Azure XSIAM

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Azure XSIAM

L1 Bithead

How is on-boarding logs using Microsoft Azure integration different from using the Azure Event hub integration? 

https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-3.x-Documentation/Onboard-Micro... 
https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Documentation/Ingest-Logs-from-... 

Also any details on what specifically is the automation features that the Microsoft Azure integration provides would be helpful? Does this replace the need to deploy agents?

 

Cortex XSIAM Azure 

2 REPLIES 2

L5 Sessionator

Hello @bridgetlitt ,

 

Greetings for the day.

1. Key Differences Between Integration Methods

(Setup Method)

Microsoft Azure Integration (CSP Onboarding):
This method uses an automated onboarding wizard to streamline Azure environment setup within Cortex XSIAM. It typically involves running an ARM template or script (for example, onboard.sh) that automatically creates the required Azure resources, including Diagnostic Settings, Event Hubs, and permissions across subscriptions.

 

Azure Event Hub Integration:
This is a manual “pull” collector approach. You must first configure the Event Hub and Diagnostic Settings within the Azure Portal, then provide Cortex XSIAM with the required credentials, including:

  • Event Hub Connection String
  • Storage Account Connection String (used for checkpointing and partition management)
  • Consumer Group

Scope and Management

-The Microsoft Azure (CSP) integration is designed for large-scale log collection across entire tenants or multiple subscriptions. If audit logs are enabled during onboarding, the integration manages the underlying Event Hub resources automatically, often eliminating the need for a separate manual Event Hub connector.

 

-The Azure Event Hub integration is typically used for targeted, high-volume log sources (such as Entra ID Sign-in logs) or logs from specific services (for example, AKS or Intune) where organizations prefer direct ingestion into XSIAM without onboarding the entire Azure environment.


2. Automation Features of the Microsoft Azure Integration

The Microsoft Azure (CSP) integration provides several automation-focused capabilities:

  • Automated Log Routing: Automatically configures Azure Diagnostic Settings to stream logs (Activity Logs, Audit Logs, etc.) to the Event Hubs used by XSIAM.
  • Asset Discovery: Automatically scans monitored Azure accounts and populates the Asset Inventory, providing centralized visibility into cloud resources.
  • Continuous Monitoring: Once onboarding is completed, XSIAM continuously monitors onboarded Azure accounts for data and configuration changes.
  • Playbook Orchestration: XSIAM leverages built-in content packs and playbooks to automatically triage, investigate, and respond to threats identified from Azure telemetry.

3. Does It Replace the Need to Deploy Agents?

No. The Microsoft Azure integration does not replace the need to deploy Cortex XDR agents.

Cortex XSIAM uses a layered architecture in which the Cortex XDR agent functions as the primary endpoint sensor for deep visibility and prevention.

The roles are complementary:

  • Cloud Log Integrations: Provide management-plane and data-plane telemetry, such as user sign-ins, resource changes, and cloud activity logs.
  • Cortex XDR Agents: Provide host-level telemetry, including process execution, file activity, registry changes, and network connections within the operating system.

Co-existence Model:

For a complete security posture:

  • Deploy Cortex XDR agents on Azure virtual machines (IaaS workloads) to enable Endpoint Detection and Response (EDR) capabilities.
  • Use Azure integrations to ingest cloud-native telemetry and management logs.

Together, these components provide a more complete security narrative across cloud infrastructure and endpoint activity.

 

If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".

 

Thanks & Regards,
S. Subashkar Sekar

Thanks for the response. This is very helpful. So the log ingestion part is same as that with Azure event hub integration except that the azure integration provides you an automated way to create that event hub.

 

For automation I was looking for what was actually meant by this in the documentation "Automation: Use automation to pre-configure a list of integrations and associated commands to automate security issue responses. Commands can be utilized individually or as part of custom playbooks for issue remediation."  What are the commands and what is meant by to pre-configure a list of integrations? 

 

Also, i suppose some of the capabilities you mentioned are not there for foundational configuration. Do you have an exact list of features that is available for foundational configuration?

  • 183 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!