Dropbox ↗
You can configure collecting Dropbox logs and data using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):
| Collection Method | Description |
|---|---|
| Standard data source overview | Forward different types of data from Dropbox Business accounts to Cortex XSIAM using the Dropbox data source. |
| Link to standard data source instructions | <p>The following types of data can be ingested from Dropbox:</p><ul><li><p>Log collection</p><ul><li>Events</li></ul></li><li><p>Directory and metadata</p><ul><li>Member Devices</li><li>Users</li><li>Groups</li></ul></li></ul><p>For more information, see Ingest logs and data from Dropbox.</p> |
| Links to content pack/ integration details (onboarded prior to July 26, 2026) | <p>The Dropbox content pack fetches and collects security events from Dropbox logs. It includes Correlation Rules, Modeling Rules, Parsing Rules, a Playbook, and a Cortex XSIAM Dashboard. It also includes the following integration:</p><ul><li>Dropbox Event Collector: Use this integration to collect events from Dropbox logs. It contains commands such as dropbox-auth-start to initiate the authorization process, dropbox-auth-complete to finish authorization, dropbox-auth-test to check connectivity, dropbox-auth-reset to reset authentication, and dropbox-get-events to retrieve events.</li></ul> |
| Link to connector (onboarded after July 26, 2026) | Dropbox |