Yes. totally correct. Panw firewall can able to send logs directly to CDL. for any other type of logs, you are able use BrokerVM , XDR collector, XDR API and FileBeat. if log type does not known by XDR, You need to write your parser rules on XDR management console and last things, logs will be searchable by using XQL and will be ingested XDR log rotation date is 30 days. You don't need to concern if you exceed 1TB. This is SAAS service. Please check you average daily log size from XDR Management console > Configurations > Dataset management. Filter out "dataset name = xdr_data" if your license is not enough for keeping 30days xdr data, you may choose to increase your license. But sizing calculator is pretty accurate.
... View more