natively support ingesting Duo admin/auth logs, however, the Duo log sync utility does support sending via CEF.  You can deploy the Broker VM and enable the Syslog Collector applet (https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/external-data-ingestion/add...) and configure to receive CEF logs.  Cortex XDR will automatically create a data set for you and you can then search logs, as well as create BIOCs, IOCs, and correlation rules. 

You are correct, CEF is an option but there seems to be a significant difference between the CEF and JSON data:

mgreer_0-1654558920340.png

I can start with CEF though and go from there.  Maybe Duo is on the roadmap for a native integration.
Thanks!

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!