- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-09-2022 12:42 PM - edited 06-09-2022 12:47 PM
Hi CraigV123,
With Cortex XDR Prevent, only the XDR Agent information can be ingested into XDR console, an XDR Pro license allows you to ingest alerts from 3rd party sources (including NGFW) and a Pro per TB license allows you to ingest the raw logs. Please refer to this doc page with detailed information on capabilities per license type (https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/cortex-xdr-overview/cortex-...).
Correction: You can use the AD integration feature to bring in data from AD for alerts and incidents. It's the Identity Analytics that you won't be able to utilize. Check out https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/get-started-with-cortex-xdr... for information on configuring this.