Workday ↗
You can configure collecting Workday report data using a standard collector, content pack integration (onboarded prior to July 26, 2026), or connector:
| Collection Method | Description |
|---|---|
| Standard collector overview | Forward Workday report data to Cortex XSIAM using the Workday data source. |
| Link to standard collector instructions | Ingest report data from Workday |
| Links to content pack/integration details (onboarded prior to July 26, 2026) | <p>The Workday content pack provides solutions for financial management, human resources, and planning, specifically supporting the collection and modeling of user activity audit logs and sign-on events. It contains classifiers, modeling rules, and parsing rules, as well as the following integrations:</p><ul><li>Workday Event Collector: Use this integration containing the workday-get-activity-logging command to get activity logs from Workday. It requires the Workday Parsing Rule and Workday Modeling Rule for parsing and modeling ingested data.</li><li>Workday: Use this integration containing the workday-list-workers command to return information for specific workers.</li><li>Workday IAM: Use this integration containing the workday-iam-get-full-report command to return report entries from Workday. It is part of the part of the IAM premium pack.</li><li>Workday Sign On Event Collector: Use this integration containing the workday-get-sign-on-events command to get sign-on logs from Workday. This command is used for developing/debugging and is to be used with caution, as it can create events, leading to events duplication and exceeding the API request limitation.</li></ul> |
| Link to connector | <ul><li>Workday Automation and Collection (onboarded after July 26, 2026)</li><li>Workday</li></ul> |