Hello @Vinothkumar_SBA ,
Thanks for reaching out on LiveCommunity!
One of the way by which you can ingest logs from any third party firewall is through syslog collector applet on broker vm. Syslog collector allow you to ingest logs in any of these logs format CEF, LEEF, CISCO, CORELIGHT, or RAW. Please follow below guide to activate and config syslog collector to ingest firewall logs.
https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Activate-the-Syslog-Collector
One more possible solution is through Cloudwatch integration. XDR provide direct integration to Cloudwatch. Hence if you can forward WAF logs to Cloudwatch, those logs can be ingested to XDR. Below is the documentation for Cloudwatch integration.
https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Ingest-Logs-from-Amazon-CloudWatch
... View more