02-13-2023 07:42 PM
Can anybody explain the storage method used by XDR for external data (and internal for that matter) better than the Beacon training and XDR admin guide. I have AWS S3 logs which I can see under Dataset management with the dataset name 'amazon_aws_raw' (imported using the Amazon S3 integration). I was under the impression these are stored in my data lake but when I access my data lake via the apps gateway I see nothing in it.
Does the XDR instance have its own Datalake that we cannot see from the apps portal?
Is the Datalake provided by the Pro per TB license the one shown in the apps portal?
In the apps portal I have a datalake. From the CSP under assets > cloud services I can see my XDR tenant is associated with my Datalake. Is this my Pro per TB datalake, or an additional datalake?
I have reviewed the architecture diagram in the documentation which appears to make sense until I try to find my logs using the explorer app and the datalake app.
Any additional information on the storage architecture for XDR would be very much appreciated.
03-01-2023 02:10 AM
As you can see from the description here - https://apps.paloaltonetworks.com/marketplace/explore Explorer is intended to allow you to search only the logs that are generated by the PAN FWs that are sending logs to your Datalake instance.
There are not separate or additional datalakes, but it just that Explorer doesn't have an option/it doesn't allow you to look at the other logs apart from PAN FW/Prisma Acess.
If you want to browser/search your AWS logs you need to use the XQL queries in XDR console and specifying the dataset you want to use.
03-01-2023 02:10 AM
As you can see from the description here - https://apps.paloaltonetworks.com/marketplace/explore Explorer is intended to allow you to search only the logs that are generated by the PAN FWs that are sending logs to your Datalake instance.
There are not separate or additional datalakes, but it just that Explorer doesn't have an option/it doesn't allow you to look at the other logs apart from PAN FW/Prisma Acess.
If you want to browser/search your AWS logs you need to use the XQL queries in XDR console and specifying the dataset you want to use.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!