Procedures for Integrating SLS and Cortex XDR

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Procedures for Integrating SLS and Cortex XDR

Hello.
This is my first time using Cortex XDR and SLS. I understand the procedure for integrating PA and SLS, but I’m not quite sure how to integrate SLS and XDR. I haven’t been able to find any instructions on any website. Could someone please help me?

2 REPLIES 2

L5 Sessionator

Hello @D.Watanabe454116 ,

 

Greetings for the day.

 

 

Integrating Strata Logging Service (SLS) with Cortex XDR allows the XDR platform to ingest and correlate detection data from Palo Alto Networks products (like NGFW or Prisma Access) that are already logging to an existing SLS instance (formerly known as Cortex Data Lake or CDL).

 

Prerequisites:

Before beginning the integration, ensure the following requirements are met:

  • Licensing: You must have a Cortex XDR Pro per GB license enabled.
  • Permissions: You must hold Super User permissions for your Customer Support Portal (CSP) account.
  • Regional Alignment: The Cortex XDR tenant and the SLS/CDL instance must be provisioned in the exact same geographical region (e.g., both in US or both in EU). A region mismatch will prevent the SLS instance from being visible in the XDR console.

Integration Steps:

To configure the connection between SLS and Cortex XDR, follow these steps in the management console:

  1. Log in to your Cortex XDR Management Console.
  2. Navigate to:
    Settings → Configurations → Data Collection → Collection Integrations
    • Note: In some newer tenants migrated to Cloud Logging Collection, the path may be Data Collection → Data Sources instead.
  3. Locate the Strata Logging Service section and click Add Instance.
  4. Select Data Lake Instance.
  5. Select the existing Strata Logging Service instances you wish to connect to this tenant.
  6. Save the configuration.

Verification:

Once configured, you can verify the status of the integration:

  • Visual Confirmation: A green check mark will appear underneath the Strata Logging Service configuration once events begin to flow into the tenant.
  • Querying Data: You can use XQL Search to confirm data presence by querying the xdr_data dataset.
  • Firewall CLI: On the firewall side, you can use the following command to confirm the connection status to the logging service:
request logging-service-forwarding status
(Support and Assistance)
  • Technical Support (TAC): Assists with "break/fix" issues where an existing configuration is not working as expected.
  • Sales Engineer (SE) or Account Team: Contact for guidance on new implementations, architectural designs, or complex multi-tenant/multi-account configurations.
  • Professional Services: Recommended for in-depth setup assistance or creating specific parsing rules.

 

Important Note for New Tenants:

If you are using a new tenant, Cortex XDR now supports direct integration (via the Cloud Logging Collection Service or CLCS) where firewalls and Panorama send logs directly to Cortex XDR without requiring a separate manual SLS/CDL setup. This is often the default for new activations.

 

If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".

 

Thanks & Regards,
S. Subashkar Sekar

 

 

Hi, @susekar ,

 

Thank you for your comment.
I can't find the “Strata Logging Service” section under “Collection Integrations” in the XDR management console. Do you know why that might be?

 

Best Regards

  • 392 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!