- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-03-2026 03:57 AM
How is on-boarding logs using Microsoft Azure integration different from using the Azure Event hub integration?
https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-3.x-Documentation/Onboard-Micro...
https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Documentation/Ingest-Logs-from-...
Also any details on what specifically is the automation features that the Microsoft Azure integration provides would be helpful? Does this replace the need to deploy agents?
06-03-2026 12:52 PM
Hello @bridgetlitt ,
Greetings for the day.
Microsoft Azure Integration (CSP Onboarding):
This method uses an automated onboarding wizard to streamline Azure environment setup within Cortex XSIAM. It typically involves running an ARM template or script (for example, onboard.sh) that automatically creates the required Azure resources, including Diagnostic Settings, Event Hubs, and permissions across subscriptions.
Azure Event Hub Integration:
This is a manual “pull” collector approach. You must first configure the Event Hub and Diagnostic Settings within the Azure Portal, then provide Cortex XSIAM with the required credentials, including:
-The Microsoft Azure (CSP) integration is designed for large-scale log collection across entire tenants or multiple subscriptions. If audit logs are enabled during onboarding, the integration manages the underlying Event Hub resources automatically, often eliminating the need for a separate manual Event Hub connector.
-The Azure Event Hub integration is typically used for targeted, high-volume log sources (such as Entra ID Sign-in logs) or logs from specific services (for example, AKS or Intune) where organizations prefer direct ingestion into XSIAM without onboarding the entire Azure environment.
The Microsoft Azure (CSP) integration provides several automation-focused capabilities:
No. The Microsoft Azure integration does not replace the need to deploy Cortex XDR agents.
Cortex XSIAM uses a layered architecture in which the Cortex XDR agent functions as the primary endpoint sensor for deep visibility and prevention.
The roles are complementary:
For a complete security posture:
Together, these components provide a more complete security narrative across cloud infrastructure and endpoint activity.
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".
Thanks & Regards,
S. Subashkar Sekar
06-04-2026 01:30 AM
Thanks for the response. This is very helpful. So the log ingestion part is same as that with Azure event hub integration except that the azure integration provides you an automated way to create that event hub.
For automation I was looking for what was actually meant by this in the documentation "Automation: Use automation to pre-configure a list of integrations and associated commands to automate security issue responses. Commands can be utilized individually or as part of custom playbooks for issue remediation." What are the commands and what is meant by to pre-configure a list of integrations?
Also, i suppose some of the capabilities you mentioned are not there for foundational configuration. Do you have an exact list of features that is available for foundational configuration?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

