- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-13-2026 06:11 AM
04-13-2026 06:47 AM
Hello @Noshutdown ,
Greetings for the day.
The Cortex XDR for QRadar extension (Version 1.2.0) and standard syslog configuration allow QRadar to receive alerts and audit logs directly from the Cortex XDR tenant. However, standard syslog integration is limited in scope and does not support forwarding raw endpoint telemetry or full EDR data.
To achieve your goal of visibility in QRadar, you must choose the integration method based on the data type required:
The "Cortex XDR for QRadar" extension is listed on the IBM X-Force App Exchange, but the standard Technical Assistance Center (TAC) does not maintain the versioning details or the installer itself.
If you are running Cortex XDR 5.0 or newer, be aware of a significant architectural change regarding syslog:
To configure standard direct alert forwarding:
Settings → Configurations → Integrations → External ApplicationsSettings → Configurations → Notifications → Notification Forwarding
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".
Thanks & Regards,
S. Subashkar Sekar
04-17-2026 01:39 PM
Hi,
in case of Cortex XDR cloud and QRadar inside private network such forward hard to be done.
using Universal Cloud REST API protocol
here the workflow files
https://github.com/iceMBD/Workflow-Palo-Alto-Cortex-XDR-Integration-for-IBM-QRadar/tree/main
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

