Cortex XDR Management Audit Logs CEF Format #192
bharathkumarnec
started this conversation in
General
Replies: 1 comment 2 replies
-
Hi @bharathkumarnec, thanks for your question. The Splunk App/Add-on supports Cortex XDR data using the XDR API only. It doesn't support syslog and there are currently no plans to add syslog. Here are the directions for setting it up: https://splunk.paloaltonetworks.com/cortex-xdr.html The App/Add-on will not support logs from any product in CEF format, because CEF requires extensive regex parsing to do field extraction in Splunk, and we try to offer more optimized ways to parse logs (CSV, JSON, etc). Hope that helps! |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hi Team,
We are getting logs from Cortex XDR with CEF format using syslog and seems this app is not yet supporting this format, is it correct or am i missing something?
https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/logs/cortex-xdr-log-notification-formats/management-audit-log-notification-format.html
Regards,
BK
Beta Was this translation helpful? Give feedback.
All reactions