cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who Me Too'd this topic

Cortex XDR logs fed into Splunk ES

Hello all,

Is there a repository of Splunk searches or queries based on Palo Alto Cortex XDR logs that I can be referred to? I am looking to create correlation searches in Splunk that will help filter through the alerts/logs received.

Is that something that everyone is building out custom? Please point me in the direction on where I can find more information around best practices for this use case.

Who Me Too'd this topic