Documentation — August 08, 2026
27 files changed, 138 insertions, 190 deletions — view the commit on the mirror.
Cortex Network Scanner is now supported for FedRAMP; Finland added to the regional IP allowlists
- Cortex Network Scanner flipped from not supported to supported for FedRAMP customers, in both places the page says so.
- A Finland (FI) region was added to four allowlist tables — engine outbound, inbound sources, regional egress and the syslog receiver — so firewall rules need updating.
- Prisma Access Browser gained a parent page and its ingestion topic moved one level deeper, taking the XSIAM book from 2,271 to 2,272 pages.
- Several connector descriptions that still said Cortex XSOAR now say Cortex XSIAM, and two links that pointed at a
file:///path or an opaque portal id were made relative. - The rest is markup: allowlist tables re-emitted as raw HTML, notes converted to GitBook hint blocks, and console names bolded.
Highlights
-
Cortex Network Scanner is now supported for FedRAMP customers
Both occurrences of "is not supported" became "is supported". A reversal, not a clarification.
-
A Finland (FI) region was added across four IP allowlist tables
New addresses appear for engine outbound, inbound sources, regional egress and syslog forwarding; the Broker VM column on the regional egress row was left blank and the inbound page labels the region "Finland (F)".
-
The Prisma Access Browser ingestion page moved under a new parent
A near-empty Prisma Access Browser page was added and the ingestion topic relocated beneath it unchanged, so the old URL breaks.
-
Policy Audit Scan added Debian and Ubuntu benchmarks
The supported list grew from the two CIS Windows benchmarks to also cover Debian and Ubuntu.
-
Two references were repointed at pages a reader can reach
The API security link was a local `file:///` path and the Defender for Endpoint prerequisite pointed at an opaque docs-cortex resource id; both are now relative portal paths.
-
The Azure Event Hub procedure lost its step numbering
Reflowing the diagnostic-settings section left lettered steps "c." and "d." inside a numbered list and renumbered the final Cortex XSIAM step from 6 to 4.
Changes
27 files listed, 15 written up and shaded below.
-
▸ ▾ README modified +1 −1
READMEGenerated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Navigation manifest (xsiam) modified +11 −4
.meta/xsiamThe book's page tree and ordering — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Resources required to enable access to XDR collectors modified +10 −10
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/xdr-collectors/resources-required-to-enable-access-to-xdr-collectorsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -12,26 +12,26 @@ Refer to the following tables for the FQDNs, IP addresses, ports, and App-ID covFor IP address ranges in GCP, refer to the following tables for IP address coverage for your deployment.For IP address ranges in GCP, refer to the following tables for IP address coverage for your deployment.• https://www.gstatic.com/ipranges/goog.json: Refer to this list to look up and allow access to the IP address ranges subnets.• https://www.gstatic.com/ipranges/goog.json: Refer to this list to look up and allow access to the IP address ranges subnets.• https://www.gstatic.com/ipranges/cloud.json: Refer to this list to look up and allow access to the IP address ranges associated with your region.• https://www.gstatic.com/ipranges/cloud.json: Refer to this list to look up and allow access to the IP address ranges associated with your region.The following table shows the required resources by region.The following table shows the required resources by region.FQDN│IP addresses and port│App-ID coverageFQDN│IP addresses and port│App-ID coverage| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------- || -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------- |<xsiam-tenant>.xdr.<region>.paloaltonetworks.comUsed to connect to the Cortex XSIAM management console.│IP address by region:- US (United States): 35.244.250.18
- EU (Europe): 35.227.237.180
- CA (Canada): 34.120.31.199
- UK (United Kingdom): 34.120.87.77
- JP (Japan): 35.241.28.254
- SG (Singapore): 34.117.211.129
- AU (Australia): 34.120.229.65
- DE (Germany): 34.98.68.183
- IN (India): 35.186.207.80
- CH (Switzerland): 34.111.6.153
- PL (Poland): 34.117.240.208
- TW (Taiwan): 34.160.28.41
- QT (Qatar): 35.190.0.180
- FA (France): 34.111.134.57
- IL (Israel): 34.111.129.144
- SA (Saudi Arabia): 35.244.157.127
- ID (Indonesia): 34.111.58.152
- ES (Spain): 34.111.188.248
- IT (Italy): 34.8.224.70
- KR (South Korea): 34.54.5.247
- ZA (South Africa): 34.149.165.12
Port: 443
│cortex-xdr<xsiam-tenant>.xdr.<region>.paloaltonetworks.comUsed to connect to the Cortex XSIAM management console.│IP address by region:- US (United States): 35.244.250.18
- EU (Europe): 35.227.237.180
- CA (Canada): 34.120.31.199
- UK (United Kingdom): 34.120.87.77
- JP (Japan): 35.241.28.254
- SG (Singapore): 34.117.211.129
- AU (Australia): 34.120.229.65
- DE (Germany): 34.98.68.183
- IN (India): 35.186.207.80
- CH (Switzerland): 34.111.6.153
- PL (Poland): 34.117.240.208
- TW (Taiwan): 34.160.28.41
- QT (Qatar): 35.190.0.180
- FA (France): 34.111.134.57
- IL (Israel): 34.111.129.144
- SA (Saudi Arabia): 35.244.157.127
- ID (Indonesia): 34.111.58.152
- ES (Spain): 34.111.188.248
- IT (Italy): 34.8.224.70
- KR (South Korea): 34.54.5.247
- ZA (South Africa): 34.149.165.12
- FI (Finland): 34.160.63.63
Port: 443
│cortex-xdrdistributions.traps.paloaltonetworks.comUsed for the first request in registration flow where the agent passes the distribution id and obtains thech-<xsiam-tenant>.traps.paloaltonetworks.comof its tenant.│- IP address: 35.223.6.69
- Port: 443
traps-management-servicedistributions.traps.paloaltonetworks.comUsed for the first request in registration flow where the agent passes the distribution id and obtains thech-<xsiam-tenant>.traps.paloaltonetworks.comof its tenant.│- IP address: 35.223.6.69
- Port: 443
traps-management-servicepanw-xdr-installers-prod-us.storage.googleapis.comUsed to download installers for upgrade actions from the server.This storage bucket is used for all regions.│- IP ranges in GCP
- Port: 443
cortex-xdrpanw-xdr-installers-prod-us.storage.googleapis.comUsed to download installers for upgrade actions from the server.This storage bucket is used for all regions.│- IP ranges in GCP
- Port: 443
cortex-xdrglobal-content-profiles-policy.storage.googleapis.comUsed to download content updates.│- IP ranges in GCP
- Port: 443
cortex-xdrglobal-content-profiles-policy.storage.googleapis.comUsed to download content updates.│- IP ranges in GCP
- Port: 443
cortex-xdrch-<xsiam-tenant>.traps.paloaltonetworks.comUsed for all other requests between the agent and its tenant server including heartbeat, uploads, action results, and scan reports.│IP address by region:- US (United States): 34.98.77.231
- EU (Europe): 34.102.140.103
- CA (Canada): 34.96.120.25
- UK (United Kingdom): 35.244.133.254
- JP (Japan): 34.95.66.187
- SG (Singapore): 34.120.142.18
- AU (Australia): 34.102.237.151
- DE (Germany): 34.107.161.143
- IN (India): 34.120.213.188
- CH (Switzerland): 34.149.180.250
- PL (Poland): 35.190.13.237
- TW (Taiwan): 34.149.248.76
- QT (Qatar): 34.107.129.254
- FA (France): 34.36.155.211
- IL (Israel): 34.128.157.130
- SA (Saudi Arabia): 34.107.213.85
- ID (Indonesia): 34.128.156.84
- ES (Spain): 34.120.102.147
- IT (Italy): 34.8.234.58
- KR (South Korea): 34.54.155.245
- ZA (South Africa): 35.190.79.68
Port: 443
│traps-management-servicech-<xsiam-tenant>.traps.paloaltonetworks.comUsed for all other requests between the agent and its tenant server including heartbeat, uploads, action results, and scan reports.│IP address by region:- US (United States): 34.98.77.231
- EU (Europe): 34.102.140.103
- CA (Canada): 34.96.120.25
- UK (United Kingdom): 35.244.133.254
- JP (Japan): 34.95.66.187
- SG (Singapore): 34.120.142.18
- AU (Australia): 34.102.237.151
- DE (Germany): 34.107.161.143
- IN (India): 34.120.213.188
- CH (Switzerland): 34.149.180.250
- PL (Poland): 35.190.13.237
- TW (Taiwan): 34.149.248.76
- QT (Qatar): 34.107.129.254
- FA (France): 34.36.155.211
- IL (Israel): 34.128.157.130
- SA (Saudi Arabia): 34.107.213.85
- ID (Indonesia): 34.128.156.84
- ES (Spain): 34.120.102.147
- IT (Italy): 34.8.234.58
- KR (South Korea): 34.54.155.245
- ZA (South Africa): 35.190.79.68
- FI (Finland): 136.110.165.34
Port: 443
│traps-management-serviceapi-<xsiam-tenant>.xdr.<region>.paloaltonetworks.comUsed for API requests and responses.│IP address by region:- US (United States): 35.222.81.194
- EU (Europe): 34.90.67.58
- CA (Canada): 35.203.82.121
- UK (United Kingdom): 34.89.56.78
- JP (Japan): 34.84.125.129
- SG (Singapore): 34.87.83.144
- AU (Australia): 35.189.18.208
- DE (Germany): 34.107.57.23
- IN (India): 35.200.158.164
- CH (Switzerland): 34.65.248.119
- PL (Poland): 34.116.216.55
- TW (Taiwan): 35.234.8.249
- QT (Qatar): 34.18.46.240
- FA (France): 34.155.222.152
- IL (Israel): 34.165.156.139
- SA (Saudi Arabia): 34.166.58.79
- ID (Indonesia): 34.128.115.238
- ES (Spain): 34.175.30.176
- IT (Italy): 34.154.195.120
- KR (South Korea): 34.64.54.175
- ZA (South Africa): 34.35.64.191
Port: 443
│-api-<xsiam-tenant>.xdr.<region>.paloaltonetworks.comUsed for API requests and responses.│IP address by region:- US (United States): 35.222.81.194
- EU (Europe): 34.90.67.58
- CA (Canada): 35.203.82.121
- UK (United Kingdom): 34.89.56.78
- JP (Japan): 34.84.125.129
- SG (Singapore): 34.87.83.144
- AU (Australia): 35.189.18.208
- DE (Germany): 34.107.57.23
- IN (India): 35.200.158.164
- CH (Switzerland): 34.65.248.119
- PL (Poland): 34.116.216.55
- TW (Taiwan): 35.234.8.249
- QT (Qatar): 34.18.46.240
- FA (France): 34.155.222.152
- IL (Israel): 34.165.156.139
- SA (Saudi Arabia): 34.166.58.79
- ID (Indonesia): 34.128.115.238
- ES (Spain): 34.175.30.176
- IT (Italy): 34.154.195.120
- KR (South Korea): 34.64.54.175
- ZA (South Africa): 34.35.64.191
- FI (Finland): 35.228.73.215
Port: 443
│-Log forwarding to a syslog receiver││Log forwarding to a syslog receiver││See Integrate a syslog receiver for information about log forwarding IP addresses per region for syslog receivers.││See Integrate a syslog receiver for information about log forwarding IP addresses per region for syslog receivers.││The following table lists the required resources for Federal (United States - Government).The following table lists the required resources for Federal (United States - Government).FQDN│IP addresses and port│App-ID coverage│Required for XDR CollectorsFQDN│IP addresses and port│App-ID coverage│Required for XDR Collectors| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------- | -------------------------- | --------------------------- || -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------- | -------------------------- | --------------------------- |distributions-prod-fed.traps.paloaltonetworks.comUsed for the first request in registration flow where the agent passes the distribution ID and obtains thech-<xsiam-tenant>.traps.paloaltonetworks.comof its tenant.│- IP address: 104.198.132.24
- Port: 443
traps-management-service│distributions-prod-fed.traps.paloaltonetworks.comUsed for the first request in registration flow where the agent passes the distribution ID and obtains thech-<xsiam-tenant>.traps.paloaltonetworks.comof its tenant.│- IP address: 104.198.132.24
- Port: 443
traps-management-service│panw-xdr-installers-prod-fr.storage.googleapis.comUsed to download installers for upgrade actions from the server.│- IP ranges in GCP
- Port: 443
cortex-xdr│panw-xdr-installers-prod-fr.storage.googleapis.comUsed to download installers for upgrade actions from the server.│- IP ranges in GCP
- Port: 443
cortex-xdr│global-content-profiles-policy-prod-fr.storage.googleapis.comUsed to download content updates.│- IP ranges in GCP
- Port: 443
cortex-xdr│global-content-profiles-policy-prod-fr.storage.googleapis.comUsed to download content updates.│- IP ranges in GCP
- Port: 443
cortex-xdr│Show markdown source
@@ -12,26 +12,26 @@ Refer to the following tables for the FQDNs, IP addresses, ports, and App-ID cov For IP address ranges in GCP, refer to the following tables for IP address coverage for your deployment. * [https://www.gstatic.com/ipranges/goog.json](https://www.gstatic.com/ipranges/goog.json): Refer to this list to look up and allow access to the IP address ranges subnets. * [https://www.gstatic.com/ipranges/cloud.json](https://www.gstatic.com/ipranges/cloud.json): Refer to this list to look up and allow access to the IP address ranges associated with your region. The following table shows the required resources by region. -| FQDN | IP addresses and port | App-ID coverage | -| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------- | -| `<xsiam-tenant>.xdr.<region>.paloaltonetworks.com` Used to connect to the Cortex XSIAM management console. | <p>IP address by region:</p><ul><li>US (United States): 35.244.250.18</li><li>EU (Europe): 35.227.237.180</li><li>CA (Canada): 34.120.31.199</li><li>UK (United Kingdom): 34.120.87.77</li><li>JP (Japan): 35.241.28.254</li><li>SG (Singapore): 34.117.211.129</li><li>AU (Australia): 34.120.229.65</li><li>DE (Germany): 34.98.68.183</li><li>IN (India): 35.186.207.80</li><li>CH (Switzerland): 34.111.6.153</li><li>PL (Poland): 34.117.240.208</li><li>TW (Taiwan): 34.160.28.41</li><li>QT (Qatar): 35.190.0.180</li><li>FA (France): 34.111.134.57</li><li>IL (Israel): 34.111.129.144</li><li>SA (Saudi Arabia): 35.244.157.127</li><li>ID (Indonesia): 34.111.58.152</li><li>ES (Spain): 34.111.188.248</li><li>IT (Italy): 34.8.224.70</li><li>KR (South Korea): 34.54.5.247</li><li>ZA (South Africa): 34.149.165.12</li></ul><p>Port: 443</p> | `cortex-xdr` | -| `distributions.traps.paloaltonetworks.com` Used for the first request in registration flow where the agent passes the distribution id and obtains the `ch-<xsiam-tenant>.traps.paloaltonetworks.com` of its tenant. | <ul><li>IP address: 35.223.6.69</li><li>Port: 443</li></ul> | `traps-management-service` | -| `panw-xdr-installers-prod-us.storage.googleapis.com` Used to download installers for upgrade actions from the server.This storage bucket is used for all regions. | <ul><li>IP ranges in GCP</li><li>Port: 443</li></ul> | `cortex-xdr` | -| `global-content-profiles-policy.storage.googleapis.com` Used to download content updates. | <ul><li>IP ranges in GCP</li><li>Port: 443</li></ul> | `cortex-xdr` | -| `ch-<xsiam-tenant>.traps.paloaltonetworks.com` Used for all other requests between the agent and its tenant server including heartbeat, uploads, action results, and scan reports. | <p>IP address by region:</p><ul><li>US (United States): 34.98.77.231</li><li>EU (Europe): 34.102.140.103</li><li>CA (Canada): 34.96.120.25</li><li>UK (United Kingdom): 35.244.133.254</li><li>JP (Japan): 34.95.66.187</li><li>SG (Singapore): 34.120.142.18</li><li>AU (Australia): 34.102.237.151</li><li>DE (Germany): 34.107.161.143</li><li>IN (India): 34.120.213.188</li><li>CH (Switzerland): 34.149.180.250</li><li>PL (Poland): 35.190.13.237</li><li>TW (Taiwan): 34.149.248.76</li><li>QT (Qatar): 34.107.129.254</li><li>FA (France): 34.36.155.211</li><li>IL (Israel): 34.128.157.130</li><li>SA (Saudi Arabia): 34.107.213.85</li><li>ID (Indonesia): 34.128.156.84</li><li>ES (Spain): 34.120.102.147</li><li>IT (Italy): 34.8.234.58</li><li>KR (South Korea): 34.54.155.245</li><li>ZA (South Africa): 35.190.79.68</li></ul><p>Port: 443</p> | `traps-management-service` | -| `api-<xsiam-tenant>.xdr.<region>.paloaltonetworks.com` Used for API requests and responses. | <p>IP address by region:</p><ul><li>US (United States): 35.222.81.194</li><li>EU (Europe): 34.90.67.58</li><li>CA (Canada): 35.203.82.121</li><li>UK (United Kingdom): 34.89.56.78</li><li>JP (Japan): 34.84.125.129</li><li>SG (Singapore): 34.87.83.144</li><li>AU (Australia): 35.189.18.208</li><li>DE (Germany): 34.107.57.23</li><li>IN (India): 35.200.158.164</li><li>CH (Switzerland): 34.65.248.119</li><li>PL (Poland): 34.116.216.55</li><li>TW (Taiwan): 35.234.8.249</li><li>QT (Qatar): 34.18.46.240</li><li>FA (France): 34.155.222.152</li><li>IL (Israel): 34.165.156.139</li><li>SA (Saudi Arabia): 34.166.58.79</li><li>ID (Indonesia): 34.128.115.238</li><li>ES (Spain): 34.175.30.176</li><li>IT (Italy): 34.154.195.120</li><li>KR (South Korea): 34.64.54.175</li><li>ZA (South Africa): 34.35.64.191</li></ul><p>Port: 443</p> | - | -| **Log forwarding to a syslog receiver** | | | -| See [Integrate a syslog receiver](../../../../onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xsiam-to-external-services/configure-external-applications-for-forwarding/integrate-a-syslog-receiver) for information about log forwarding IP addresses per region for syslog receivers. | | | +| FQDN | IP addresses and port | App-ID coverage | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------- | +| `<xsiam-tenant>.xdr.<region>.paloaltonetworks.com` Used to connect to the Cortex XSIAM management console. | <p>IP address by region:</p><ul><li>US (United States): 35.244.250.18</li><li>EU (Europe): 35.227.237.180</li><li>CA (Canada): 34.120.31.199</li><li>UK (United Kingdom): 34.120.87.77</li><li>JP (Japan): 35.241.28.254</li><li>SG (Singapore): 34.117.211.129</li><li>AU (Australia): 34.120.229.65</li><li>DE (Germany): 34.98.68.183</li><li>IN (India): 35.186.207.80</li><li>CH (Switzerland): 34.111.6.153</li><li>PL (Poland): 34.117.240.208</li><li>TW (Taiwan): 34.160.28.41</li><li>QT (Qatar): 35.190.0.180</li><li>FA (France): 34.111.134.57</li><li>IL (Israel): 34.111.129.144</li><li>SA (Saudi Arabia): 35.244.157.127</li><li>ID (Indonesia): 34.111.58.152</li><li>ES (Spain): 34.111.188.248</li><li>IT (Italy): 34.8.224.70</li><li>KR (South Korea): 34.54.5.247</li><li>ZA (South Africa): 34.149.165.12</li><li>FI (Finland): 34.160.63.63</li></ul><p>Port: 443</p> | `cortex-xdr` | +| `distributions.traps.paloaltonetworks.com` Used for the first request in registration flow where the agent passes the distribution id and obtains the `ch-<xsiam-tenant>.traps.paloaltonetworks.com` of its tenant. | <ul><li>IP address: 35.223.6.69</li><li>Port: 443</li></ul> | `traps-management-service` | +| `panw-xdr-installers-prod-us.storage.googleapis.com` Used to download installers for upgrade actions from the server.This storage bucket is used for all regions. | <ul><li>IP ranges in GCP</li><li>Port: 443</li></ul> | `cortex-xdr` | +| `global-content-profiles-policy.storage.googleapis.com` Used to download content updates. | <ul><li>IP ranges in GCP</li><li>Port: 443</li></ul> | `cortex-xdr` | +| `ch-<xsiam-tenant>.traps.paloaltonetworks.com` Used for all other requests between the agent and its tenant server including heartbeat, uploads, action results, and scan reports. | <p>IP address by region:</p><ul><li>US (United States): 34.98.77.231</li><li>EU (Europe): 34.102.140.103</li><li>CA (Canada): 34.96.120.25</li><li>UK (United Kingdom): 35.244.133.254</li><li>JP (Japan): 34.95.66.187</li><li>SG (Singapore): 34.120.142.18</li><li>AU (Australia): 34.102.237.151</li><li>DE (Germany): 34.107.161.143</li><li>IN (India): 34.120.213.188</li><li>CH (Switzerland): 34.149.180.250</li><li>PL (Poland): 35.190.13.237</li><li>TW (Taiwan): 34.149.248.76</li><li>QT (Qatar): 34.107.129.254</li><li>FA (France): 34.36.155.211</li><li>IL (Israel): 34.128.157.130</li><li>SA (Saudi Arabia): 34.107.213.85</li><li>ID (Indonesia): 34.128.156.84</li><li>ES (Spain): 34.120.102.147</li><li>IT (Italy): 34.8.234.58</li><li>KR (South Korea): 34.54.155.245</li><li>ZA (South Africa): 35.190.79.68</li><li>FI (Finland): 136.110.165.34</li></ul><p>Port: 443</p> | `traps-management-service` | +| `api-<xsiam-tenant>.xdr.<region>.paloaltonetworks.com` Used for API requests and responses. | <p>IP address by region:</p><ul><li>US (United States): 35.222.81.194</li><li>EU (Europe): 34.90.67.58</li><li>CA (Canada): 35.203.82.121</li><li>UK (United Kingdom): 34.89.56.78</li><li>JP (Japan): 34.84.125.129</li><li>SG (Singapore): 34.87.83.144</li><li>AU (Australia): 35.189.18.208</li><li>DE (Germany): 34.107.57.23</li><li>IN (India): 35.200.158.164</li><li>CH (Switzerland): 34.65.248.119</li><li>PL (Poland): 34.116.216.55</li><li>TW (Taiwan): 35.234.8.249</li><li>QT (Qatar): 34.18.46.240</li><li>FA (France): 34.155.222.152</li><li>IL (Israel): 34.165.156.139</li><li>SA (Saudi Arabia): 34.166.58.79</li><li>ID (Indonesia): 34.128.115.238</li><li>ES (Spain): 34.175.30.176</li><li>IT (Italy): 34.154.195.120</li><li>KR (South Korea): 34.64.54.175</li><li>ZA (South Africa): 34.35.64.191</li><li>FI (Finland): 35.228.73.215</li></ul><p>Port: 443</p> | - | +| **Log forwarding to a syslog receiver** | | | +| See [Integrate a syslog receiver](../../../../onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xsiam-to-external-services/configure-external-applications-for-forwarding/integrate-a-syslog-receiver) for information about log forwarding IP addresses per region for syslog receivers. | | | The following table lists the required resources for Federal (United States - Government). | FQDN | IP addresses and port | App-ID coverage | Required for XDR Collectors | | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------- | -------------------------- | --------------------------- | | `distributions-prod-fed.traps.paloaltonetworks.com` Used for the first request in registration flow where the agent passes the distribution ID and obtains the `ch-<xsiam-tenant>.traps.paloaltonetworks.com` of its tenant. | <ul><li>IP address: 104.198.132.24</li><li>Port: 443</li></ul> | `traps-management-service` | | | `panw-xdr-installers-prod-fr.storage.googleapis.com` Used to download installers for upgrade actions from the server. | <ul><li>IP ranges in GCP</li><li>Port: 443</li></ul> | `cortex-xdr` | | | `global-content-profiles-policy-prod-fr.storage.googleapis.com` Used to download content updates. | <ul><li>IP ranges in GCP</li><li>Port: 443</li></ul> | `cortex-xdr` | |
-
