cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who rated this post

L3 Networker

Syslog is not supported in the PAN_TA for Cortex XDR so there is no parsing of the fields. 

Cortex XDR · GitBook (paloaltonetworks.com)

Cortex XDR incidents are cloud-hosted so logs are retrieved by Splunk using the Cortex XDR API (syslog not supported).

 

The method that is supported is with API but it only pulls the INC# and a link to the XDR console which doesn't provide value for correlation. This use to work using the TRAPS syslog parsing but that was removed in 7.X and forward. 

Who rated this post