Dropbox

You can configure collecting Dropbox logs and data using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):

| Collection Method | Description |
| ----------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Standard data source overview | Forward different types of data from Dropbox Business accounts to Cortex XSIAM using the Dropbox data source. |
| Link to standard data source instructions | <p>The following types of data can be ingested from Dropbox:</p><ul><li><p>Log collection</p><ul><li>Events</li></ul></li><li><p>Directory and metadata</p><ul><li>Member Devices</li><li>Users</li><li>Groups</li></ul></li></ul><p>For more information, see <a href="dropbox/ingest-logs-and-data-from-dropbox">Ingest logs and data from Dropbox</a>.</p> |
| Links to content pack/ integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/Dropbox/">Dropbox</a> content pack fetches and collects security events from Dropbox logs. It includes Correlation Rules, Modeling Rules, Parsing Rules, a Playbook, and a Cortex XSIAM Dashboard. It also includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/dropbox-events-collector">Dropbox Event Collector</a>: Use this integration to collect events from Dropbox logs. It contains commands such as <strong><code>dropbox-auth-start</code></strong> to initiate the authorization process, <strong><code>dropbox-auth-complete</code></strong> to finish authorization, <strong><code>dropbox-auth-test</code></strong> to check connectivity, <strong><code>dropbox-auth-reset</code></strong> to reset authentication, and <strong><code>dropbox-get-events</code></strong> to retrieve events.</li></ul> |
| Link to connector (onboarded after July 26, 2026) | [Dropbox](dropbox/dropbox) |

Sub-topics