▸ ▾ Cortex Data Lake modified +2 −2 The Strata Logging Service connector is described as an XSIAM connector rather than an XSOAR one, in both the intro and the sub-capability list.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/cortex-data-lakeRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -3,15 +3,15 @@hint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex AgentiX license.This sub-capability is available with any active Cortex AgentiX license.Palo Alto Networks Strata Logging Service XSOAR Connector provides cloud-based, centralized log storage and aggregation for your on premise, virtual (private cloud and public cloud) firewalls, for Prisma Access, and for cloud-delivered services such as Cortex XDR.Palo Alto Networks Strata Logging Service XSIAM Connector provides cloud-based, centralized log storage and aggregation for your on premise, virtual (private cloud and public cloud) firewalls, for Prisma Access, and for cloud-delivered services such as Cortex XDR.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Cortex Data Lake: Palo Alto Networks Strata Logging Service XSOAR Connector provides cloud-based, centralized log storage and aggregation for your organization on premise, virtual (private cloud and public cloud) firewalls, for Prisma Access, and for cloud-delivered services such as Cortex XDR.• Cortex Data Lake: Palo Alto Networks Strata Logging Service XSIAM Connector provides cloud-based, centralized log storage and aggregation for your organization on premise, virtual (private cloud and public cloud) firewalls, for Prisma Access, and for cloud-delivered services such as Cortex XDR.To configure this connector, follow the steps outlined in the configuration wizard.To configure this connector, follow the steps outlined in the configuration wizard.Show markdown source
@@ -3,15 +3,15 @@ {% hint style="warning" %} **Important** This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. {% endhint %} This sub-capability is available with any active Cortex AgentiX license. -Palo Alto Networks Strata Logging Service XSOAR Connector provides cloud-based, centralized log storage and aggregation for your on premise, virtual (private cloud and public cloud) firewalls, for Prisma Access, and for cloud-delivered services such as Cortex XDR. +Palo Alto Networks Strata Logging Service XSIAM Connector provides cloud-based, centralized log storage and aggregation for your on premise, virtual (private cloud and public cloud) firewalls, for Prisma Access, and for cloud-delivered services such as Cortex XDR. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -* **Cortex Data Lake:** Palo Alto Networks Strata Logging Service XSOAR Connector provides cloud-based, centralized log storage and aggregation for your organization on premise, virtual (private cloud and public cloud) firewalls, for Prisma Access, and for cloud-delivered services such as Cortex XDR. +* **Cortex Data Lake:** Palo Alto Networks Strata Logging Service XSIAM Connector provides cloud-based, centralized log storage and aggregation for your organization on premise, virtual (private cloud and public cloud) firewalls, for Prisma Access, and for cloud-delivered services such as Cortex XDR. To configure this connector, follow the steps outlined in the configuration wizard. -
▸ ▾ Prisma Access Browser added +2 −0 New page, currently a heading only, inserted as the parent of the Prisma Access Browser ingestion topic.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/prisma-access-browserRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -0,0 +1,2 @@# Prisma Access BrowserShow markdown source
@@ -0,0 +1,2 @@ +# Prisma Access Browser +
-
▸ ▾ Ingest logs from Prisma Access Browser renamed +0 −0 Moved here unchanged from the palo-alto-networks-integrations root; the previous path no longer resolves.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/prisma-access-browser/ingest-logs-from-prisma-access-browserRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗ moved from
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/ingest-logs-from-prisma-access-browser.md -
▸ ▾ Apache modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/apache/apacheRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -3,15 +3,15 @@hint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Integrate with ActiveMQ to send and read messages on queues and topics, and to fetch messages from a queue or topic and create issues in Cortex XSOAR per message.Integrate with ActiveMQ to send and read messages on queues and topics, and to fetch messages from a queue or topic and create issues in Cortex XSIAM per message.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):To configure this connector, follow the steps outlined in the configuration wizard.To configure this connector, follow the steps outlined in the configuration wizard.Show markdown source
@@ -3,15 +3,15 @@ {% hint style="warning" %} **Important** This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. -Integrate with ActiveMQ to send and read messages on queues and topics, and to fetch messages from a queue or topic and create issues in Cortex XSOAR per message. +Integrate with ActiveMQ to send and read messages on queues and topics, and to fetch messages from a queue or topic and create issues in Cortex XSIAM per message. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [ActiveMQ](https://xsoar.pan.dev/docs/reference/integrations/active-mq): Integration with ActiveMQ queue. To configure this connector, follow the steps outlined in the configuration wizard. -
▸ ▾ Ingest data for API security modified +1 −1 The API security link was a local file:/// path and now resolves to the cloud-security API landscape page.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/api-security/ingest-data-for-api-securityRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,3 +1,3 @@# Ingest data for API security# Ingest data for API securityConfigure the settings in both Cortex XSIAM and your cloud service provider to retrieve and collect API data for further analysis by Cortex's comprehensive API security capabilities that provides a transparent view of API traffic, helping to identify potential security threats.Configure the settings in both Cortex XSIAM and your cloud service provider to retrieve and collect API data for further analysis by Cortex's comprehensive API security capabilities that provides a transparent view of API traffic, helping to identify potential security threats.Show markdown source
@@ -1,3 +1,3 @@ # Ingest data for API security -Configure the settings in both Cortex XSIAM and your cloud service provider to retrieve and collect API data for further analysis by Cortex's comprehensive [API security](file:///protect-your-endpoints/web-and-api-security--waas-/secure-your-api-landscape/gain-visibility-and-assess-risk-of-api-endpoints.html) capabilities that provides a transparent view of API traffic, helping to identify potential security threats. +Configure the settings in both Cortex XSIAM and your cloud service provider to retrieve and collect API data for further analysis by Cortex's comprehensive [API security](../../../../cloud-security/overview/secure-your-api-landscape/gain-visibility-and-assess-risk-of-api-endpoints) capabilities that provides a transparent view of API traffic, helping to identify potential security threats.
-
▸ ▾ Atlassian Automation and Collection modified +2 −2
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/atlassian/atlassian-automation-and-collectionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -9,15 +9,15 @@ This connector is only available for tenants that onboarded after July 26, 2026.Integrate with Atlassian products to automate work and collect data across Jira, Jira Service Management, Confluence, Bitbucket, OpsGenie, and Atlassian IAM. Manage issues, content, spaces, users, alerts, and assets; run automated actions; and collect audit logs and events from Atlassian Cloud and on-prem deployments.Integrate with Atlassian products to automate work and collect data across Jira, Jira Service Management, Confluence, Bitbucket, OpsGenie, and Atlassian IAM. Manage issues, content, spaces, users, alerts, and assets; run automated actions; and collect audit logs and events from Atlassian Cloud and on-prem deployments.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Atlassian Cloud MCP: Use this integration to connect securely with an Atlassian Cloud Model Context Protocol (MCP) server and access its tools in real time. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• Atlassian Cloud MCP: Use this integration to connect securely with an Atlassian Cloud Model Context Protocol (MCP) server and access its tools in real time. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• Atlassian Confluence Cloud: Atlassian Confluence Cloud allows users to interact with confluence entities like content, space, users, and groups. Users can also manage the space permissions. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Atlassian Confluence Cloud: Atlassian Confluence Cloud allows users to interact with confluence entities like content, space, users, and groups. Users can also manage the space permissions. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Atlassian Confluence Server: This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Atlassian Confluence Server: This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Atlassian IAM: This sub-capability is available with any active Cortex XSIAM, Cortex XDR, or Cortex AgentiX license.• Atlassian IAM: This sub-capability is available with any active Cortex XSIAM, Cortex XDR, or Cortex AgentiX license.• AtlassianJiraServiceManagement: Use this integration to manage Jira objects and attach files to Jira objects from Cortex XSOAR. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• AtlassianJiraServiceManagement: Use this integration to manage Jira objects and attach files to Jira objects from Cortex XSIAM. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Bitbucket: Bitbucket Cloud is a Git-based code and CI/CD tool optimized for teams using Jira. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Bitbucket: Bitbucket Cloud is a Git-based code and CI/CD tool optimized for teams using Jira. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Jira Event Collector: Jira logs event collector integration for Cortex XSIAM. This sub-capability is available with any active Cortex XSIAM license.• Jira Event Collector: Jira logs event collector integration for Cortex XSIAM. This sub-capability is available with any active Cortex XSIAM license.• Jira V3: Use the Jira integration to manage issues, create Cortex XSOAR incidents from Jira projects, and mirror issues to existing issue incidents in Cortex XSOAR. The integration now supports both OnPrem, and Cloud instances. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• Jira V3: Use the Jira integration to manage issues, create Cortex XSIAM incidents from Jira projects, and mirror issues to existing issue incidents in Cortex XSIAM. The integration now supports both OnPrem, and Cloud instances. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• OpsGenieV3: Integration with Atlassian OpsGenie. OpsGenie is a cloud-based service that enables operations teams to manage alerts generated by monitoring tools to ensure the right people are notified, and the problems are addressed in a timely manner. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• OpsGenieV3: Integration with Atlassian OpsGenie. OpsGenie is a cloud-based service that enables operations teams to manage alerts generated by monitoring tools to ensure the right people are notified, and the problems are addressed in a timely manner. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.To configure this connector, follow the steps outlined in the configuration wizard.To configure this connector, follow the steps outlined in the configuration wizard.Show markdown source
@@ -9,15 +9,15 @@ This connector is only available for tenants that onboarded after July 26, 2026. Integrate with Atlassian products to automate work and collect data across Jira, Jira Service Management, Confluence, Bitbucket, OpsGenie, and Atlassian IAM. Manage issues, content, spaces, users, alerts, and assets; run automated actions; and collect audit logs and events from Atlassian Cloud and on-prem deployments. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Atlassian Cloud MCP](https://xsoar.pan.dev/docs/reference/integrations/atlassian-cloud-mcp): Use this integration to connect securely with an Atlassian Cloud Model Context Protocol (MCP) server and access its tools in real time. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. * [Atlassian Confluence Cloud](https://xsoar.pan.dev/docs/reference/integrations/atlassian-confluence-cloud): Atlassian Confluence Cloud allows users to interact with confluence entities like content, space, users, and groups. Users can also manage the space permissions. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [Atlassian Confluence Server](https://xsoar.pan.dev/docs/reference/integrations/atlassian-confluence-server): This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [Atlassian IAM](https://xsoar.pan.dev/docs/reference/integrations/atlassian-iam): This sub-capability is available with any active Cortex XSIAM, Cortex XDR, or Cortex AgentiX license. -* [AtlassianJiraServiceManagement](https://xsoar.pan.dev/docs/reference/integrations/atlassian-jira-service-management): Use this integration to manage Jira objects and attach files to Jira objects from Cortex XSOAR. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. +* [AtlassianJiraServiceManagement](https://xsoar.pan.dev/docs/reference/integrations/atlassian-jira-service-management): Use this integration to manage Jira objects and attach files to Jira objects from Cortex XSIAM. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [Bitbucket](https://xsoar.pan.dev/docs/reference/integrations/bitbucket): Bitbucket Cloud is a Git-based code and CI/CD tool optimized for teams using Jira. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [Jira Event Collector](https://xsoar.pan.dev/docs/reference/integrations/jira-event-collector): Jira logs event collector integration for Cortex XSIAM. This sub-capability is available with any active Cortex XSIAM license. -* [Jira V3](https://xsoar.pan.dev/docs/reference/integrations/jira-v3): Use the Jira integration to manage issues, create Cortex XSOAR incidents from Jira projects, and mirror issues to existing issue incidents in Cortex XSOAR. The integration now supports both OnPrem, and Cloud instances. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. +* [Jira V3](https://xsoar.pan.dev/docs/reference/integrations/jira-v3): Use the Jira integration to manage issues, create Cortex XSIAM incidents from Jira projects, and mirror issues to existing issue incidents in Cortex XSIAM. The integration now supports both OnPrem, and Cloud instances. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. * [OpsGenieV3](https://xsoar.pan.dev/docs/reference/integrations/ops-genie-v3): Integration with Atlassian OpsGenie. OpsGenie is a cloud-based service that enables operations teams to manage alerts generated by monitoring tools to ensure the right people are notified, and the problems are addressed in a timely manner. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. To configure this connector, follow the steps outlined in the configuration wizard.
-
▸ ▾ Box modified +6 −6
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/boxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@# Box# BoxYou can configure collecting Box logs and data using a standard data using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connectors:You can configure collecting Box logs and data using a standard data using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connectors:Box vendor│DescriptionBox vendor│Description| ---------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ---------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Standard data source overview│Forward different types of data from Box enterprise accounts to Cortex XSIAM using the Box data source.Standard data source overview│Forward different types of data from Box enterprise accounts to Cortex XSIAM using the Box data source.Link to standard data source instructions│The following types of data can be ingested from Dropbox:Events and security alerts
- Events (admin_logs)
- Box Shield Alerts
Directory and metadata
- Users
- Groups
For more information, see Ingest logs and data from Box.
Link to standard data source instructions│The following types of data can be ingested from Dropbox:Events and security alerts
- Events (admin_logs)
- Box Shield Alerts
Directory and metadata
- Users
- Groups
For more information, see Ingest logs and data from Box.
Links to content pack integration details (onboarded prior to July 26, 2026)│The Box content pack contains classifiers, issue fields and types, and parsing and modeling rules to normalize Box data in Cortex XSIAM. It also includes the following integrations:
- Box Event Collector: Use this integration to collect events from Box's logs. It includes a command to get Box events.
- Box V2: Use this integration to manage Box users. It includes commands to search Box content and manage file folders and share links.
Links to content pack integration details (onboarded prior to July 26, 2026)│The Box content pack contains classifiers, issue fields and types, and parsing and modeling rules to normalize Box data in Cortex XSIAM. It also includes the following integrations:
- Box Event Collector: Use this integration to collect events from Box's logs. It includes a command to get Box events.
- Box V2: Use this integration to manage Box users. It includes commands to search Box content and manage file folders and share links.
Link to connectors│- Box Automation and Collection (onboarded after July 26, 2026)
- Box
Link to connectors│- Box Automation and Collection (onboarded after July 26, 2026)
- Box
Show markdown source
@@ -1,10 +1,10 @@ # Box You can configure collecting Box logs and data using a standard data using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connectors: -| Box vendor | Description | -| ---------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Standard data source overview | Forward different types of data from Box enterprise accounts to Cortex XSIAM using the Box data source. | -| Link to standard data source instructions | <p>The following types of data can be ingested from Dropbox:</p><ul><li><p>Events and security alerts</p><ul><li>Events (admin_logs)</li><li>Box Shield Alerts</li></ul></li><li><p>Directory and metadata</p><ul><li>Users</li><li>Groups</li></ul></li></ul><p>For more information, see <a href="box/ingest-logs-and-data-from-box">Ingest logs and data from Box</a>.</p> | -| Links to content pack integration details (onboarded prior to July 26, 2026) | <p></p><p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/Box">Box </a>content pack contains classifiers, issue fields and types, and parsing and modeling rules to normalize Box data in Cortex XSIAM. It also includes the following integrations:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/box-events-collector">Box Event Collector</a>: Use this integration to collect events from Box's logs. It includes a command to get Box events.</li><li><a href="https://xsoar.pan.dev/docs/reference/integrations/box-v2">Box V2</a>: Use this integration to manage Box users. It includes commands to search Box content and manage file folders and share links.</li></ul> | -| Link to connectors | <ul><li><a href="box/box-automation-and-collection">Box Automation and Collection</a> (onboarded after July 26, 2026)</li><li><a href="box/box">Box</a></li></ul> | +| Box vendor | Description | +| ---------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| Standard data source overview | Forward different types of data from Box enterprise accounts to Cortex XSIAM using the Box data source. | +| Link to standard data source instructions | <p>The following types of data can be ingested from Dropbox:</p><ul><li><p>Events and security alerts</p><ul><li>Events (admin_logs)</li><li>Box Shield Alerts</li></ul></li><li><p>Directory and metadata</p><ul><li>Users</li><li>Groups</li></ul></li></ul><p>For more information, see <a href="box/ingest-logs-and-data-from-box">Ingest logs and data from Box</a>.</p> | +| Links to content pack integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/Box">Box </a>content pack contains classifiers, issue fields and types, and parsing and modeling rules to normalize Box data in Cortex XSIAM. It also includes the following integrations:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/box-events-collector">Box Event Collector</a>: Use this integration to collect events from Box's logs. It includes a command to get Box events.</li><li><a href="https://xsoar.pan.dev/docs/reference/integrations/box-v2">Box V2</a>: Use this integration to manage Box users. It includes commands to search Box content and manage file folders and share links.</li></ul> | +| Link to connectors | <ul><li><a href="box/box-automation-and-collection">Box Automation and Collection</a> (onboarded after July 26, 2026)</li><li><a href="box/box">Box</a></li></ul> |
-
▸ ▾ Cisco ASA firewalls and AnyConnect` modified +6 −6
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-asa-firewalls-and-anyconnectRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,12 +1,12 @@# Cisco ASA firewalls and AnyConnect`# Cisco ASA firewalls and AnyConnect`You can configure collecting Cisco ASA firewall and AnyConnect VPN logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):You can configure collecting Cisco ASA firewall and AnyConnect VPN logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):Cisco ASA firewalls and AnyConnect vendor│DescriptionCisco ASA firewalls and AnyConnect vendor│Description| -------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || -------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Syslog Collector applet overview│If you use Cisco ASA firewalls or Cisco AnyConnect VPN, you can forward Cisco ASA firewall and AnyConnect VPN logs to Cortex XSIAM using the Broker VM Syslog Collector applet in a CISCO format.Syslog Collector applet overview│If you use Cisco ASA firewalls or Cisco AnyConnect VPN, you can forward Cisco ASA firewall and AnyConnect VPN logs to Cortex XSIAM using the Broker VM Syslog Collector applet in a CISCO format.Link to Syslog Collector applet instructions│Ingest logs from Cisco ASA firewalls and AnyConnectLink to Syslog Collector applet instructions│Ingest logs from Cisco ASA firewalls and AnyConnectLink to content pack/integration instructions (onboarded prior to July 26, 2026)│The Cisco ASA content pack interacts with the Cisco Adaptive Security Appliance Software via an API to manage interfaces, rules, and network objects. The content pack includes the following integration:
- Cisco Adaptive Security Appliance Software: Use this integration to manage interfaces, rules, and network objects on the Cisco Adaptive Security Appliance Software platform. This integration includes commands for listing and managing network object groups, local user groups, local users, time ranges, security object groups, user objects, interface information, configuration backup, and creating, listing, getting, editing, and deleting firewall rules, along with the command to save the running configuration to memory (
cisco-asa-write-memory).
