Inquiry About Third-Party VPN Logs and Analytics Alerts in XSIAM

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Inquiry About Third-Party VPN Logs and Analytics Alerts in XSIAM

L1 Bithead

Hi All,

■Background
I would like to inquire about the Ivanti VPN logs ingested into XSIAM.
I have installed the data model rules from the content pack. However, I encountered the following issues:

Analytics Alerts: No Analytics alerts related to third-party VPNs have been generated.
Datasets: The logs are not displayed in the "vpn_logs" or "xdr_data" datasets either.

■Questions
I would appreciate it if you could clarify the following points:

1.Regarding the data sources for Analytics alerts:
・Are the data sources for third-party VPNs targeted by Analytics alerts fixed?
・If they are not fixed, are there any required schema conditions for the data model rules?

2.Regarding the "vpn_logs" dataset:
・Are the data sources for third-party VPNs targeted by the "vpn_logs" dataset fixed?
・If they are not fixed, are there any required schema conditions for the data model rules?

Cortex XSIAM  

1 REPLY 1

L1 Bithead

https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Analytics-Alert-Reference-by-da...

 

  • Requires one of the following data sources:
    • Palo Alto Networks Global Protect
      OR
    • Third-Party VPNs

It would be nice if they listed  which Third-Party VPNs are expected to be supported.

  • 337 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!