You can configure collecting PingOne authentication logs and data using a standard collector, content pack integration (onboarded prior to July 26, 2026), or connector:
| PingOne vendor | Description |
| --------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Standard collector overview | Forward authentication logs and data to Cortex XSIAM from PingOne for Enterprise using the PingOne data source. |
| Link to standard collector instructions | [Ingest authentication logs and data from PingOne](pingone/ingest-authentication-logs-and-data-from-pingone) |
| Link to content pack/integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/PingIdentity">PingIdentity</a> content pack provides capabilities to utilize PingOne's cloud identity and access management services for various triggering events. It includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/ping-one">PingOne (Partner Contribution)</a>: Use this integration to integrate with the PingOne Management API. It includes commands to unlock, create, delete, and update users.</li></ul> |
| Link to connector | [Ping Identity](pingone/ping-identity) |