Link to content pack/integration instructions (onboarded prior to July 26, 2026)│The Cisco ASA content pack interacts with the Cisco Adaptive Security Appliance Software via an API to manage interfaces, rules, and network objects. The content pack includes the following integration:
- Cisco Adaptive Security Appliance Software: Use this integration to manage interfaces, rules, and network objects on the Cisco Adaptive Security Appliance Software platform. This integration includes commands for listing and managing network object groups, local user groups, local users, time ranges, security object groups, user objects, interface information, configuration backup, and creating, listing, getting, editing, and deleting firewall rules, along with the command to save the running configuration to memory (
cisco-asa-write-memory).
Link to connector (onboarded after July 26, 2026)│Cisco ASALink to connector (onboarded after July 26, 2026)│Cisco ASAShow markdown source
@@ -1,12 +1,12 @@ # Cisco ASA firewalls and AnyConnect\` You can configure collecting Cisco ASA firewall and AnyConnect VPN logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026): -| Cisco ASA firewalls and AnyConnect vendor | Description | -| -------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Syslog Collector applet overview | If you use Cisco ASA firewalls or Cisco AnyConnect VPN, you can forward Cisco ASA firewall and AnyConnect VPN logs to Cortex XSIAM using the Broker VM Syslog Collector applet in a CISCO format. | -| Link to Syslog Collector applet instructions | [Ingest logs from Cisco ASA firewalls and AnyConnect](../../generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/cisco-asa-firewalls-and-anyconnect/ingest-logs-from-cisco-asa-firewalls-and-anyconnect) | -| Link to content pack/integration instructions (onboarded prior to July 26, 2026) | <p></p><p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/CiscoASA/">Cisco ASA</a> content pack interacts with the Cisco Adaptive Security Appliance Software via an API to manage interfaces, rules, and network objects. The content pack includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/cisco-asa">Cisco Adaptive Security Appliance Software</a>: Use this integration to manage interfaces, rules, and network objects on the Cisco Adaptive Security Appliance Software platform. This integration includes commands for listing and managing network object groups, local user groups, local users, time ranges, security object groups, user objects, interface information, configuration backup, and creating, listing, getting, editing, and deleting firewall rules, along with the command to save the running configuration to memory (<strong><code>cisco-asa-write-memory</code></strong>).</li></ul> | -| Link to connector (onboarded after July 26, 2026) | [Cisco ASA](cisco-asa) | +| Cisco ASA firewalls and AnyConnect vendor | Description | +| -------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| Syslog Collector applet overview | If you use Cisco ASA firewalls or Cisco AnyConnect VPN, you can forward Cisco ASA firewall and AnyConnect VPN logs to Cortex XSIAM using the Broker VM Syslog Collector applet in a CISCO format. | +| Link to Syslog Collector applet instructions | [Ingest logs from Cisco ASA firewalls and AnyConnect](../../generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/cisco-asa-firewalls-and-anyconnect/ingest-logs-from-cisco-asa-firewalls-and-anyconnect) | +| Link to content pack/integration instructions (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/CiscoASA/">Cisco ASA</a> content pack interacts with the Cisco Adaptive Security Appliance Software via an API to manage interfaces, rules, and network objects. The content pack includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/cisco-asa">Cisco Adaptive Security Appliance Software</a>: Use this integration to manage interfaces, rules, and network objects on the Cisco Adaptive Security Appliance Software platform. This integration includes commands for listing and managing network object groups, local user groups, local users, time ranges, security object groups, user objects, interface information, configuration backup, and creating, listing, getting, editing, and deleting firewall rules, along with the command to save the running configuration to memory (<strong><code>cisco-asa-write-memory</code></strong>).</li></ul> | +| Link to connector (onboarded after July 26, 2026) | [Cisco ASA](cisco-asa) |
- Cisco Adaptive Security Appliance Software: Use this integration to manage interfaces, rules, and network objects on the Cisco Adaptive Security Appliance Software platform. This integration includes commands for listing and managing network object groups, local user groups, local users, time ranges, security object groups, user objects, interface information, configuration backup, and creating, listing, getting, editing, and deleting firewall rules, along with the command to save the running configuration to memory (
-
▸ ▾ Ingest alerts and metadata from Crowdstrike APIs modified +7 −12 The inline base64 Falcon logo became a hosted image, and the two API-client screenshots were dropped from the procedure.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/crowdstrike/crowdstrike-apis/ingest-alerts-and-metadata-from-crowdstrike-apisRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -9,32 +9,27 @@ To receive CrowdStrike API real-time alerts and logs, you must first configure dFor more information on configuring data collection from CrowdStrike APIs, see the CrowdStrike Documentation.For more information on configuring data collection from CrowdStrike APIs, see the CrowdStrike Documentation.When Cortex XSIAM begins receiving alerts and logs, it automatically creates a CrowdStrike API XQL dataset (crowdstrike_falcon_incident_raw). You can use the issues created by Cortex XSIAM in rules, and search the logs using XQL Search. For example queries, refer to the in-app XQL Library.When Cortex XSIAM begins receiving alerts and logs, it automatically creates a CrowdStrike API XQL dataset (crowdstrike_falcon_incident_raw). You can use the issues created by Cortex XSIAM in rules, and search the logs using XQL Search. For example queries, refer to the in-app XQL Library.In order to ingest alert and host data, they must be configured correctly at both the CrowdStrike and the Cortex XSIAM sides, as explained in the following steps.In order to ingest alert and host data, they must be configured correctly at both the CrowdStrike and the Cortex XSIAM sides, as explained in the following steps.1. Configure data collection from CrowdStrike APIs.1. Configure data collection from CrowdStrike APIs.1. In the CrowdStrike Falcon application, select 🖼 cs-logo.png Support → API Clients and Keys.1. In the CrowdStrike Falcon application, select 🖼 cs-logo.png Support → API Clients and Keys.2. Under the OAuth2 API Clients section, Add new API client.2. Under the OAuth2 API Clients section, Add new API client.3. Configure your new API client with these settings:3. Configure your new API client with these settings• CLIENT NAME: Specify a name for the new API client.[](https://docs-cortex.paloaltonetworks.com/viewer/attachment/5CAbsl8idaK8R43ZLhoTOw/Z18IdWiHcHDfIYxyQvqhtQ-5CAbsl8idaK8R43ZLhoTOw)• DESCRIPTION: (Optional) Specify a description for the new API client.• API SCOPES → Event streams: Select the Read permissions check box.• CLIENT NAME: Specify a name for the new API client.• API SCOPES → Hosts: Select the Read permissions check box.• DESCRIPTION: (Optional) Specify a description for the new API client.• API SCOPES → Event streams: Select the Read permissions check box.• API SCOPES → Hosts: Select the Read permissions check box.4. Click ADD.4. Click ADD.5. Copy the values for the CLIENT ID, SECRET, and BASE URL, and save them, because you will need them when you configure the Data Collection settings in Cortex XSIAM.5. Copy the values for the CLIENT ID, SECRET, and BASE URL, and save them, because you will need them when you configure the Data Collection settings in Cortex XSIAM.Ensure that you save the SECRET value because this is the only time that it is displayed.Ensure that you save the SECRET value because this is the only time that it is displayed[](https://docs-cortex.paloaltonetworks.com/viewer/attachment/5CAbsl8idaK8R43ZLhoTOw/gKtp7yoLJE_DiJXWwYrcNA-5CAbsl8idaK8R43ZLhoTOw)f. Click DONE.f. Click DONE.2. Configure the CrowdStrike Platform collection in Cortex XSIAM.2. Configure the CrowdStrike Platform collection in Cortex XSIAM.1. Navigate to Settings → Data Sources & Integrations.1. Navigate to Settings → Data Sources & Integrations.2. On the Data Sources & Integrations page, click + Add New, search for CrowdStrike Platform, then hover over it and click Add.2. On the Data Sources & Integrations page, click + Add New, search for CrowdStrike Platform, then hover over it and click Add.3. Set these parameters:3. Set these parameters:• Name: Specify a descriptive name for your log collection configuration, preferably the same CLIENT NAME used when adding a new client API in the CrowdStrike Falcon application, as explained above.• Name: Specify a descriptive name for your log collection configuration, preferably the same CLIENT NAME used when adding a new client API in the CrowdStrike Falcon application, as explained above.Show markdown source
@@ -9,32 +9,27 @@ To receive CrowdStrike API real-time alerts and logs, you must first configure d For more information on configuring data collection from CrowdStrike APIs, see the CrowdStrike Documentation. When Cortex XSIAM begins receiving alerts and logs, it automatically creates a CrowdStrike API XQL dataset (`crowdstrike_falcon_incident_raw`). You can use the issues created by Cortex XSIAM in rules, and search the logs using XQL Search. For example queries, refer to the in-app XQL Library. In order to ingest alert and host data, they must be configured correctly at both the CrowdStrike and the Cortex XSIAM sides, as explained in the following steps. 1. Configure data collection from CrowdStrike APIs. - 1. In the CrowdStrike Falcon application, select [](https://docs-cortex.paloaltonetworks.com/viewer/attachment/5CAbsl8idaK8R43ZLhoTOw/qATr_yEenE8HnjMR5rtXLw-5CAbsl8idaK8R43ZLhoTOw) Support → API Clients and Keys. + 1. In the CrowdStrike Falcon application, select  Support → API Clients and Keys. 2. Under the OAuth2 API Clients section, Add new API client. - 3. Configure your new API client with these settings: - - [](https://docs-cortex.paloaltonetworks.com/viewer/attachment/5CAbsl8idaK8R43ZLhoTOw/Z18IdWiHcHDfIYxyQvqhtQ-5CAbsl8idaK8R43ZLhoTOw) - - * CLIENT NAME: Specify a name for the new API client. - * DESCRIPTION: (Optional) Specify a description for the new API client. - * API SCOPES → Event streams: Select the Read permissions check box. - * API SCOPES → Hosts: Select the Read permissions check box. + 3. Configure your new API client with these settings + * CLIENT NAME: Specify a name for the new API client. + * DESCRIPTION: (Optional) Specify a description for the new API client. + * API SCOPES → Event streams: Select the Read permissions check box. + * API SCOPES → Hosts: Select the Read permissions check box. 4. Click ADD. 5. Copy the values for the CLIENT ID, SECRET, and BASE URL, and save them, because you will need them when you configure the Data Collection settings in Cortex XSIAM. - Ensure that you save the SECRET value because this is the only time that it is displayed. - - [](https://docs-cortex.paloaltonetworks.com/viewer/attachment/5CAbsl8idaK8R43ZLhoTOw/gKtp7yoLJE_DiJXWwYrcNA-5CAbsl8idaK8R43ZLhoTOw) + Ensure that you save the SECRET value because this is the only time that it is displayed f. Click DONE. 2. Configure the CrowdStrike Platform collection in Cortex XSIAM. 1. Navigate to Settings → Data Sources & Integrations. 2. On the Data Sources & Integrations page, click + Add New, search for CrowdStrike Platform, then hover over it and click Add. 3. Set these parameters: * Name: Specify a descriptive name for your log collection configuration, preferably the same CLIENT NAME used when adding a new client API in the CrowdStrike Falcon application, as explained above. -
▸ ▾ Dropbox modified +6 −6
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/dropboxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@# Dropbox# DropboxYou can configure collecting Dropbox logs and data using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):You can configure collecting Dropbox logs and data using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):Dropbox vendor│DescriptionDropbox vendor│Description| ----------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ----------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Standard data source overview│Forward different types of data from Dropbox Business accounts to Cortex XSIAM using the Dropbox data source.Standard data source overview│Forward different types of data from Dropbox Business accounts to Cortex XSIAM using the Dropbox data source.Link to standard data source instructions│The following types of data can be ingested from Dropbox:Log collection
- Events
Directory and metadata
- Member Devices
- Users
- Groups
For more information, see Ingest logs and data from Dropbox.
Link to standard data source instructions│The following types of data can be ingested from Dropbox:Log collection
- Events
Directory and metadata
- Member Devices
- Users
- Groups
For more information, see Ingest logs and data from Dropbox.
Links to content pack/ integration details (onboarded prior to July 26, 2026)│The Dropbox content pack fetches and collects security events from Dropbox logs. It includes Correlation Rules, Modeling Rules, Parsing Rules, a Playbook, and a Cortex XSIAM Dashboard. It also includes the following integration:
- Dropbox Event Collector: Use this integration to collect events from Dropbox logs. It contains commands such as
dropbox-auth-startto initiate the authorization process,dropbox-auth-completeto finish authorization,dropbox-auth-testto check connectivity,dropbox-auth-resetto reset authentication, anddropbox-get-eventsto retrieve events.
Links to content pack/ integration details (onboarded prior to July 26, 2026)│The Dropbox content pack fetches and collects security events from Dropbox logs. It includes Correlation Rules, Modeling Rules, Parsing Rules, a Playbook, and a Cortex XSIAM Dashboard. It also includes the following integration:
- Dropbox Event Collector: Use this integration to collect events from Dropbox logs. It contains commands such as
dropbox-auth-startto initiate the authorization process,dropbox-auth-completeto finish authorization,dropbox-auth-testto check connectivity,dropbox-auth-resetto reset authentication, anddropbox-get-eventsto retrieve events.
Link to connector (onboarded after July 26, 2026)│DropboxLink to connector (onboarded after July 26, 2026)│DropboxShow markdown source
@@ -1,10 +1,10 @@ # Dropbox You can configure collecting Dropbox logs and data using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026): -| Dropbox vendor | Description | -| ----------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Standard data source overview | Forward different types of data from Dropbox Business accounts to Cortex XSIAM using the Dropbox data source. | -| Link to standard data source instructions | <p>The following types of data can be ingested from Dropbox:</p><ul><li><p>Log collection</p><ul><li>Events</li></ul></li><li><p>Directory and metadata</p><ul><li>Member Devices</li><li>Users</li><li>Groups</li></ul></li></ul><p>For more information, see <a href="dropbox/ingest-logs-and-data-from-dropbox">Ingest logs and data from Dropbox</a>.</p> | -| Links to content pack/ integration details (onboarded prior to July 26, 2026) | <p></p><p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/Dropbox/">Dropbox</a> content pack fetches and collects security events from Dropbox logs. It includes Correlation Rules, Modeling Rules, Parsing Rules, a Playbook, and a Cortex XSIAM Dashboard. It also includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/dropbox-events-collector">Dropbox Event Collector</a>: Use this integration to collect events from Dropbox logs. It contains commands such as <strong><code>dropbox-auth-start</code></strong> to initiate the authorization process, <strong><code>dropbox-auth-complete</code></strong> to finish authorization, <strong><code>dropbox-auth-test</code></strong> to check connectivity, <strong><code>dropbox-auth-reset</code></strong> to reset authentication, and <strong><code>dropbox-get-events</code></strong> to retrieve events.</li></ul> | -| Link to connector (onboarded after July 26, 2026) | [Dropbox](dropbox/dropbox) | +| Dropbox vendor | Description | +| ----------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| Standard data source overview | Forward different types of data from Dropbox Business accounts to Cortex XSIAM using the Dropbox data source. | +| Link to standard data source instructions | <p>The following types of data can be ingested from Dropbox:</p><ul><li><p>Log collection</p><ul><li>Events</li></ul></li><li><p>Directory and metadata</p><ul><li>Member Devices</li><li>Users</li><li>Groups</li></ul></li></ul><p>For more information, see <a href="dropbox/ingest-logs-and-data-from-dropbox">Ingest logs and data from Dropbox</a>.</p> | +| Links to content pack/ integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/Dropbox/">Dropbox</a> content pack fetches and collects security events from Dropbox logs. It includes Correlation Rules, Modeling Rules, Parsing Rules, a Playbook, and a Cortex XSIAM Dashboard. It also includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/dropbox-events-collector">Dropbox Event Collector</a>: Use this integration to collect events from Dropbox logs. It contains commands such as <strong><code>dropbox-auth-start</code></strong> to initiate the authorization process, <strong><code>dropbox-auth-complete</code></strong> to finish authorization, <strong><code>dropbox-auth-test</code></strong> to check connectivity, <strong><code>dropbox-auth-reset</code></strong> to reset authentication, and <strong><code>dropbox-get-events</code></strong> to retrieve events.</li></ul> | +| Link to connector (onboarded after July 26, 2026) | [Dropbox](dropbox/dropbox) |
-
▸ ▾ Forcepoint DLP modified +1 −1 The table's first column header changed from "Forcepoint DLP vendor" to "Collection Method".
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/forcepoint/forcepoint-dlpRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@# Forcepoint DLP# Forcepoint DLPYou can configure collecting Corelight Zeek logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):You can configure collecting Corelight Zeek logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):Forcepoint DLP vendor│DescriptionCollection Method│Description| --------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || --------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Syslog Collector applet overview│If you use Forcepoint DLP to prevent data loss over endpoint channels, you can forward logs to Cortex XSIAM using the Broker VM Syslog Collector applet in a CEF or LEEF format.Syslog Collector applet overview│If you use Forcepoint DLP to prevent data loss over endpoint channels, you can forward logs to Cortex XSIAM using the Broker VM Syslog Collector applet in a CEF or LEEF format.Link to Syslog Collector applet instructions│Ingest logs from Forcepoint DLPLink to Syslog Collector applet instructions│Ingest logs from Forcepoint DLPLink to content pack/integration details (onboarded prior to July 26, 2026)│The Forcepoint DLP content pack fetches security incidents from Forcepoint DLP and ingests them as events into Cortex XSIAM for processing and analysis. contains the
Forcepoint DLP Modeling Rule, and theForcepoint DLP Parsing Rule. It also includes the following integration:- Forcepoint DLP Event Collector (Beta): Use this integration to fetch security incidents from Forcepoint DLP as Cortex XSIAM events. This integration is an event collector and utilizes parsing and modeling rules within the content pack for data normalization.
