Dropbox

You can configure collecting Dropbox logs and data using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):

Collection Method Description
Standard data source overview Forward different types of data from Dropbox Business accounts to Cortex XSIAM using the Dropbox data source.
Link to standard data source instructions <p>The following types of data can be ingested from Dropbox:</p><ul><li><p>Log collection</p><ul><li>Events</li></ul></li><li><p>Directory and metadata</p><ul><li>Member Devices</li><li>Users</li><li>Groups</li></ul></li></ul><p>For more information, see Ingest logs and data from Dropbox.</p>
Links to content pack/ integration details (onboarded prior to July 26, 2026) <p>The Dropbox content pack fetches and collects security events from Dropbox logs. It includes Correlation Rules, Modeling Rules, Parsing Rules, a Playbook, and a Cortex XSIAM Dashboard. It also includes the following integration:</p><ul><li>Dropbox Event Collector: Use this integration to collect events from Dropbox logs. It contains commands such as dropbox-auth-start to initiate the authorization process, dropbox-auth-complete to finish authorization, dropbox-auth-test to check connectivity, dropbox-auth-reset to reset authentication, and dropbox-get-events to retrieve events.</li></ul>
Link to connector (onboarded after July 26, 2026) Dropbox