Box ↗
You can configure collecting Box logs and data using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connectors:
| Collection Method | Description |
|---|---|
| Standard data source overview | Forward different types of data from Box enterprise accounts to Cortex XSIAM using the Box data source. |
| Link to standard data source instructions | <p>The following types of data can be ingested from Dropbox:</p><ul><li><p>Events and security alerts</p><ul><li>Events (admin_logs)</li><li>Box Shield Alerts</li></ul></li><li><p>Directory and metadata</p><ul><li>Users</li><li>Groups</li></ul></li></ul><p>For more information, see Ingest logs and data from Box.</p> |
| Links to content pack integration details (onboarded prior to July 26, 2026) | <p>The Box content pack contains classifiers, issue fields and types, and parsing and modeling rules to normalize Box data in Cortex XSIAM. It also includes the following integrations:</p><ul><li>Box Event Collector: Use this integration to collect events from Box's logs. It includes a command to get Box events.</li><li>Box V2: Use this integration to manage Box users. It includes commands to search Box content and manage file folders and share links.</li></ul> |
| Link to connectors | <ul><li>Box Automation and Collection (onboarded after July 26, 2026)</li><li>Box</li></ul> |