Link to content pack/integration details (onboarded prior to July 26, 2026)│The Forcepoint DLP content pack fetches security incidents from Forcepoint DLP and ingests them as events into Cortex XSIAM for processing and analysis. contains the
Forcepoint DLP Modeling Rule, and theForcepoint DLP Parsing Rule. It also includes the following integration:- Forcepoint DLP Event Collector (Beta): Use this integration to fetch security incidents from Forcepoint DLP as Cortex XSIAM events. This integration is an event collector and utilizes parsing and modeling rules within the content pack for data normalization.
Link to connector (onboarded after July 26, 2026)│ForcepointLink to connector (onboarded after July 26, 2026)│ForcepointShow markdown source
@@ -1,10 +1,10 @@ # Forcepoint DLP You can configure collecting Corelight Zeek logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026): -| Forcepoint DLP vendor | Description | +| Collection Method | Description | | --------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Syslog Collector applet overview | If you use Forcepoint DLP to prevent data loss over endpoint channels, you can forward logs to Cortex XSIAM using the Broker VM Syslog Collector applet in a CEF or LEEF format. | | Link to Syslog Collector applet instructions | [Ingest logs from Forcepoint DLP](../../generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/forcepoint-dlp/ingest-logs-from-forcepoint-dlp) | | Link to content pack/integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/ForcepointDLP">Forcepoint DLP</a> content pack fetches security incidents from Forcepoint DLP and ingests them as events into Cortex XSIAM for processing and analysis. contains the <strong><code>Forcepoint DLP Modeling Rule</code></strong>, and the <strong><code>Forcepoint DLP Parsing Rule</code></strong>. It also includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/forcepoint-dlp-event-collector">Forcepoint DLP Event Collector (Beta)</a>: Use this integration to fetch security incidents from Forcepoint DLP as Cortex XSIAM events. This integration is an event collector and utilizes parsing and modeling rules within the content pack for data normalization.</li></ul> | | Link to connector (onboarded after July 26, 2026) | [Forcepoint](forcepoint) |
-
▸ ▾ JumpCloud modified +1 −0
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/jumpcloud/jumpcloudRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -3,8 +3,9 @@The capabilities and sub-capabilities listed for this connector are available with any active Cortex XSIAM or Cortex Cloud Posture Security license.The capabilities and sub-capabilities listed for this connector are available with any active Cortex XSIAM or Cortex Cloud Posture Security license.This connector includes the following capabilities and sub-capabilities (if applicable):This connector includes the following capabilities and sub-capabilities (if applicable):• Security Posture: Detect, monitor and alert on settings of your SAAS application.• Security Posture: Detect, monitor and alert on settings of your SAAS application.• saas-posture-config-remediation: Help remediate the misconfigured security settings of your SAAS application.• saas-posture-config-remediation: Help remediate the misconfigured security settings of your SAAS application.To configure this connector, follow the steps outlined in the configuration wizard.To configure this connector, follow the steps outlined in the configuration wizard.Show markdown source
@@ -3,8 +3,9 @@ The capabilities and sub-capabilities listed for this connector are available with any active Cortex XSIAM or Cortex Cloud Posture Security license. This connector includes the following capabilities and sub-capabilities (if applicable): * Security Posture: Detect, monitor and alert on settings of your SAAS application. * saas-posture-config-remediation: Help remediate the misconfigured security settings of your SAAS application. To configure this connector, follow the steps outlined in the configuration wizard. +
-
▸ ▾ Ingest logs from Microsoft Azure Event Hub modified +48 −44 Notes became GitBook hint blocks and console names were bolded, but the diagnostic-settings steps are now mis-numbered.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-event-hub/ingest-logs-from-microsoft-azure-event-hubRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,11 +1,11 @@# Ingest logs from Microsoft Azure Event Hub# Ingest logs from Microsoft Azure Event HubCortex XSIAM can ingest different types of data from Microsoft Azure Event Hub using the Microsoft Azure Event Hub data collector. To receive logs from Azure Event Hub, you must configure the settings in Cortex XSIAM based on your Microsoft Azure Event Hub configuration. After you set up data collection, Cortex XSIAM begins receiving new logs and data from the source.Cortex XSIAM can ingest different types of data from Microsoft Azure Event Hub using the Microsoft Azure Event Hub data collector. To receive logs from Azure Event Hub, you must configure the settings in Cortex XSIAM based on your Microsoft Azure Event Hub configuration. After you set up data collection, Cortex XSIAM begins receiving new logs and data from the source.When Cortex XSIAM begins receiving logs, the app creates a new dataset (MSFT_Azure_raw) that you can use to initiate XQL Search queries. For example, queries refer to the in-app XQL Library. For enhanced cloud protection, you can also configure Cortex XSIAM to normalize Azure Event Hub audit logs, including Azure Kubernetes Service (AKS) audit logs, with other Cortex XSIAM authentication stories across all cloud providers using the same format, which you can query with XQL Search using thecloud_audit_logsdataset. For logs that you do not configure Cortex XSIAM to normalize, you can change the default dataset. Cortex XSIAM can also generate Cortex XSIAM issues (Analytics, IOC, BIOC, and Correlation Rules) when relevant from Azure Event Hub logs. While Correlation Rules issues are generated on non-normalized and normalized logs, Analytics, IOC, and BIOC issues are only raised on normalized logs.When Cortex XSIAM begins receiving logs, the app creates a new dataset (MSFT_Azure_raw) that you can use to initiate XQL Search queries. For example, queries refer to the in-app XQL Library. For enhanced cloud protection, you can also configure Cortex XSIAM to normalize Azure Event Hub audit logs, including Azure Kubernetes Service (AKS) audit logs, with other Cortex XSIAM authentication stories across all cloud providers using the same format, which you can query with XQL Search using thecloud_audit_logsdataset. For logs that you do not configure Cortex XSIAM to normalize, you can change the default dataset. Cortex XSIAM can also generate Cortex XSIAM issues (Analytics, IOC, BIOC, and Correlation Rules) when relevant from Azure Event Hub logs. While Correlation Rules issues are generated on non-normalized and normalized logs, Analytics, IOC, and BIOC issues are only raised on normalized logs.Enhanced cloud protection provides:Enhanced cloud protection provides:• Normalization of cloud logs• Normalization of cloud logs• Cloud logs stitching• Cloud logs stitching• Enrichment with cloud data• Enrichment with cloud data@@ -23,83 +23,87 @@ Enhanced cloud protection provides:The following table provides a brief description of the different types of Azure audit logs you can collect.The following table provides a brief description of the different types of Azure audit logs you can collect.hint infohint infoNoteNoteFor more information on Azure Event Hub audit logs, see Overview of Azure platform logs.For more information on Azure Event Hub audit logs, see Overview of Azure platform logs.endhintendhintType of data│DescriptionType of data│Description| -------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || -------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Activity logs│Retrieves events related to the operations on each Azure resource in the subscription from the outside in addition to updates on Service Health events.
Note:These logs are from the management plane.Activity logs│Retrieves events related to the operations on each Azure resource in the subscription from the outside in addition to updates on Service Health events.
Note
These logs are from the management plane.Microsoft Entra ID Activity logs and Microsoft Entra ID Sign-in logs│Contain the history of sign-in activity and audit trail of changes made in Microsoft Entra ID (formerly Azure AD) for a particular tenant. ### Note Even though you can collect Microsoft Entra ID Activity logs and Microsoft Entra ID Sign-in logs using the Azure Event Hub data collector, we recommend using the Microsoft Office 365 data collector, because it is easier to configure. In addition, ensure that you do not configure both collectors to collect the same types of logs, because if you do so, you will be creating duplicate data in Cortex XSIAM.
Note: Even though you can collect Microsoft Entra ID Activity logs and Microsoft Entra ID Sign-in logs using the Azure Event Hub data collector, we recommend using the Microsoft Office 365 data collector, because it is easier to configure. In addition, ensure that you do not configure both collectors to collect the same types of logs, because if you do so, you will be creating duplicate data in Cortex XSIAM.Microsoft Entra ID Activity logs and Microsoft Entra ID Sign-in logs│Contain the history of sign-in activity and audit trail of changes made in Microsoft Entra ID (formerly Azure AD) for a particular tenant.
Note
Even though you can collect Microsoft Entra ID Activity logs and Microsoft Entra ID Sign-in logs using the Azure Event Hub data collector, we recommend using the Microsoft Office 365 data collector, because it is easier to configure. Do not configure both collectors for the same log types. Doing so creates duplicate data in Cortex XSIAM.Resource logs, including AKS audit logs│Retrieves events related to operations that were performed within an Azure resource. Note: These logs are from the data plane.Resource logs, including AKS audit logs│Retrieves events related to operations that were performed within an Azure resource.
Note
These logs are from the data plane.hint infohint infoPrerequisitePrerequisiteEnsure that you do the following tasks before you begin configuring data collection from Azure Event Hub.Ensure that you do the following tasks before you begin configuring data collection from Azure Event Hub.• Before you set up an Azure Event Hub, calculate the quantity of data that you expect to send to Cortex XSIAM, taking into account potential data spikes and potential increases in data ingestion, because partitions cannot be modified after creation. Use this information to ascertain the optimal number of partitions and Throughput Units (for Azure Basic or Standard) or Processing Units (for Azure Premium). Configure your Event Hub accordingly.• Before you set up an Azure Event Hub, calculate the quantity of data that you expect to send to Cortex XSIAM, taking into account potential data spikes and potential increases in data ingestion, because partitions cannot be modified after creation. Use this information to ascertain the optimal number of partitions and Throughput Units (for Azure Basic or Standard) or Processing Units (for Azure Premium). Configure your Event Hub accordingly.• Create an Azure Event Hub. We recommend using a dedicated Azure Event Hub for this Cortex XSIAM integration. For more information, see Quickstart: Create an event hub using Azure portal.• Create an Azure Event Hub. We recommend using a dedicated Azure Event Hub for this Cortex XSIAM integration. For more information, see Quickstart: Create an event hub using Azure portal.• Each partition can support a throughput of up to 1 MB/s.• Each partition can support a throughput of up to 1 MB/s.• Ensure the format for the logs you want collected from the Azure Event Hub is either JSON or raw.• Ensure the format for the logs you want collected from the Azure Event Hub is either JSON or raw.endhintendhintConfigure the Azure Event Hub collection in Cortex XSIAM:Configure the Azure Event Hub collection in Cortex XSIAM:1. In the Microsoft Azure console, open the Event Hubs page, and select the Azure Event Hub that you created for collection in Cortex XSIAM.1. In the Microsoft Azure console, open the Event Hubs page, and select the Azure Event Hub that you created for collection in Cortex XSIAM.2. Record the following parameters from your configured event hub, which you will need when configuring data collection in Cortex XSIAM.2. Record the following parameters from your configured event hub, which you will need when configuring data collection in Cortex XSIAM.• Your event hub’s consumer group.• Your event hub’s consumer group.1. Select Entities → Event Hubs, and select your event hub.1. Select Entities → Event Hubs, and select your event hub.2. Select Entities → Consumer groups, and select your event hub.2. Select Entities → Consumer groups, and select your event hub.3. In the Consumer group table, copy the applicable value listed in the Name column for your Cortex XSIAM data collection configuration.3. In the Consumer group table, copy the applicable value listed in the Name column for your Cortex XSIAM data collection configuration.• Your event hub’s connection string for the designated policy.• Your event hub’s connection string for the designated policy.1. Select Settings → Shared access policies.1. Select Settings → Shared access policies.2. In the Shared access policies table, select the applicable policy.2. In the Shared access policies table, select the applicable policy.3. Copy the Connection string-primary key.3. Copy the Connection string-primary key.• Your storage account connection string required for partitions lease management and checkpointing in Cortex XSIAM.• Your storage account connection string required for partitions lease management and checkpointing in Cortex XSIAM.1. Open the Storage accounts page, and either create a new storage account or select an existing one, which will contain the storage account connection string.1. Open the Storage accounts page, and either create a new storage account or select an existing one, which will contain the storage account connection string.2. Select Security + networking → Access keys, and click Show keys.2. Select Security + networking → Access keys, and click Show keys.3. Copy the applicable Connection string.3. Copy the applicable Connection string.3. Configure diagnostic settings for the relevant log types you want to collect and then direct these diagnostic settings to the designated Azure Event Hub.3. Configure diagnostic settings for the relevant log types you want to collect and then direct these diagnostic settings to the designated Azure Event Hub.1. Open the Microsoft Azure console.2. Your navigation is dependent on the type of logs you want to configure.1. Open the Microsoft Azure console.2. Your navigation is dependent on the type of logs you want to configure.Log type│Navigation path| -------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Log type│Navigation pathActivity logs│Select Azure services → Activity log → Export Activity Logs, and +Add diagnostic setting.| -------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Microsoft Entra ID Activity logs and Microsoft Entra ID Sign-in logs│1. Select Azure services → Azure Active Directory.
2. Select Monitoring → Diagnostic settings, and +Add diagnostic setting.Activity logs│Select Azure services → Activity log → Export Activity Logs, and +Add diagnostic setting.Resource logs, including AKS audit logs│1. Search for Monitor, and select Settings → Diagnostic settings.
2. From your list of available resources, select the resource that you want to configure for log collection, and then select +Add diagnostic setting.
Note: For every resource that you want to confiure, you'll have to repeat this step, or use Azure policy for a general configuration.Microsoft Entra ID Activity logs and Microsoft Entra ID Sign-in logs│1. Select Azure services → Azure Active Directory.
2. Select Monitoring → Diagnostic settings, and +Add diagnostic setting.4. Set the following parameters:Resource logs, including AKS audit logs│1. Search for Monitor, and select Settings → Diagnostic settings.
2. From your list of available resources, select the resource that you want to configure for log collection, and then select +Add diagnostic setting.Note
For every resource that you want to configure, you'll have to repeat this step, or use Azure policy for a general configuration.
• Diagnostic setting name: Specify a name for your Diagnostic setting.• Logs Categories/Metrics: The options listed are dependent on the type of logs you want to configure. For Activity logs and Microsoft Entra ID logs and Microsoft Entra ID Sign-in logs, the option is called Logs Categories, and for Resource logs it's called Metrics.c. Set the following parameters:Log type│Log categories/metrics• Diagnostic setting name: Specify a name for your Diagnostic setting.| -------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |• Logs Categories/Metrics: The options listed are dependent on the type of logs you want to configure. For Activity logs and Microsoft Entra ID logs and Microsoft Entra ID Sign-in logs, the option is called Logs Categories, and for Resource logs it's called Metrics.Activity logs│Select from the list of applicable Activity log categories, the ones that you want to configure your designated resource to collect. We recommend selecting all of the options.
- Administrative
- Security
- ServiceHealth
- Alert
- Recommendation
- Policy
- Autoscale
- ResourceHealth
Microsoft Entra ID Activity logs and Microsoft Entra ID Sign-in logs│Select from the list of applicable Microsoft Entra ID Activity and Microsoft Entra ID Sign-in Logs Categories, the ones that you want to configure your designated resource to collect. You can select any of the following categories to collect these types of Microsoft Entra ID logs.Microsoft Entra ID Activity logs:
- AuditLogs
Microsoft Entra ID Sign-in logs:
- SignInLogs
- NonInteractiveUserSignInLogs
- ServicePrincipalSignInLogs
- ManagedIdentitySignInLogs
- ADFSSignInLogs
Note: There are additional log categories displayed. We recommend selecting all the available options.Log type│Log categories/metricsResource logs, including AKS audit logs│The list displayed is dependent on the resource that you selected. We recommend selecting all the options available for the resource.| -------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |• Destination details: Select Stream to event hub, where additional parameters are displayed that you need to configure. Ensure that you set the following parameters using the same settings for the Azure Event Hub that you created for the collection.Activity logs│Select from the list of applicable Activity log categories, the ones that you want to configure your designated resource to collect. We recommend selecting all of the options.
- Administrative
- Security
- ServiceHealth
- Alert
- Recommendation
- Policy
- Autoscale
- ResourceHealth
• Subscription: Select the applicable Subscription for the Azure Event Hub.Microsoft Entra ID Activity logs and Microsoft Entra ID Sign-in logs│Select from the list of applicable Microsoft Entra ID Activity and Microsoft Entra ID Sign-in Logs Categories, the ones that you want to configure your designated resource to collect. You can select any of the following categories to collect these types of Microsoft Entra ID logs.
Microsoft Entra ID Activity logs:
- AuditLogs
Microsoft Entra ID Sign-in logs:
- SignInLogs
- NonInteractiveUserSignInLogs
- ServicePrincipalSignInLogs
- ManagedIdentitySignInLogs
- ADFSSignInLogs
Note
There are additional log categories displayed. We recommend selecting all the available options.
• Event hub namespace: Select the applicable Subscription for the Azure Event Hub.Resource logs, including AKS audit logs│The list displayed is dependent on the resource that you selected. We recommend selecting all the options available for the resource.• (Optional) Event hub name: Specify the name of your Azure Event Hub.• Destination details: Select Stream to event hub, where additional parameters are displayed that you need to configure. Ensure that you set the following parameters using the same settings for the Azure Event Hub that you created for the collection.• Event hub policy: Select the applicable Event hub policy for your Azure Event Hub.• Subscription: Select the applicable Subscription for the Azure Event Hub.5. Save your settings.• Event hub namespace: Select the applicable Subscription for the Azure Event Hub.6. Configure the Azure Event Hub collection in Cortex XSIAM.• (Optional) Event hub name: Specify the name of your Azure Event Hub.1. Navigate to Settings → Data Sources & Integrations.• Event hub policy: Select the applicable Event hub policy for your Azure Event Hub.2. On the Data Sources & Integrations page, click + Add New, search for Azure Event Hub, then hover over it and click Add.d. Save your settings.4. Configure the Azure Event Hub collection in Cortex XSIAM.1. Navigate to Settings → Data Sources & Integrations.2. On the Data Sources & Integrations page, click + Add New, search for Azure Event Hub, then hover over it and click Add.3. Set these parameters:3. Set these parameters:• Name: Specify a descriptive name for your log collection configuration.• Name: Specify a descriptive name for your log collection configuration.• Event Hub Connection String: Specify your event hub’s connection string for the designated policy.• Event Hub Connection String: Specify your event hub’s connection string for the designated policy.• Storage Account Connection String: Specify your storage account’s connection string for the designated policy.• Storage Account Connection String: Specify your storage account’s connection string for the designated policy.• Consumer Group: Specify your event hub’s consumer group.• Consumer Group: Specify your event hub’s consumer group.• Log Format: Select the log format for the logs collected from the Azure Event Hub as Raw, JSON, CEF, LEEF, Cisco-asa, or Corelight.• Log Format: Select the log format for the logs collected from the Azure Event Hub as Raw, JSON, CEF, LEEF, Cisco-asa, or Corelight.**Note:** When you Normalize and enrich audit logs, the log format is automatically configured. As a result, the Log Format option is removed and is no longer available to configure (default).<div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>When you Normalize and enrich audit logs, the log format is automatically configured. As a result, the Log Format option is removed and is no longer available to configure (default).</p></div>• Vendor and Product: Specify the Vendor and Product for the type of logs you are ingesting. The Vendor and Product are used to define the name of your Cortex Query Language (XQL) dataset (<vendor>_<product>_raw). The Vendor and Product values vary depending on the Log Format selected. To uniquely identify the log source, consider changing the values if the values are configurable.• Vendor and Product: Specify the Vendor and Product for the type of logs you are ingesting. The Vendor and Product are used to define the name of your Cortex Query Language (XQL) dataset (<vendor>_<product>_raw). The Vendor and Product values vary depending on the Log Format selected. To uniquely identify the log source, consider changing the values if the values are configurable.**Note:** When you Normalize and enrich audit logs, the Vendor and Product fields are automatically configured, so these fields are removed as available options (default).<div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>When you Normalize and enrich audit logs, the Vendor and Product fields are automatically configured, so these fields are removed as available options (default).</p></div>• Normalize and enrich audit logs: (Optional) For enhanced cloud protection, you can Normalize and enrich audit logs by selecting the checkbox (default). If selected, Cortex XSIAM normalizes and enriches Azure Event Hub audit logs with other Cortex XSIAM authentication stories across all cloud providers using the same format. You can query this normalized data with XQL Search using thecloud_audit_logsdataset.• Normalize and enrich audit logs: (Optional) For enhanced cloud protection, you can Normalize and enrich audit logs by selecting the checkbox (default). If selected, Cortex XSIAM normalizes and enriches Azure Event Hub audit logs with other Cortex XSIAM authentication stories across all cloud providers using the same format. You can query this normalized data with XQL Search using thecloud_audit_logsdataset.4. Click Test to validate access, and then click Enable. When events start to come in, a green check mark appears underneath the Azure Event Hub configuration with the amount of data received.4. Click Test to validate access, and then click Enable. When events start to come in, a green check mark appears underneath the Azure Event Hub configuration with the amount of data received.Show markdown source
@@ -1,11 +1,11 @@ # Ingest logs from Microsoft Azure Event Hub -Cortex XSIAM can ingest different types of data from Microsoft Azure Event Hub using the Microsoft Azure Event Hub data collector. To receive logs from Azure Event Hub, you must configure the settings in Cortex XSIAM based on your Microsoft Azure Event Hub configuration. After you set up data collection, Cortex XSIAM begins receiving new logs and data from the source. +Cortex XSIAM can ingest different types of data from **Microsoft Azure Event Hub** using the Microsoft Azure Event Hub data collector. To receive logs from Azure Event Hub, you must configure the settings in Cortex XSIAM based on your Microsoft Azure Event Hub configuration. After you set up data collection, Cortex XSIAM begins receiving new logs and data from the source. When Cortex XSIAM begins receiving logs, the app creates a new dataset (`MSFT_Azure_raw`) that you can use to initiate XQL Search queries. For example, queries refer to the in-app XQL Library. For enhanced cloud protection, you can also configure Cortex XSIAM to normalize Azure Event Hub audit logs, including Azure Kubernetes Service (AKS) audit logs, with other Cortex XSIAM authentication stories across all cloud providers using the same format, which you can query with XQL Search using the `cloud_audit_logs` dataset. For logs that you do not configure Cortex XSIAM to normalize, you can change the default dataset. Cortex XSIAM can also generate Cortex XSIAM issues (Analytics, IOC, BIOC, and Correlation Rules) when relevant from Azure Event Hub logs. While Correlation Rules issues are generated on non-normalized and normalized logs, Analytics, IOC, and BIOC issues are only raised on normalized logs. Enhanced cloud protection provides: * Normalization of cloud logs * Cloud logs stitching * Enrichment with cloud data @@ -23,83 +23,87 @@ Enhanced cloud protection provides: The following table provides a brief description of the different types of Azure audit logs you can collect. {% hint style="info" %} **Note** For more information on Azure Event Hub audit logs, see [Overview of Azure platform logs](https://learn.microsoft.com/en-us/azure/azure-monitor/essentials/platform-logs-overview). {% endhint %} -| Type of data | Description | -| -------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Activity logs | <p>Retrieves events related to the operations on each Azure resource in the subscription from the outside in addition to updates on Service Health events.<br>Note:These logs are from the management plane.</p> | -| Microsoft Entra ID Activity logs and Microsoft Entra ID Sign-in logs | <p>Contain the history of sign-in activity and audit trail of changes made in Microsoft Entra ID (formerly Azure AD) for a particular tenant. ### Note Even though you can collect Microsoft Entra ID Activity logs and Microsoft Entra ID Sign-in logs using the Azure Event Hub data collector, we recommend using the Microsoft Office 365 data collector, because it is easier to configure. In addition, ensure that you do not configure both collectors to collect the same types of logs, because if you do so, you will be creating duplicate data in Cortex XSIAM.<br>Note: Even though you can collect Microsoft Entra ID Activity logs and Microsoft Entra ID Sign-in logs using the Azure Event Hub data collector, we recommend using the Microsoft Office 365 data collector, because it is easier to configure. In addition, ensure that you do not configure both collectors to collect the same types of logs, because if you do so, you will be creating duplicate data in Cortex XSIAM.</p> | -| Resource logs, including AKS audit logs | Retrieves events related to operations that were performed within an Azure resource. Note: These logs are from the data plane. | +| Type of data | Description | +| -------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| Activity logs | <p>Retrieves events related to the operations on each Azure resource in the subscription from the outside in addition to updates on Service Health events.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong><br><br>These logs are from the management plane.</p></div> | +| Microsoft Entra ID Activity logs and Microsoft Entra ID Sign-in logs | <p>Contain the history of sign-in activity and audit trail of changes made in Microsoft Entra ID (formerly Azure AD) for a particular tenant.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><br><strong>Note</strong><br><br>Even though you can collect Microsoft Entra ID Activity logs and Microsoft Entra ID Sign-in logs using the Azure Event Hub data collector, we recommend using the Microsoft Office 365 data collector, because it is easier to configure. Do not configure both collectors for the same log types. Doing so creates duplicate data in Cortex XSIAM.<br></p></div> | +| Resource logs, including AKS audit logs | <p>Retrieves events related to operations that were performed within an Azure resource.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong><br><br>These logs are from the data plane.</p></div> | {% hint style="info" %} **Prerequisite** Ensure that you do the following tasks before you begin configuring data collection from Azure Event Hub. * Before you set up an Azure Event Hub, calculate the quantity of data that you expect to send to Cortex XSIAM, taking into account potential data spikes and potential increases in data ingestion, because partitions cannot be modified after creation. Use this information to ascertain the optimal number of partitions and Throughput Units (for Azure Basic or Standard) or Processing Units (for Azure Premium). Configure your Event Hub accordingly. * Create an Azure Event Hub. We recommend using a dedicated Azure Event Hub for this Cortex XSIAM integration. For more information, see [Quickstart: Create an event hub using Azure portal](https://docs.microsoft.com/en-us/azure/event-hubs/event-hubs-create). * Each partition can support a throughput of up to 1 MB/s. * Ensure the format for the logs you want collected from the Azure Event Hub is either JSON or raw. {% endhint %} Configure the Azure Event Hub collection in Cortex XSIAM: -1. In the Microsoft Azure console, open the Event Hubs page, and select the Azure Event Hub that you created for collection in Cortex XSIAM. +1. In the Microsoft Azure console, open the **Event Hubs** page, and select the Azure Event Hub that you created for collection in Cortex XSIAM. 2. Record the following parameters from your configured event hub, which you will need when configuring data collection in Cortex XSIAM. * Your event hub’s consumer group. - 1. Select Entities → Event Hubs, and select your event hub. - 2. Select Entities → Consumer groups, and select your event hub. - 3. In the Consumer group table, copy the applicable value listed in the Name column for your Cortex XSIAM data collection configuration. + 1. Select **Entities** → **Event Hubs**, and select your event hub. + 2. Select **Entities** → **Consumer groups**, and select your event hub. + 3. In the Consumer group table, copy the applicable value listed in the **Name** column for your Cortex XSIAM data collection configuration. * Your event hub’s connection string for the designated policy. - 1. Select Settings → Shared access policies. + 1. Select **Settings** → **Shared access policies**. 2. In the Shared access policies table, select the applicable policy. 3. Copy the Connection string-primary key. * Your storage account connection string required for partitions lease management and checkpointing in Cortex XSIAM. - 1. Open the Storage accounts page, and either create a new storage account or select an existing one, which will contain the storage account connection string. - 2. Select Security + networking → Access keys, and click Show keys. - 3. Copy the applicable Connection string. - -3. Configure diagnostic settings for the relevant log types you want to collect and then direct these diagnostic settings to the designated Azure Event Hub. - 1. Open the Microsoft Azure console. - 2. Your navigation is dependent on the type of logs you want to configure. - - | Log type | Navigation path | - | -------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | - | Activity logs | Select Azure services → Activity log → Export Activity Logs, and +Add diagnostic setting. | - | Microsoft Entra ID Activity logs and Microsoft Entra ID Sign-in logs | <p>1. Select Azure services → Azure Active Directory.<br>2. Select Monitoring → Diagnostic settings, and +Add diagnostic setting.</p> | - | Resource logs, including AKS audit logs | <p>1. Search for Monitor, and select Settings → Diagnostic settings.<br>2. From your list of available resources, select the resource that you want to configure for log collection, and then select +Add diagnostic setting.<br><br><strong>Note:</strong> For every resource that you want to confiure, you'll have to repeat this step, or use <a href="https://learn.microsoft.com/en-us/azure/governance/policy/overview">Azure policy</a> for a general configuration.</p> | -4. Set the following parameters: - * **Diagnostic setting name:** Specify a name for your Diagnostic setting. - * **Logs Categories/Metrics:** The options listed are dependent on the type of logs you want to configure. For Activity logs and Microsoft Entra ID logs and Microsoft Entra ID Sign-in logs, the option is called Logs Categories, and for Resource logs it's called Metrics. - - | Log type | Log categories/metrics | - | -------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | - | Activity logs | <p>Select from the list of applicable Activity log categories, the ones that you want to configure your designated resource to collect. We recommend selecting all of the options.</p><ul><li>Administrative</li><li>Security</li><li>ServiceHealth</li><li>Alert</li><li>Recommendation</li><li>Policy</li><li>Autoscale</li><li>ResourceHealth</li></ul> | - | Microsoft Entra ID Activity logs and Microsoft Entra ID Sign-in logs | <p>Select from the list of applicable Microsoft Entra ID Activity and Microsoft Entra ID Sign-in Logs Categories, the ones that you want to configure your designated resource to collect. You can select any of the following categories to collect these types of Microsoft Entra ID logs.</p><ul><li><p>Microsoft Entra ID Activity logs:</p><ul><li>AuditLogs</li></ul></li><li><p>Microsoft Entra ID Sign-in logs:</p><ul><li>SignInLogs</li><li>NonInteractiveUserSignInLogs</li><li>ServicePrincipalSignInLogs</li><li>ManagedIdentitySignInLogs</li><li>ADFSSignInLogs</li></ul></li></ul><p><br><strong>Note:</strong> There are additional log categories displayed. We recommend selecting all the available options.</p> | - | Resource logs, including AKS audit logs | The list displayed is dependent on the resource that you selected. We recommend selecting all the options available for the resource. | - * **Destination details:** Select Stream to event hub, where additional parameters are displayed that you need to configure. Ensure that you set the following parameters using the same settings for the Azure Event Hub that you created for the collection. - * **Subscription:** Select the applicable Subscription for the Azure Event Hub. - * **Event hub namespace:** Select the applicable Subscription for the Azure Event Hub. - * **(Optional) Event hub name:** Specify the name of your Azure Event Hub. - * **Event hub policy:** Select the applicable Event hub policy for your Azure Event Hub. -5. Save your settings. -6. Configure the Azure Event Hub collection in Cortex XSIAM. - 1. Navigate to Settings → Data Sources & Integrations. - 2. On the Data Sources & Integrations page, click + Add New, search for Azure Event Hub, then hover over it and click Add. + 1. Open the **Storage accounts** page, and either create a new storage account or select an existing one, which will contain the storage account connection string. + 2. Select **Security + networking** → **Access keys**, and click **Show keys**. + 3. Copy the applicable **Connection string**. + +3. Configure diagnostic settings for the relevant log types you want to collect and then direct these diagnostic settings to the designated Azure Event Hub. + + 1. Open the Microsoft Azure console. + 2. Your navigation is dependent on the type of logs you want to configure. + + | Log type | Navigation path | + | -------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | + | Activity logs | Select **Azure services** → **Activity log** → **Export Activity Logs**, and **+Add diagnostic setting**. | + | Microsoft Entra ID Activity logs and Microsoft Entra ID Sign-in logs | <p>1. Select <strong>Azure services</strong> → <strong>Azure Active Directory</strong>.<br>2. Select <strong>Monitoring</strong> → <strong>Diagnostic settings</strong>, and <strong>+Add diagnostic setting</strong>.</p> | + | Resource logs, including AKS audit logs | <p>1. Search for <strong>Monitor</strong>, and select <strong>Settings</strong> → <strong>Diagnostic settings</strong>.<br>2. From your list of available resources, select the resource that you want to configure for log collection, and then select <strong>+Add diagnostic setting</strong>.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>For every resource that you want to configure, you'll have to repeat this step, or use <a href="https://learn.microsoft.com/en-us/azure/governance/policy/overview">Azure policy</a> for a general configuration.</p></div> | + + c. Set the following parameters: + + * **Diagnostic setting name:** Specify a name for your Diagnostic setting. + * **Logs Categories/Metrics:** The options listed are dependent on the type of logs you want to configure. For Activity logs and Microsoft Entra ID logs and Microsoft Entra ID Sign-in logs, the option is called **Logs Categories**, and for Resource logs it's called **Metrics**. + + | Log type | Log categories/metrics | + | -------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | + | Activity logs | <p>Select from the list of applicable Activity log categories, the ones that you want to configure your designated resource to collect. We recommend selecting all of the options.</p><ul><li>Administrative</li><li>Security</li><li>ServiceHealth</li><li>Alert</li><li>Recommendation</li><li>Policy</li><li>Autoscale</li><li>ResourceHealth</li></ul> | + | Microsoft Entra ID Activity logs and Microsoft Entra ID Sign-in logs | <p>Select from the list of applicable Microsoft Entra ID Activity and Microsoft Entra ID Sign-in <strong>Logs Categories</strong>, the ones that you want to configure your designated resource to collect. You can select any of the following categories to collect these types of Microsoft Entra ID logs.</p><ul><li><p>Microsoft Entra ID Activity logs:</p><ul><li><strong>AuditLogs</strong></li></ul></li><li><p>Microsoft Entra ID Sign-in logs:</p><ul><li><strong>SignInLogs</strong></li><li><strong>NonInteractiveUserSignInLogs</strong></li><li><strong>ServicePrincipalSignInLogs</strong></li><li><strong>ManagedIdentitySignInLogs</strong></li><li><strong>ADFSSignInLogs</strong></li></ul></li></ul><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>There are additional log categories displayed. We recommend selecting all the available options.</p></div> | + | Resource logs, including AKS audit logs | The list displayed is dependent on the resource that you selected. We recommend selecting all the options available for the resource. | + * **Destination details:** Select **Stream to event hub**, where additional parameters are displayed that you need to configure. Ensure that you set the following parameters using the same settings for the Azure Event Hub that you created for the collection. + * **Subscription:** Select the applicable **Subscription** for the Azure Event Hub. + * **Event hub namespace:** Select the applicable **Subscription** for the Azure Event Hub. + * **(Optional) Event hub name:** Specify the name of your Azure Event Hub. + * **Event hub policy:** Select the applicable **Event hub policy** for your Azure Event Hub. + + d. Save your settings. +4. Configure the Azure Event Hub collection in Cortex XSIAM. + 1. Navigate to **Settings** → **Data Sources & Integrations**. + 2. On the **Data Sources & Integrations** page, click **+ Add New**, search for **Azure Event Hub**, then hover over it and click **Add**. 3. Set these parameters: * **Name:** Specify a descriptive name for your log collection configuration. * **Event Hub Connection String:** Specify your event hub’s connection string for the designated policy. * **Storage Account Connection String:** Specify your storage account’s connection string for the designated policy. * **Consumer Group:** Specify your event hub’s consumer group. * **Log Format:** Select the log format for the logs collected from the Azure Event Hub as Raw, JSON, CEF, LEEF, Cisco-asa, or Corelight. - **Note:** When you Normalize and enrich audit logs, the log format is automatically configured. As a result, the Log Format option is removed and is no longer available to configure (default). + <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>When you Normalize and enrich audit logs, the log format is automatically configured. As a result, the Log Format option is removed and is no longer available to configure (default).</p></div> * **Vendor and Product:** Specify the Vendor and Product for the type of logs you are ingesting. The Vendor and Product are used to define the name of your Cortex Query Language (XQL) dataset (`<vendor>_<product>_raw`). The Vendor and Product values vary depending on the Log Format selected. To uniquely identify the log source, consider changing the values if the values are configurable. - **Note:** When you Normalize and enrich audit logs, the Vendor and Product fields are automatically configured, so these fields are removed as available options (default). + <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>When you Normalize and enrich audit logs, the Vendor and Product fields are automatically configured, so these fields are removed as available options (default).</p></div> * **Normalize and enrich audit logs:** (Optional) For enhanced cloud protection, you can Normalize and enrich audit logs by selecting the checkbox (default). If selected, Cortex XSIAM normalizes and enriches Azure Event Hub audit logs with other Cortex XSIAM authentication stories across all cloud providers using the same format. You can query this normalized data with XQL Search using the `cloud_audit_logs` dataset. 4. Click Test to validate access, and then click Enable. When events start to come in, a green check mark appears underneath the Azure Event Hub configuration with the amount of data received. -
▸ ▾ Ingest raw EDR events from Microsoft Defender for Endpoint modified +1 −1 The Enable access to required PANW resources prerequisite now uses a relative path instead of an opaque docs-cortex resource id.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-defender-for-endpoint-events/ingest-raw-edr-events-from-microsoft-defender-for-endpointRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -28,17 +28,17 @@ Ensure that you do the following tasks before you begin configuring data collect• Create an Azure Event Hub. For more information, see Quickstart: Create an event hub using Azure portal.• Create an Azure Event Hub. For more information, see Quickstart: Create an event hub using Azure portal.1. Create a resource group (optional if you already have a resource group configured).1. Create a resource group (optional if you already have a resource group configured).2. Create an Event Hubs namespace.2. Create an Event Hubs namespace.3. Create an event hub within the namespace. On the Settings → Networking page → Public Access tab, ensure that you add Palo Alto Networks IP addresses to the Firewall allow list. Set Exception to Yes.3. Create an event hub within the namespace. On the Settings → Networking page → Public Access tab, ensure that you add Palo Alto Networks IP addresses to the Firewall allow list. Set Exception to Yes.4. Ensure that you keep a copy of the Event Hub resource ID and the Event Hub name for use in the following procedures. To get your Event Hubs resource ID, go to your Azure Event Hub namespace page on Azure's Properties tab, and copy the text under Resource ID.4. Ensure that you keep a copy of the Event Hub resource ID and the Event Hub name for use in the following procedures. To get your Event Hubs resource ID, go to your Azure Event Hub namespace page on Azure's Properties tab, and copy the text under Resource ID.5. Create a storage account.5. Create a storage account.• Ensure that you have Microsoft Defender user credentials to sign in as a Security Administrator.• Ensure that you have Microsoft Defender user credentials to sign in as a Security Administrator.• Refer to this topic for additional information: Enable access to required PANW resources• Refer to this topic for additional information: Enable access to required PANW resourcesThe IP addresses that should be used are the ones under: **To Collect 3rd Party Data from Customer's SaaS and Cloud resources**.The IP addresses that should be used are the ones under: **To Collect 3rd Party Data from Customer's SaaS and Cloud resources**.• It might be necessary to set the firewall on the Event Hub, but it could also be necessary to configure it on the storage account firewall.• It might be necessary to set the firewall on the Event Hub, but it could also be necessary to configure it on the storage account firewall.1. Enable raw data streaming:1. Enable raw data streaming:1. Sign in to the Microsoft Defender portal as a Security Administrator.1. Sign in to the Microsoft Defender portal as a Security Administrator.2. Go to the data export settings page in the Microsoft Defender portal: System → Settings → Windows Defender XDR → Streaming API.2. Go to the data export settings page in the Microsoft Defender portal: System → Settings → Windows Defender XDR → Streaming API.Show markdown source
@@ -28,17 +28,17 @@ Ensure that you do the following tasks before you begin configuring data collect * Create an Azure Event Hub. For more information, see [Quickstart: Create an event hub using Azure portal](https://docs.microsoft.com/en-us/azure/event-hubs/event-hubs-create). 1. Create a resource group (optional if you already have a resource group configured). 2. Create an Event Hubs namespace. 3. Create an event hub within the namespace. On the Settings → Networking page → Public Access tab, ensure that you add Palo Alto Networks IP addresses to the Firewall allow list. Set Exception to Yes. 4. Ensure that you keep a copy of the Event Hub resource ID and the Event Hub name for use in the following procedures. To get your Event Hubs resource ID, go to your Azure Event Hub namespace page on Azure's Properties tab, and copy the text under Resource ID. 5. Create a storage account. * Ensure that you have Microsoft Defender user credentials to sign in as a Security Administrator. -* Refer to this topic for additional information: [Enable access to required PANW resources](https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/IWU8BPTfKWhw35rIRJGKbQ) +* Refer to this topic for additional information: [Enable access to required PANW resources](../../../../../onboard-cortex-xsiam/deployment-steps/activate-cortex-xsiam/enable-access-to-required-panw-resources) The IP addresses that should be used are the ones under: **To Collect 3rd Party Data from Customer's SaaS and Cloud resources**. * It might be necessary to set the firewall on the Event Hub, but it could also be necessary to configure it on the storage account firewall. 1. Enable raw data streaming: 1. Sign in to the Microsoft Defender portal as a Security Administrator. 2. Go to the data export settings page in the Microsoft Defender portal: System → Settings → Windows Defender XDR → Streaming API. -
▸ ▾ Ingest logs and data from Okta modified +6 −8
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/okta/ingest-logs-and-data-from-oktaRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -10,26 +10,26 @@ The options available in the UI depend on your specific product license:Collect Configuration│Enabled│Enabled│Enabled with Cloud Posture Security or Cloud Runtime Security add-on│Enabled with Cloud Posture Security or Cloud Runtime Security add-on│DisabledCollect Configuration│Enabled│Enabled│Enabled with Cloud Posture Security or Cloud Runtime Security add-on│Enabled with Cloud Posture Security or Cloud Runtime Security add-on│Disabledhint infohint infoPrerequisitePrerequisiteAdministrator privileges: Your Okta user must have a role capable of creating API tokens, such as Read-only Administrator, Super Administrator, or Organization Administrator. For more information, see the Okta Administrators Documentation.Administrator privileges: Your Okta user must have a role capable of creating API tokens, such as Read-only Administrator, Super Administrator, or Organization Administrator. For more information, see the Okta Administrators Documentation.endhintendhintTo receive logs and configuration data from Okta, configure the Data Sources & Integrations settings in Cortex XSIAM. Once enabled, the system immediately begins ingesting activity logs activity logs and identity configuration metadata, according to your configuration settings.To receive logs and configuration data from Okta, configure the Data Sources & Integrations settings in Cortex XSIAM. Once enabled, the system immediately begins ingesting activity logs activity logs and identity configuration metadata, according to your configuration settings.Activity logs are searchable in theokta_sso_rawdataset and normalized toxdr_dataorsaas_audit_logs.Activity logs are searchable in theokta_sso_rawdataset and normalized toxdr_dataorsaas_audit_logs.### API rate limits and monitoring### API rate limits and monitoringThe Okta API enforces concurrent rate limits. To prevent service disruption:The Okta API enforces concurrent rate limits. To prevent service disruption:• The Okta data collector includes a mechanism that automatically reduces the amount of requests whenever an error is received from the Okta API indicating that too many requests have already been sent.• The Okta data collector includes a mechanism that automatically reduces the amount of requests whenever an error is received from the Okta API indicating that too many requests have already been sent.• To ensure you are notified when this occurs, an alert is displayed in the Notification Area and a record is added to the Management Audit Logs.• To ensure you are notified when this occurs, an alert is displayed in the Notification Area and a record is added to the Management Audit Logs.### How to configure the Okta collection?### How to configure the Okta collection?#### Step 1: Configure Okta for integration#### Step 1: Configure Okta for integrationPerform these steps in your Okta Admin Console to prepare for the connection.Perform these steps in your Okta Admin Console to prepare for the connection.1. Identify your Okta Domain:1. Identify your Okta Domain:@@ -59,14 +59,12 @@ For more information, see the [Okta Documentation](https://developer.okta.com/do4. Collect Configuration: This option is disabled and can't be configured.4. Collect Configuration: This option is disabled and can't be configured.5. Test the connection.5. Test the connection.6. Click Enable.6. Click Enable.#### Step 3. Accessing the data#### Step 3. Accessing the dataData is routed differently depending on which collection option is enabled:Data is routed differently depending on which collection option is enabled:Activity Data (using Collect Logs)• Activity Data (using Collect Logs)• XQL: Searchable using theokta_sso_rawdataset.• XQL: Searchable using theokta_sso_rawdataset.• Normalization: Depending on the event type, data is normalized to eitherxdr_dataorsaas_audit_logsdatasets.• Normalization: Depending on the event type, data is normalized to eitherxdr_dataorsaas_audit_logsdatasets.• Configuration data (using Collect Configuration)Configuration data (using Collect Configuration)Show markdown source
@@ -10,26 +10,26 @@ The options available in the UI depend on your specific product license: | Collect Configuration | Enabled | Enabled | Enabled with Cloud Posture Security or Cloud Runtime Security add-on | Enabled with Cloud Posture Security or Cloud Runtime Security add-on | Disabled | {% hint style="info" %} **Prerequisite** **Administrator privileges**: Your Okta user must have a role capable of creating API tokens, such as Read-only Administrator, Super Administrator, or Organization Administrator. For more information, see the [Okta Administrators Documentation](https://help.okta.com/en-us/Content/Topics/Security/Administrators.htm?cshid=ext_Security_Administrators). {% endhint %} -To receive logs and configuration data from Okta, configure the Data Sources & Integrations settings in Cortex XSIAM. Once enabled, the system immediately begins ingesting activity logs activity logs and identity configuration metadata, according to your configuration settings. +To receive logs and configuration data from Okta, configure the **Data Sources & Integrations** settings in Cortex XSIAM. Once enabled, the system immediately begins ingesting activity logs activity logs and identity configuration metadata, according to your configuration settings. Activity logs are searchable in the `okta_sso_raw` dataset and normalized to `xdr_data` or `saas_audit_logs`. ### API rate limits and monitoring The Okta API enforces concurrent rate limits. To prevent service disruption: * The Okta data collector includes a mechanism that automatically reduces the amount of requests whenever an error is received from the Okta API indicating that too many requests have already been sent. -* To ensure you are notified when this occurs, an alert is displayed in the Notification Area and a record is added to the Management Audit Logs. +* To ensure you are notified when this occurs, an alert is displayed in the **Notification Area** and a record is added to the **Management Audit Logs**. ### How to configure the Okta collection? #### Step 1: Configure Okta for integration Perform these steps in your Okta Admin Console to prepare for the connection. 1. Identify your Okta Domain: @@ -59,14 +59,12 @@ For more information, see the [Okta Documentation](https://developer.okta.com/do 4. **Collect Configuration**: This option is disabled and can't be configured. 5. Test the connection. 6. Click **Enable**. #### Step 3. Accessing the data Data is routed differently depending on which collection option is enabled: -**Activity Data (using Collect Logs)** - -* **XQL**: Searchable using the `okta_sso_raw` dataset. -* **Normalization**: Depending on the event type, data is normalized to either `xdr_data` or `saas_audit_logs` datasets. - -**Configuration data (using Collect Configuration)** +* Activity Data (using **Collect Logs**) + * **XQL**: Searchable using the `okta_sso_raw` dataset. + * **Normalization**: Depending on the event type, data is normalized to either `xdr_data` or `saas_audit_logs` datasets. +* Configuration data (using **Collect Configuration**) -
▸ ▾ Ingest logs and data from OneLogin modified +2 −6
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/onelogin/ingest-logs-and-data-from-oneloginRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -34,22 +34,18 @@ Configure Cortex XSIAM to receive logs and data from OneLogin.• Domain: Specify the domain of the OneLogin instance. The domain name must be in the formathttps://<subdomain-name>.onelogin.com.• Domain: Specify the domain of the OneLogin instance. The domain name must be in the formathttps://<subdomain-name>.onelogin.com.• Name: Specify a descriptive and unique name for the configuration.• Name: Specify a descriptive and unique name for the configuration.• Client ID: Specify the Client ID for the OneLogin API credential pair.• Client ID: Specify the Client ID for the OneLogin API credential pair.• Secret: Specify the Client Secret for the OneLogin API credential pair.• Secret: Specify the Client Secret for the OneLogin API credential pair.• Collect: Select the types of data to collect. By default, all the options are selected.• Collect: Select the types of data to collect. By default, all the options are selected.• Log Collection• Log Collection• Events: Retrieves user logins, administrative operations, provisioning, and OneLogin event types. After normalization, the event types are enriched with the event name and description.• Events: Retrieves user logins, administrative operations, provisioning, and OneLogin event types. After normalization, the event types are enriched with the event name and description.> **Note**<div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Event data is collected every 30 seconds.</p></div>>> Event data is collected every 30 seconds.• Directory• Directory• Users: Retrieves lists of users.• Users: Retrieves lists of users.• Groups: Retrieves lists of groups.• Groups: Retrieves lists of groups.• Apps: Retrieves lists of apps.• Apps: Retrieves lists of apps.> **Note**<div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Inventory data snapshots are collected every 10 minutes.</p></div>>> Inventory data snapshots are collected every 10 minutes.7. Test the connection settings. If successful, Enable the OneLogin log collection.7. Test the connection settings. If successful, Enable the OneLogin log collection.When events start to come in, a green check mark appears underneath the OneLogin configuration.When events start to come in, a green check mark appears underneath the OneLogin configuration.Show markdown source
@@ -34,22 +34,18 @@ Configure Cortex XSIAM to receive logs and data from OneLogin. * **Domain**: Specify the domain of the OneLogin instance. The domain name must be in the format `https://<subdomain-name>.onelogin.com`. * **Name**: Specify a descriptive and unique name for the configuration. * **Client ID**: Specify the Client ID for the OneLogin API credential pair. * **Secret**: Specify the Client Secret for the OneLogin API credential pair. * **Collect**: Select the types of data to collect. By default, all the options are selected. * **Log Collection** * **Events**: Retrieves user logins, administrative operations, provisioning, and OneLogin event types. After normalization, the event types are enriched with the event name and description. - > **Note** - > - > Event data is collected every 30 seconds. + <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Event data is collected every 30 seconds.</p></div> * **Directory** * **Users**: Retrieves lists of users. * **Groups**: Retrieves lists of groups. * **Apps**: Retrieves lists of apps. - > **Note** - > - > Inventory data snapshots are collected every 10 minutes. + <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Inventory data snapshots are collected every 10 minutes.</p></div> 7. Test the connection settings. If successful, **Enable** the OneLogin log collection. When events start to come in, a green check mark appears underneath the OneLogin configuration. -
▸ ▾ Workday modified +6 −5 Gains a row describing the Workday content pack for tenants onboarded before July 26, 2026.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/workdayRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,11 @@# Workday# WorkdayYou can configure collecting Workday report data using a standard collector, content pack integration (onboarded prior to July 26, 2026), or connector:You can configure collecting Workday report data using a standard collector, content pack integration (onboarded prior to July 26, 2026), or connector:Workday vendor│DescriptionWorkday vendor│Description| --------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ---------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Standard collector overview│Forward Workday report data to Cortex XSIAM using the Workday data source.Standard collector overview│Forward Workday report data to Cortex XSIAM using the Workday data source.Link to standard collector instructions│Ingest report data from WorkdayLink to standard collector instructions│Ingest report data from WorkdayLink to connector│- Workday Automation and Collection (onboarded after July 26, 2026)
- Workday
Links to content pack/integration details (onboarded prior to July 26, 2026)│The Workday content pack provides solutions for financial management, human resources, and planning, specifically supporting the collection and modeling of user activity audit logs and sign-on events. It contains classifiers, modeling rules, and parsing rules, as well as the following integrations:
- Workday Event Collector: Use this integration containing the
workday-get-activity-loggingcommand to get activity logs from Workday. It requires theWorkday Parsing RuleandWorkday Modeling Rulefor parsing and modeling ingested data. - Workday: Use this integration containing the
workday-list-workerscommand to return information for specific workers. - Workday IAM: Use this integration containing the
workday-iam-get-full-reportcommand to return report entries from Workday. It is part of the part of the IAM premium pack. - Workday Sign On Event Collector: Use this integration containing the
workday-get-sign-on-eventscommand to get sign-on logs from Workday. This command is used for developing/debugging and is to be used with caution, as it can create events, leading to events duplication and exceeding the API request limitation.
Link to connector│- Workday Automation and Collection (onboarded after July 26, 2026)
- Workday
Show markdown source
@@ -1,10 +1,11 @@ # Workday You can configure collecting Workday report data using a standard collector, content pack integration (onboarded prior to July 26, 2026), or connector: -| Workday vendor | Description | -| --------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Standard collector overview | Forward Workday report data to Cortex XSIAM using the Workday data source. | -| Link to standard collector instructions | [Ingest report data from Workday](workday/ingest-report-data-from-workday) | -| Link to connector | <ul><li><a href="workday/workday-automation-and-collection">Workday Automation and Collection</a> (onboarded after July 26, 2026)</li><li><a href="workday/workday">Workday</a></li></ul> | +| Workday vendor | Description | +| ---------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| Standard collector overview | Forward Workday report data to Cortex XSIAM using the Workday data source. | +| Link to standard collector instructions | [Ingest report data from Workday](workday/ingest-report-data-from-workday) | +| Links to content pack/integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/Workday">Workday</a> content pack provides solutions for financial management, human resources, and planning, specifically supporting the collection and modeling of user activity audit logs and sign-on events. It contains classifiers, modeling rules, and parsing rules, as well as the following integrations:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/workday-event-collector">Workday Event Collector</a>: Use this integration containing the <strong><code>workday-get-activity-logging</code></strong> command to get activity logs from Workday. It requires the <strong><code>Workday Parsing Rule</code></strong> and <strong><code>Workday Modeling Rule</code></strong> for parsing and modeling ingested data.</li><li><a href="https://xsoar.pan.dev/docs/reference/integrations/workday">Workday</a>: Use this integration containing the <strong><code>workday-list-workers</code></strong> command to return information for specific workers.</li><li><a href="https://xsoar.pan.dev/docs/reference/integrations/workday-iam">Workday IAM</a>: Use this integration containing the <strong><code>workday-iam-get-full-report</code></strong> command to return report entries from Workday. It is part of the part of the IAM premium pack.</li><li><a href="https://xsoar.pan.dev/docs/reference/integrations/workday-sign-on-event-collector">Workday Sign On Event Collector</a>: Use this integration containing the <strong><code>workday-get-sign-on-events</code></strong> command to get sign-on logs from Workday. This command is used for developing/debugging and is to be used with caution, as it can create events, leading to events duplication and exceeding the API request limitation.</li></ul> | +| Link to connector | <ul><li><a href="workday/workday-automation-and-collection">Workday Automation and Collection</a> (onboarded after July 26, 2026)</li><li><a href="workday/workday">Workday</a></li></ul> |
-
▸ ▾ Zscaler Internet Access modified +6 −6
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/zscaler/zscaler-internet-accessRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,11 +1,11 @@# Zscaler Internet Access# Zscaler Internet AccessYou can configure collecting Zscaler Internet Access logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):You can configure collecting Zscaler Internet Access logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):Zscaler Internet Access vendor│DescriptionZscaler Internet Access vendor│Description| ---------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ || ---------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Syslog Collector applet overview│Forward firewall and network logs to Cortex XSIAM from Zscaler Internet Access using the Broker VM Syslog Collector applet in a CEF format.Syslog Collector applet overview│Forward firewall and network logs to Cortex XSIAM from Zscaler Internet Access using the Broker VM Syslog Collector applet in a CEF format.Link to Syslog Collector applet instructions│Ingest logs from Zscaler Internet AccessLink to Syslog Collector applet instructions│Ingest logs from Zscaler Internet AccessLinks to content pack/integration details (onboarded prior to July 26, 2026)│The Zscaler Internet Access content pack provides Cloud security features, including managing URL and IP address policies, managing categories, sandbox reporting, and ingestion and normalization of Zscaler Internet Access (ZIA) logs into Cortex XSIAM via both VM-based NSS Feed and Cloud NSS Feed methods. It contains the
Zscaler Internet Access Modeling Rule, theZscaler ZIA Parsing Rule, and the Block Domain - Zscaler playbook. It also includes the following integration:- Zscaler Internet Access: Use this integration to manage URL and IP address allow lists and block lists, manage and update categories, retrieve Sandbox reports, and manage IP destination groups within a Zscaler session. It includes commands for blacklisting and unblacklisting URLs and IPs, managing categories (adding/removing URLs and IPs), retrieving categories, listing, creating, editing, and deleting IP destination groups, manually logging in and logging out, and activating configuration changes in Zscaler.
Links to content pack/integration details (onboarded prior to July 26, 2026)│The Zscaler Internet Access content pack provides Cloud security features, including managing URL and IP address policies, managing categories, sandbox reporting, and ingestion and normalization of Zscaler Internet Access (ZIA) logs into Cortex XSIAM via both VM-based NSS Feed and Cloud NSS Feed methods. It contains the
Zscaler Internet Access Modeling Rule, theZscaler ZIA Parsing Rule, and the Block Domain - Zscaler playbook. It also includes the following integration:- Zscaler Internet Access: Use this integration to manage URL and IP address allow lists and block lists, manage and update categories, retrieve Sandbox reports, and manage IP destination groups within a Zscaler session. It includes commands for blacklisting and unblacklisting URLs and IPs, managing categories (adding/removing URLs and IPs), retrieving categories, listing, creating, editing, and deleting IP destination groups, manually logging in and logging out, and activating configuration changes in Zscaler.
Link to connector (onboarded after July 26, 2026)│ZscalerLink to connector (onboarded after July 26, 2026)│ZscalerShow markdown source
@@ -1,11 +1,11 @@ # Zscaler Internet Access You can configure collecting Zscaler Internet Access logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026): -| Zscaler Internet Access vendor | Description | -| ---------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -| Syslog Collector applet overview | Forward firewall and network logs to Cortex XSIAM from Zscaler Internet Access using the Broker VM Syslog Collector applet in a CEF format. | -| Link to Syslog Collector applet instructions | [Ingest logs from Zscaler Internet Access](../../generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/zscaler-internet-access/ingest-logs-from-zscaler-internet-access) | -| Links to content pack/integration details (onboarded prior to July 26, 2026) | <p></p><p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/Zscaler">Zscaler Internet Access</a> content pack provides Cloud security features, including managing URL and IP address policies, managing categories, sandbox reporting, and ingestion and normalization of Zscaler Internet Access (ZIA) logs into Cortex XSIAM via both VM-based NSS Feed and Cloud NSS Feed methods. It contains the <strong><code>Zscaler Internet Access Modeling Rule</code></strong>, the <strong><code>Zscaler ZIA Parsing Rule</code></strong>, and the Block Domain - Zscaler playbook. It also includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/zscaler">Zscaler Internet Access</a>: Use this integration to manage URL and IP address allow lists and block lists, manage and update categories, retrieve Sandbox reports, and manage IP destination groups within a Zscaler session. It includes commands for blacklisting and unblacklisting URLs and IPs, managing categories (adding/removing URLs and IPs), retrieving categories, listing, creating, editing, and deleting IP destination groups, manually logging in and logging out, and activating configuration changes in Zscaler.</li></ul> | -| Link to connector (onboarded after July 26, 2026) | [Zscaler](zscaler) | +| Zscaler Internet Access vendor | Description | +| ---------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| Syslog Collector applet overview | Forward firewall and network logs to Cortex XSIAM from Zscaler Internet Access using the Broker VM Syslog Collector applet in a CEF format. | +| Link to Syslog Collector applet instructions | [Ingest logs from Zscaler Internet Access](../../generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/zscaler-internet-access/ingest-logs-from-zscaler-internet-access) | +| Links to content pack/integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/Zscaler">Zscaler Internet Access</a> content pack provides Cloud security features, including managing URL and IP address policies, managing categories, sandbox reporting, and ingestion and normalization of Zscaler Internet Access (ZIA) logs into Cortex XSIAM via both VM-based NSS Feed and Cloud NSS Feed methods. It contains the <strong><code>Zscaler Internet Access Modeling Rule</code></strong>, the <strong><code>Zscaler ZIA Parsing Rule</code></strong>, and the Block Domain - Zscaler playbook. It also includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/zscaler">Zscaler Internet Access</a>: Use this integration to manage URL and IP address allow lists and block lists, manage and update categories, retrieve Sandbox reports, and manage IP destination groups within a Zscaler session. It includes commands for blacklisting and unblacklisting URLs and IPs, managing categories (adding/removing URLs and IPs), retrieving categories, listing, creating, editing, and deleting IP destination groups, manually logging in and logging out, and activating configuration changes in Zscaler.</li></ul> | +| Link to connector (onboarded after July 26, 2026) | [Zscaler](zscaler) |
-
▸ ▾ Cortex Network Scanner modified +3 −3 FedRAMP support reversed to supported in both notices, and Policy Audit Scan now also covers Debian and Ubuntu alongside the CIS Windows benchmarks.
xsiam/detect-investigate-and-respond-to-threats/exposure-management/cortex-network-scannerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -64,17 +64,17 @@ Network vulnerability scanning is a resource-intensive task. To ensure optimal aWe recommend deploying a dedicated Broker VM for the Cortex Network Scanner with no other applets running, though this is not a strict technical limitation. If you plan to run other applets on the same Broker VM alongside the scanner, we recommend configuring the VM with more than 16 GB of RAM.We recommend deploying a dedicated Broker VM for the Cortex Network Scanner with no other applets running, though this is not a strict technical limitation. If you plan to run other applets on the same Broker VM alongside the scanner, we recommend configuring the VM with more than 16 GB of RAM.hint infohint info### Note### NoteThe Cortex Network Scanner applet is not supported in High Availability (HA) cluster configurations.The Cortex Network Scanner applet is not supported in High Availability (HA) cluster configurations.The Cortex Network Scanner applet is not supported for FedRAMP customers.The Cortex Network Scanner applet is supported for FedRAMP customers.endhintendhint#### Firewall and other security control recommendations#### Firewall and other security control recommendationsThe Cortex Network Scanner uses various methods to actively detect, probe and assess detected services on all or most TCP and UDP ports. The nature of vulnerability scanning conflicts with security controls such as firewalls and IPS that are meant to block such activity. When deploying Broker VMs that run the Cortex Network Scanner (further - Scanners), we recommend taking one or both of the following actions:The Cortex Network Scanner uses various methods to actively detect, probe and assess detected services on all or most TCP and UDP ports. The nature of vulnerability scanning conflicts with security controls such as firewalls and IPS that are meant to block such activity. When deploying Broker VMs that run the Cortex Network Scanner (further - Scanners), we recommend taking one or both of the following actions:• [Recommended] Deploy scanners strategically within each target security zone or segment (e.g., firewall-configured segments). This ensures scanner traffic remains local to the segment and avoids crossing the firewall or other network security device.• [Recommended] Deploy scanners strategically within each target security zone or segment (e.g., firewall-configured segments). This ensures scanner traffic remains local to the segment and avoids crossing the firewall or other network security device.• Configure security policy rules on the firewall and other network security controls that prevent the blocking of traffic from Cortex Network Scanner. Follow the guidelines for your security controls and keep rules as narrow as possible. For Palo Alto Networks NGFW, you must allow traffic from the scanner to the target, using “Application”(App-ID) and “Service” (port) set to “any”.• Configure security policy rules on the firewall and other network security controls that prevent the blocking of traffic from Cortex Network Scanner. Follow the guidelines for your security controls and keep rules as narrow as possible. For Palo Alto Networks NGFW, you must allow traffic from the scanner to the target, using “Application”(App-ID) and “Service” (port) set to “any”.@@ -128,17 +128,17 @@ Cortex Network Scanner is installed as an applet on a Broker VM.### Notice### NoticeThis feature is included with a Cortex XSIAM Premium license. It is also included with an active Cortex XSIAM NG SIEM and Cortex XSIAM Enterprise license that has the Exposure Management add-on.This feature is included with a Cortex XSIAM Premium license. It is also included with an active Cortex XSIAM NG SIEM and Cortex XSIAM Enterprise license that has the Exposure Management add-on.endhintendhinthint infohint info### Important### ImportantThe Cortex Network Scanner applet is not supported for FedRAMP customers.The Cortex Network Scanner applet is supported for FedRAMP customers.Cortex Network Scanner does not support high availability (HA) Broker VM configuration.Cortex Network Scanner does not support high availability (HA) Broker VM configuration.endhintendhinthint warninghint warning### Prerequisites### Prerequisites• Review the Cortex Network Scanner deployment recommendations and complete any prerequisites.• Review the Cortex Network Scanner deployment recommendations and complete any prerequisites.@@ -350,17 +350,17 @@ Cortex XSIAM uses the Network Scanner to identify active hosts, services, and vu• Credentials: Save SSH (Unix) or SMB (Windows) credentials in Settings+Configurations+General+Credentials.• Credentials: Save SSH (Unix) or SMB (Windows) credentials in Settings+Configurations+General+Credentials.2. Scan Creation Wizard2. Scan Creation WizardTo begin, navigate to Modules+Vulnerability & Exposure Management+Scan Management and click **+ Create Scan**. Select a template based on your objective:To begin, navigate to Modules+Vulnerability & Exposure Management+Scan Management and click **+ Create Scan**. Select a template based on your objective:• Discovery Scan: Identifies active hosts and gathers high-level OS information.• Discovery Scan: Identifies active hosts and gathers high-level OS information.• Vulnerability Scan: Performs deep inspection of services to identify known CVEs and security weaknesses.• Vulnerability Scan: Performs deep inspection of services to identify known CVEs and security weaknesses.• Focused Vulnerability Scan: Targets specific vulnerabilities, including emerging threats and zero-day vulnerabilities (ideal for verifying patches or high-priority CVEs).• Focused Vulnerability Scan: Targets specific vulnerabilities, including emerging threats and zero-day vulnerabilities (ideal for verifying patches or high-priority CVEs).• Policy Audit Scan: Helps you check if a specified Asset Group is in compliance with selected policies and standards. CIS Microsoft Windows 11 Enterprise Benchmark and CIS Microsoft Windows Server 2022 Benchmark are currently supported• Policy Audit Scan: Helps you check if a specified Asset Group is in compliance with selected policies and standards. CIS Microsoft Windows 11 Enterprise Benchmark, Microsoft Windows Server 2022 Benchmark, Debian, and Ubuntu are currently supported1. General Configuration1. General ConfigurationConfigure the basic identity and timing for the scan:Configure the basic identity and timing for the scan:• Name & Description: Provide a unique identifier and optional context.• Name & Description: Provide a unique identifier and optional context.• Scan Scheduling:• Scan Scheduling:• Create and save the scan configuration. To launch a scan, right click on the configured scan and select Launch Scan.• Create and save the scan configuration. To launch a scan, right click on the configured scan and select Launch Scan.Show markdown source
@@ -64,17 +64,17 @@ Network vulnerability scanning is a resource-intensive task. To ensure optimal a We recommend deploying a dedicated Broker VM for the Cortex Network Scanner with no other applets running, though this is not a strict technical limitation. If you plan to run other applets on the same Broker VM alongside the scanner, we recommend configuring the VM with more than 16 GB of RAM. {% hint style="info" %} ### Note The Cortex Network Scanner applet is not supported in High Availability (HA) cluster configurations. -The Cortex Network Scanner applet is not supported for FedRAMP customers. +The Cortex Network Scanner applet is supported for FedRAMP customers. {% endhint %} #### **Firewall and other security control recommendations** The Cortex Network Scanner uses various methods to actively detect, probe and assess detected services on all or most TCP and UDP ports. The nature of vulnerability scanning conflicts with security controls such as firewalls and IPS that are meant to block such activity. When deploying Broker VMs that run the Cortex Network Scanner (further - Scanners), we recommend taking one or both of the following actions: * \[Recommended] Deploy scanners strategically within each target security zone or segment (e.g., firewall-configured segments). This ensures scanner traffic remains local to the segment and avoids crossing the firewall or other network security device. * Configure security policy rules on the firewall and other network security controls that prevent the blocking of traffic from Cortex Network Scanner. Follow the guidelines for your security controls and keep rules as narrow as possible. For Palo Alto Networks NGFW, you must allow traffic from the scanner to the target, using “`Application”` (App-ID) and “`Service`” (port) set to “`any`”. @@ -128,17 +128,17 @@ Cortex Network Scanner is installed as an applet on a Broker VM. ### Notice This feature is included with a Cortex XSIAM Premium license. It is also included with an active Cortex XSIAM NG SIEM and Cortex XSIAM Enterprise license that has the Exposure Management add-on. {% endhint %} {% hint style="info" %} ### Important -The Cortex Network Scanner applet is not supported for FedRAMP customers. +The Cortex Network Scanner applet is supported for FedRAMP customers. Cortex Network Scanner does not support high availability (HA) Broker VM configuration. {% endhint %} {% hint style="warning" %} ### Prerequisites * Review the Cortex Network Scanner [deployment recommendations](#deployment-recommendations) and complete any prerequisites. @@ -350,17 +350,17 @@ Cortex XSIAM uses the Network Scanner to identify active hosts, services, and vu * Credentials: Save SSH (Unix) or SMB (Windows) credentials in Settings+Configurations+General+Credentials. 2. **Scan Creation Wizard** To begin, navigate to Modules+Vulnerability & Exposure Management+Scan Management and click **+ Create Scan**. Select a template based on your objective: * **Discovery Scan**: Identifies active hosts and gathers high-level OS information. * **Vulnerability Scan**: Performs deep inspection of services to identify known CVEs and security weaknesses. * **Focused Vulnerability Scan**: Targets specific vulnerabilities, including emerging threats and zero-day vulnerabilities (ideal for verifying patches or high-priority CVEs). - * **Policy Audit Scan**: Helps you check if a specified Asset Group is in compliance with selected policies and standards. CIS Microsoft Windows 11 Enterprise Benchmark and CIS Microsoft Windows Server 2022 Benchmark are currently supported + * **Policy Audit Scan**: Helps you check if a specified Asset Group is in compliance with selected policies and standards. CIS Microsoft Windows 11 Enterprise Benchmark, Microsoft Windows Server 2022 Benchmark, Debian, and Ubuntu are currently supported 1. **General Configuration** Configure the basic identity and timing for the scan: * **Name & Description**: Provide a unique identifier and optional context. * **Scan Scheduling**: * Create and save the scan configuration. To launch a scan, right click on the configured scan and select **Launch Scan**. -
▸ ▾ Enable access to required PANW resources modified +2 −40 The full FQDN, IP and App-ID allowlist table was re-emitted as one HTML table; no FQDN or port was added or removed.
xsiam/onboard-cortex-xsiam/deployment-steps/activate-cortex-xsiam/enable-access-to-required-panw-resourcesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -17,48 +17,10 @@ Before configuring your firewall, review these guidelines:hint infohint info### Note### Note<tenant-name>refers to the selected subdomain of your Cortex XSIAM tenant, and<region>is the region in which your tenant is deployed. For more information, see Cortex XSIAM supported regions.<tenant-name>refers to the selected subdomain of your Cortex XSIAM tenant, and<region>is the region in which your tenant is deployed. For more information, see Cortex XSIAM supported regions.endhintendhintThe following tables list required FQDNs, IP addresses, ports, and App-ID coverage for your deployment.The following tables list required FQDNs, IP addresses, ports, and App-ID coverage for your deployment.FQDN│IP Addresses and Port│App-ID Coverage| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Egress││<tenant-name>.xdr.<region>.paloaltonetworks.comUsed to connect to the Cortex XSIAM tenant.
│IP address by region:
- US (United States): 35.244.250.18:443
- EU (Europe): 35.227.237.180:443
- CA (Canada): 34.120.31.199:443
- UK (United Kingdom): 34.120.87.77:443
- JP (Japan): 35.241.28.254:443
- SG (Singapore): 34.117.211.129:443
- AU (Australia): 34.120.229.65:443
- DE (Germany): 34.98.68.183:443
- IN (India): 35.186.207.80:443
- DL (Delhi): 34.8.67.192:443
- CH (Switzerland): 34.111.6.153:443
- PL (Poland): 34.117.240.208:443
- TW (Taiwan): 34.160.28.41:443
- QT (Qatar): 35.190.0.180:443
- FA (France): 34.111.134.57:443
- IL (Israel): 34.111.129.144:443
- SA (Saudi Arabia): 35.244.157.127:443
- ID (Indonesia): 34.111.58.152:443
- ES (Spain): 34.111.188.248:443
- IT (Italy): 34.8.224.70:443
- KR (South Korea): 34.54.5.247:443
- ZA (South Africa): 34.149.165.12:443
- BR (Brazil): 34.96.83.202:443
cortex-xdrdistributions.traps.paloaltonetworks.comUsed for the first request in registration flow where the agent passes the distribution id and obtains the
│ch-<tenant-name>.traps.paloaltonetworks.comof its tenant.- IP address: 35.223.6.69
- Port: 443
traps-management-servicehttps://lrc-<region>.paloaltonetworks.comwss://lrc-<region>.paloaltonetworks.comUsed in live terminal flow.
│IP address by region:
- US (United States): 35.190.88.43:443
- EU (Europe): 35.244.251.25:443
- CA (Canada): 35.203.99.74:443
- UK (United Kingdom): 35.242.159.176:443
- JP (Japan): 34.84.201.32:443
- SG (Singapore): 34.87.61.186:443
- AU (Australia): 35.244.66.177:443
- DE (Germany): 34.107.61.141:443
- IN (India): 35.200.146.253:443
- DL (Delhi): 34.131.116.135:443
- CH (Switzerland): 34.65.213.226:443
- PL (Poland): 34.118.62.80:443
- TW (Taiwan): 34.80.34.30:443
- QT (Qatar): 34.18.34.73:443
- FA (France): 34.163.57.57:443
- IL (Israel): 34.165.43.106:443
- SA (Saudi Arabia): 34.166.54.6:443
- ID (Indonesia): 34.101.214.157:443
- ES (Spain): 34.175.18.78:443
- IT (Italy): 34.154.154.5:443
- KR (South Korea): 34.22.66.91:443
- ZA (South Africa): 34.35.56.170:443
- BR (Brazil): 34.151.236.197:443
cortex-xdrpanw-xdr-installers-prod-us.storage.googleapis.comUsed to download installers for upgrade actions from the server.
This storage bucket is used for all regions.
│- IP ranges in GCP
- Port: 443
cortex-xdrpanw-xdr-payloads-prod-us.storage.googleapis.comUsed to download the executable for the live terminal for XDR agents earlier than version 7.1.0.
This storage bucket is used for all regions.
│- IP ranges in GCP
- Port: 443
cortex-xdrglobal-content-profiles-policy.storage.googleapis.comUsed to download content updates.
│- IP ranges in GCP
- Port: 443
cortex-xdrpanw-xdr-evr-prod-<region>.storage.googleapis.comUsed to download extended verdict request results in scanning.
│- IP ranges in GCP
- Port: 443
cortex-xdrhttps://<region>-docker.pkg.devUsed to download the Kubernetes image from the registry for Kubernetes agents installation.
Refer to Regional Docker registry mapping for your specific tenant location and corresponding Docker registry URL.
│- IP ranges in GCP
- Port: 443
Regional Docker registry mapping││Tenant location│GCP region│Registry URLUKNetherlands (EU)
United States (US)
Canada (CA)
South Korea (KR)
Singapore (SG)
Australia (AU)
Japan (JP)
India (IN)
Germany (DE)
France (FR)
│europe-west2europe-west4
us-central1
northamerica-northeast1
asia-northeast3
asia-southeast1
australia-southeast1
asia-northeast1
asia-south1
europe-west3
europe-west9
│europe-west2-docker.pkg.deveurope-west4-docker.pkg.dev
us-central1-docker.pkg.dev
northamerica-northeast1-docker.pkg.dev
asia-northeast3-docker.pkg.dev
asia-southeast1-docker.pkg.dev
australia-southeast1-docker.pkg.dev
asia-northeast1-docker.pkg.dev
asia-south1-docker.pkg.dev
europe-west3-docker.pkg.dev
europe-west9-docker.pkg.dev
dc-<tenant-name>.traps.paloaltonetworks.comUsed for EDR data upload.
│IP address by region:
- US (United States): 34.98.77.231:443
- EU (Europe): 34.102.140.103:443
- CA (Canada): 34.96.120.25:443
- UK (United Kingdom): 35.244.133.254:443
- JP (Japan): 34.95.66.187:443
- SG (Singapore): 34.120.142.18:443
- AU (Australia): 34.102.237.151:443
- DE (Germany): 34.107.161.143:443
- IN (India): 34.120.213.187:443
- DL (Delhi): 136.110.132.208:443
- CH (Switzerland): 34.149.180.250:443
- PL (Poland): 35.190.13.237:443
- TW (Taiwan): 34.149.248.76:443
- QT (Qatar): 34.107.129.254:443
- FA (France): 34.36.155.211:443
- IL (Israel): 34.128.157.130:443
- SA (Saudi Arabia): 34.107.213.85:443
- ID (Indonesia): 34.128.156.84:443
- ES (Spain): 34.120.102.147:443
- IT (Italy): 34.8.234.58:443
- KR (South Korea): 34.54.155.245:443
- ZA (South Africa): 35.190.79.68:443
- BR (Brazil): 136.110.146.246:443
traps-management-servicech-<tenant-name>.traps.paloaltonetworks.comUsed for all other requests between the agent and its tenant server, including heartbeat, uploads, action results, and scan reports.
│IP address by region:
- US (United States): 34.98.77.231:443
- EU (Europe): 34.102.140.103:443
- CA (Canada): 34.96.120.25:443
- UK (United Kingdom): 35.244.133.254:443
- JP (Japan): 34.95.66.187:443
- SG (Singapore): 34.120.142.18:443
- AU (Australia): 34.102.237.151:443
- DE (Germany): 34.107.161.143:443
- IN (India): 34.120.213.188:443
- DL (Delhi): 136.110.132.208:443
- CH (Switzerland): 34.149.180.250:443
- PL (Poland): 35.190.13.237:443
- TW (Taiwan): 34.149.248.76:443
- QT (Qatar): 34.107.129.254:443
- FA (France): 34.36.155.211:443
- IL (Israel): 34.128.157.130:443
- SA (Saudi Arabia): 34.107.213.85:443
- ID (Indonesia): 34.128.156.84:443
- ES (Spain): 34.120.102.147:443
- IT (Italy): 34.8.234.58:443
- KR (South Korea): 34.54.155.245:443
- ZA (South Africa): 35.190.79.68:443
- BR (Brazil): 136.110.146.246:443
traps-management-serviceapi-<tenant-name>.xdr.<region>.paloaltonetworks.comUsed for API requests and responses and to connect to an engine.
│IP address by region:
- US (United States): 35.222.81.194:443
- EU (Europe): 34.90.67.58:443
- CA (Canada): 35.203.82.121:443
- UK (United Kingdom): 34.89.56.78:443
- JP (Japan): 34.84.125.129:443
- SG (Singapore): 34.87.83.144:443
- AU (Australia): 35.189.18.208:443
- DE (Germany): 34.107.57.23:443
- IN (India): 35.200.158.164:443
- DL (Delhi): 34.131.165.103:443
- CH (Switzerland): 34.65.248.119:443
- PL (Poland): 34.116.216.55:443
- TW (Taiwan): 35.234.8.249:443
- QT (Qatar): 34.18.46.240:443
- FA (France): 34.155.222.152:443
- IL (Israel): 34.165.156.139:443
- SA (Saudi Arabia): 34.166.58.79:443
- ID (Indonesia): 34.128.115.238:443
- ES (Spain): 34.175.30.176:443
- IT (Italy): 34.154.195.120:443
- KR (South Korea): 34.64.54.175:443
- ZA (South Africa): 34.35.64.191:443
- BR (Brazil): 34.39.136.78:443
cc-<tenant-name>.traps.paloaltonetworks.comUsed for get-verdict requests.
For agents on endpoints, you must allow the IP address for the closest region to ensure connectivity. Endpoints use latency-based routing. An agent that belongs to a US tenant, for example, but that is physically located in Singapore, routes to Singapore to get the verdict.
│IP address by region:
- US (United States): 35.224.140.142:443
- EU (Europe): 34.90.71.103:443
- CA (Canada): 35.203.35.23:443
- UK (United Kingdom): 34.89.42.214:443
- JP (Japan): 34.84.225.105:443
- SG (Singapore): 35.247.161.94:443
- AU (Australia): 35.201.23.188:443
- DE (Germany): 35.242.201.199:443
- IN (India): 35.244.57.196:443
- DL (Delhi): 34.131.47.126:443
- CH (Switzerland): 34.65.137.215:443
- PL (Poland): 34.116.213.71:443
- TW (Taiwan): 35.229.186.216:443
- QT (Qatar): 34.18.53.229:443
- FA (France): 34.155.110.169:443
- IL (Israel): 34.165.2.110:443
- SA (Saudi Arabia): 34.166.53.160:443
- ID (Indonesia): 34.101.155.198:443
- ES (Spain): 34.175.205.166:443
- IT (Italy): 34.154.230.76:443
- KR (South Korea): 34.64.228.117:443
- ZA (South Africa): 34.35.13.198:443
- BR (Brazil): 34.39.195.104:443
traps-management-servicexdr-<region>-<project ID>-tim-indicators.storage.googleapis.comUsed to download the IOC indicators from the tenant.
│IP address by region:
- US (United States): 35.224.140.142:443
- EU (Europe): 34.90.71.103:443
- CA (Canada): 35.203.35.23:443
- UK (United Kingdom): 34.89.42.214:443
- JP (Japan): 34.84.225.105:443
- SG (Singapore): 35.247.161.94:443
- AU (Australia): 35.201.23.188:443
- DE (Germany): 35.242.201.199:443
- IN (India): 35.244.57.196:443
- DL (Delhi): 34.131.47.126:443
- CH (Switzerland): 34.65.137.215:443
- PL (Poland): 34.116.213.71:443
- TW (Taiwan): 35.229.186.216:443
- QT (Qatar): 34.18.53.229:443
- FA (France): 34.155.110.169:443
- IL (Israel): 34.165.2.110:443
- SA (Saudi Arabia): 34.166.53.160:443
- ID (Indonesia): 34.101.155.198:443
- ES (Spain): 34.175.205.166:443
- IT (Italy): 34.154.230.76:443
- KR (South Korea): 34.64.228.117:443
- ZA (South Africa): 34.35.13.198:443
- BR (Brazil): 34.39.195.104:443
cortex-xdrBroker VM ResourcesRequired for deployments that use Broker VM features
││xdr-ova-installers-prod-us.storage.googleapis.comUsed to download Broker VM images from the server.
This storage bucket is used for all regions.
│- IP ranges in GCP
- Port: 443
cortex-xdrbr-<tenant-name>.xdr.<region>.paloaltonetworks.com│IP address by region:
- US (United States): 104.155.131.72:443
- EU (Europe): 34.91.128.226:443
- CA (Canada): 34.95.8.232:443
- UK (United Kingdom): 35.197.219.110:443
- JP (Japan):34.85.74.43:443
- SG (Singapore): 34.87.167.125:443
- AU (Australia): 35.244.93.0:443
- DE (Germany): 35.198.112.13:443
- IN (India): 35.200.234.99:443
- DL (Delhi): 34.131.131.141:443
- CH (Switzerland): 34.65.51.103:443
- PL (Poland): 34.116.176.97:443
- TW (Taiwan): 34.80.230.166:443
- QT (Qatar): 34.18.37.73:443
- FA (France): 34.155.90.61:443
- IL (Israel): 34.165.24.222:443
- SA (Saudi Arabia): 34.166.55.153:443
- ID (Indonesia): 34.101.101.170:443
- ES (Spain): 34.175.182.55:443
- IT (Italy): 34.154.168.139:443
- KR (South Korea): 34.64.46.249:443
- ZA (South Africa): 34.35.45.251:443
- BR (Brazil): 35.198.38.182:443
@@ diff truncated @@Show markdown source
@@ -17,48 +17,10 @@ Before configuring your firewall, review these guidelines: {% hint style="info" %} ### Note _**`<tenant-name>`**_ refers to the selected subdomain of your Cortex XSIAM tenant, and _**`<region>`**_ is the region in which your tenant is deployed. For more information, see [Cortex XSIAM supported regions](cortex-xsiam-supported-regions). {% endhint %} The following tables list required FQDNs, IP addresses, ports, and App-ID coverage for your deployment. -| FQDN | IP Addresses and Port | App-ID Coverage | -| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| **Egress** | | | -| <p><em><strong><code><tenant-name></code></strong></em><strong><code>.xdr.</code></strong><em><strong><code><region></code></strong></em><strong><code>.paloaltonetworks.com</code></strong></p><p>Used to connect to the Cortex XSIAM tenant.</p> | <p>IP address by region:</p><ul><li>US (United States): 35.244.250.18:443</li><li>EU (Europe): 35.227.237.180:443</li><li>CA (Canada): 34.120.31.199:443</li><li>UK (United Kingdom): 34.120.87.77:443</li><li>JP (Japan): 35.241.28.254:443</li><li>SG (Singapore): 34.117.211.129:443</li><li>AU (Australia): 34.120.229.65:443</li><li>DE (Germany): 34.98.68.183:443</li><li>IN (India): 35.186.207.80:443</li><li>DL (Delhi): 34.8.67.192:443</li><li>CH (Switzerland): 34.111.6.153:443</li><li>PL (Poland): 34.117.240.208:443</li><li>TW (Taiwan): 34.160.28.41:443</li><li>QT (Qatar): 35.190.0.180:443</li><li>FA (France): 34.111.134.57:443</li><li>IL (Israel): 34.111.129.144:443</li><li>SA (Saudi Arabia): 35.244.157.127:443</li><li>ID (Indonesia): 34.111.58.152:443</li><li>ES (Spain): 34.111.188.248:443</li><li>IT (Italy): 34.8.224.70:443</li><li>KR (South Korea): 34.54.5.247:443</li><li>ZA (South Africa): 34.149.165.12:443</li><li>BR (Brazil): 34.96.83.202:443</li></ul> | **`cortex-xdr`** | -| <p><strong><code>distributions.traps.paloaltonetworks.com</code></strong></p><p>Used for the first request in registration flow where the agent passes the distribution id and obtains the <strong><code>ch-</code></strong><em><strong><code><tenant-name></code></strong></em><strong><code>.traps.paloaltonetworks.com</code></strong> of its tenant.</p> | <ul><li>IP address: 35.223.6.69</li><li>Port: 443</li></ul> | **`traps-management-service`** | -| <p><strong><code>https://lrc-</code></strong><em><strong><code><region></code></strong></em><strong><code>.paloaltonetworks.com</code></strong></p><p><strong><code>wss://lrc-</code></strong><em><strong><code><region></code></strong></em><strong><code>.paloaltonetworks.com</code></strong></p><p>Used in live terminal flow.</p> | <p>IP address by region:</p><ul><li>US (United States): 35.190.88.43:443</li><li>EU (Europe): 35.244.251.25:443</li><li>CA (Canada): 35.203.99.74:443</li><li>UK (United Kingdom): 35.242.159.176:443</li><li>JP (Japan): 34.84.201.32:443</li><li>SG (Singapore): 34.87.61.186:443</li><li>AU (Australia): 35.244.66.177:443</li><li>DE (Germany): 34.107.61.141:443</li><li>IN (India): 35.200.146.253:443</li><li>DL (Delhi): 34.131.116.135:443</li><li>CH (Switzerland): 34.65.213.226:443</li><li>PL (Poland): 34.118.62.80:443</li><li>TW (Taiwan): 34.80.34.30:443</li><li>QT (Qatar): 34.18.34.73:443</li><li>FA (France): 34.163.57.57:443</li><li>IL (Israel): 34.165.43.106:443</li><li>SA (Saudi Arabia): 34.166.54.6:443</li><li>ID (Indonesia): 34.101.214.157:443</li><li>ES (Spain): 34.175.18.78:443</li><li>IT (Italy): 34.154.154.5:443</li><li>KR (South Korea): 34.22.66.91:443</li><li>ZA (South Africa): 34.35.56.170:443</li><li>BR (Brazil): 34.151.236.197:443</li></ul> | **`cortex-xdr`** | -| <p><strong><code>panw-xdr-installers-prod-us.storage.googleapis.com</code></strong></p><p>Used to download installers for upgrade actions from the server.</p><p>This storage bucket is used for all regions.</p> | <ul><li>IP ranges in GCP</li><li>Port: 443</li></ul> | **`cortex-xdr`** | -| <p><strong><code>panw-xdr-payloads-prod-us.storage.googleapis.com</code></strong></p><p>Used to download the executable for the live terminal for XDR agents earlier than version 7.1.0.</p><p>This storage bucket is used for all regions.</p> | <ul><li>IP ranges in GCP</li><li>Port: 443</li></ul> | **`cortex-xdr`** | -| <p><strong><code>global-content-profiles-policy.storage.googleapis.com</code></strong></p><p>Used to download content updates.</p> | <ul><li>IP ranges in GCP</li><li>Port: 443</li></ul> | **`cortex-xdr`** | -| <p><strong><code>panw-xdr-evr-prod-</code></strong><em><strong><code><region></code></strong></em><strong><code>.storage.googleapis.com</code></strong></p><p>Used to download extended verdict request results in scanning.</p> | <ul><li>IP ranges in GCP</li><li>Port: 443</li></ul> | **`cortex-xdr`** | -| <p><strong><code>https://</code></strong><em><strong><code><region></code></strong></em><strong><code>-docker.pkg.dev</code></strong></p><p>Used to download the Kubernetes image from the registry for Kubernetes agents installation.</p><p>Refer to <strong>Regional Docker registry mapping</strong> for your specific tenant location and corresponding Docker registry URL.</p> | <ul><li>IP ranges in GCP</li><li>Port: 443</li></ul> | | -| **Regional Docker registry mapping** | | | -| **Tenant location** | **GCP region** | **Registry URL** | -| <p>UK</p><p>Netherlands (EU)</p><p>United States (US)</p><p>Canada (CA)</p><p>South Korea (KR)</p><p>Singapore (SG)</p><p>Australia (AU)</p><p>Japan (JP)</p><p>India (IN)</p><p>Germany (DE)</p><p>France (FR)</p> | <p>europe-west2</p><p>europe-west4</p><p>us-central1</p><p>northamerica-northeast1</p><p>asia-northeast3</p><p>asia-southeast1</p><p>australia-southeast1</p><p>asia-northeast1</p><p>asia-south1</p><p>europe-west3</p><p>europe-west9</p> | <p>europe-west2-docker.pkg.dev</p><p>europe-west4-docker.pkg.dev</p><p>us-central1-docker.pkg.dev</p><p>northamerica-northeast1-docker.pkg.dev</p><p>asia-northeast3-docker.pkg.dev</p><p>asia-southeast1-docker.pkg.dev</p><p>australia-southeast1-docker.pkg.dev</p><p>asia-northeast1-docker.pkg.dev</p><p>asia-south1-docker.pkg.dev</p><p>europe-west3-docker.pkg.dev</p><p>europe-west9-docker.pkg.dev</p> | -| <p><strong><code>dc-</code></strong><em><strong><code><tenant-name></code></strong></em><strong><code>.traps.paloaltonetworks.com</code></strong></p><p>Used for EDR data upload.</p> | <p>IP address by region:</p><ul><li>US (United States): 34.98.77.231:443</li><li>EU (Europe): 34.102.140.103:443</li><li>CA (Canada): 34.96.120.25:443</li><li>UK (United Kingdom): 35.244.133.254:443</li><li>JP (Japan): 34.95.66.187:443</li><li>SG (Singapore): 34.120.142.18:443</li><li>AU (Australia): 34.102.237.151:443</li><li>DE (Germany): 34.107.161.143:443</li><li>IN (India): 34.120.213.187:443</li><li>DL (Delhi): 136.110.132.208:443</li><li>CH (Switzerland): 34.149.180.250:443</li><li>PL (Poland): 35.190.13.237:443</li><li>TW (Taiwan): 34.149.248.76:443</li><li>QT (Qatar): 34.107.129.254:443</li><li>FA (France): 34.36.155.211:443</li><li>IL (Israel): 34.128.157.130:443</li><li>SA (Saudi Arabia): 34.107.213.85:443</li><li>ID (Indonesia): 34.128.156.84:443</li><li>ES (Spain): 34.120.102.147:443</li><li>IT (Italy): 34.8.234.58:443</li><li>KR (South Korea): 34.54.155.245:443</li><li>ZA (South Africa): 35.190.79.68:443</li><li>BR (Brazil): 136.110.146.246:443</li></ul> | **`traps-management-service`** | -| <p><strong><code>ch-</code></strong><em><strong><code><tenant-name></code></strong></em><strong><code>.traps.paloaltonetworks.com</code></strong></p><p>Used for all other requests between the agent and its tenant server, including heartbeat, uploads, action results, and scan reports.</p> | <p>IP address by region:</p><ul><li>US (United States): 34.98.77.231:443</li><li>EU (Europe): 34.102.140.103:443</li><li>CA (Canada): 34.96.120.25:443</li><li>UK (United Kingdom): 35.244.133.254:443</li><li>JP (Japan): 34.95.66.187:443</li><li>SG (Singapore): 34.120.142.18:443</li><li>AU (Australia): 34.102.237.151:443</li><li>DE (Germany): 34.107.161.143:443</li><li>IN (India): 34.120.213.188:443</li><li>DL (Delhi): 136.110.132.208:443</li><li>CH (Switzerland): 34.149.180.250:443</li><li>PL (Poland): 35.190.13.237:443</li><li>TW (Taiwan): 34.149.248.76:443</li><li>QT (Qatar): 34.107.129.254:443</li><li>FA (France): 34.36.155.211:443</li><li>IL (Israel): 34.128.157.130:443</li><li>SA (Saudi Arabia): 34.107.213.85:443</li><li>ID (Indonesia): 34.128.156.84:443</li><li>ES (Spain): 34.120.102.147:443</li><li>IT (Italy): 34.8.234.58:443</li><li>KR (South Korea): 34.54.155.245:443</li><li>ZA (South Africa): 35.190.79.68:443</li><li>BR (Brazil): 136.110.146.246:443</li></ul> | **`traps-management-service`** | -| <p><strong><code>api-</code></strong><em><strong><code><tenant-name>.xdr.<region></code></strong></em><strong><code>.paloaltonetworks.com</code></strong></p><p>Used for API requests and responses and to connect to an engine.</p> | <p>IP address by region:</p><ul><li>US (United States): 35.222.81.194:443</li><li>EU (Europe): 34.90.67.58:443</li><li>CA (Canada): 35.203.82.121:443</li><li>UK (United Kingdom): 34.89.56.78:443</li><li>JP (Japan): 34.84.125.129:443</li><li>SG (Singapore): 34.87.83.144:443</li><li>AU (Australia): 35.189.18.208:443</li><li>DE (Germany): 34.107.57.23:443</li><li>IN (India): 35.200.158.164:443</li><li>DL (Delhi): 34.131.165.103:443</li><li>CH (Switzerland): 34.65.248.119:443</li><li>PL (Poland): 34.116.216.55:443</li><li>TW (Taiwan): 35.234.8.249:443</li><li>QT (Qatar): 34.18.46.240:443</li><li>FA (France): 34.155.222.152:443</li><li>IL (Israel): 34.165.156.139:443</li><li>SA (Saudi Arabia): 34.166.58.79:443</li><li>ID (Indonesia): 34.128.115.238:443</li><li>ES (Spain): 34.175.30.176:443</li><li>IT (Italy): 34.154.195.120:443</li><li>KR (South Korea): 34.64.54.175:443</li><li>ZA (South Africa): 34.35.64.191:443</li><li>BR (Brazil): 34.39.136.78:443</li></ul> | — | -| <p><strong><code>cc-</code></strong><em><strong><code><tenant-name></code></strong></em><strong><code>.traps.paloaltonetworks.com</code></strong></p><p>Used for get-verdict requests.</p><p>For agents on endpoints, you must allow the IP address for the closest region to ensure connectivity. Endpoints use latency-based routing. An agent that belongs to a US tenant, for example, but that is physically located in Singapore, routes to Singapore to get the verdict.</p> | <p>IP address by region:</p><ul><li>US (United States): 35.224.140.142:443</li><li>EU (Europe): 34.90.71.103:443</li><li>CA (Canada): 35.203.35.23:443</li><li>UK (United Kingdom): 34.89.42.214:443</li><li>JP (Japan): 34.84.225.105:443</li><li>SG (Singapore): 35.247.161.94:443</li><li>AU (Australia): 35.201.23.188:443</li><li>DE (Germany): 35.242.201.199:443</li><li>IN (India): 35.244.57.196:443</li><li>DL (Delhi): 34.131.47.126:443</li><li>CH (Switzerland): 34.65.137.215:443</li><li>PL (Poland): 34.116.213.71:443</li><li>TW (Taiwan): 35.229.186.216:443</li><li>QT (Qatar): 34.18.53.229:443</li><li>FA (France): 34.155.110.169:443</li><li>IL (Israel): 34.165.2.110:443</li><li>SA (Saudi Arabia): 34.166.53.160:443</li><li>ID (Indonesia): 34.101.155.198:443</li><li>ES (Spain): 34.175.205.166:443</li><li>IT (Italy): 34.154.230.76:443</li><li>KR (South Korea): 34.64.228.117:443</li><li>ZA (South Africa): 34.35.13.198:443</li><li>BR (Brazil): 34.39.195.104:443</li></ul> | **`traps-management-service`** | -| <p><code>xdr-<region>-<project ID>-tim-indicators.storage.googleapis.com</code></p><p>Used to download the IOC indicators from the tenant.</p> | <p>IP address by region:</p><ul><li>US (United States): 35.224.140.142:443</li><li>EU (Europe): 34.90.71.103:443</li><li>CA (Canada): 35.203.35.23:443</li><li>UK (United Kingdom): 34.89.42.214:443</li><li>JP (Japan): 34.84.225.105:443</li><li>SG (Singapore): 35.247.161.94:443</li><li>AU (Australia): 35.201.23.188:443</li><li>DE (Germany): 35.242.201.199:443</li><li>IN (India): 35.244.57.196:443</li><li>DL (Delhi): 34.131.47.126:443</li><li>CH (Switzerland): 34.65.137.215:443</li><li>PL (Poland): 34.116.213.71:443</li><li>TW (Taiwan): 35.229.186.216:443</li><li>QT (Qatar): 34.18.53.229:443</li><li>FA (France): 34.155.110.169:443</li><li>IL (Israel): 34.165.2.110:443</li><li>SA (Saudi Arabia): 34.166.53.160:443</li><li>ID (Indonesia): 34.101.155.198:443</li><li>ES (Spain): 34.175.205.166:443</li><li>IT (Italy): 34.154.230.76:443</li><li>KR (South Korea): 34.64.228.117:443</li><li>ZA (South Africa): 34.35.13.198:443</li><li>BR (Brazil): 34.39.195.104:443</li></ul> | `cortex-xdr` | -| <p><strong>Broker VM Resources</strong></p><p>Required for deployments that use Broker VM features</p> | | | -| <p><a href="http://xdr-ova-installers-prod-us.storage.googleapis.com/">xdr-ova-installers-prod-us.storage.googleapis.com</a></p><p>Used to download Broker VM images from the server.</p><p>This storage bucket is used for all regions.</p> | <ul><li>IP ranges in GCP</li><li>Port: 443</li></ul> | **`cortex-xdr`** | -| **`br-`**_**`<tenant-name>.xdr.<region>`**_**`.paloaltonetworks.com`** | <p>IP address by region:</p><ul><li>US (United States): 104.155.131.72:443</li><li>EU (Europe): 34.91.128.226:443</li><li>CA (Canada): 34.95.8.232:443</li><li>UK (United Kingdom): 35.197.219.110:443</li><li>JP (Japan):34.85.74.43:443</li><li>SG (Singapore): 34.87.167.125:443</li><li>AU (Australia): 35.244.93.0:443</li><li>DE (Germany): 35.198.112.13:443</li><li>IN (India): 35.200.234.99:443</li><li>DL (Delhi): 34.131.131.141:443</li><li>CH (Switzerland): 34.65.51.103:443</li><li>PL (Poland): 34.116.176.97:443</li><li>TW (Taiwan): 34.80.230.166:443</li><li>QT (Qatar): 34.18.37.73:443</li><li>FA (France): 34.155.90.61:443</li><li>IL (Israel): 34.165.24.222:443</li><li>SA (Saudi Arabia): 34.166.55.153:443</li><li>ID (Indonesia): 34.101.101.170:443</li><li>ES (Spain): 34.175.182.55:443</li><li>IT (Italy): 34.154.168.139:443</li><li>KR (South Korea): 34.64.46.249:443</li><li>ZA (South Africa): 34.35.45.251:443</li><li>BR (Brazil): 35.198.38.182:443</li></ul> | — | @@ diff truncated @@ -
▸ ▾ Engine IP addresses (outbound) modified +1 −0 Adds Finland (FI) engine outbound addresses 35.228.175.228 and 35.228.44.44.
xsiam/onboard-cortex-xsiam/deployment-steps/activate-cortex-xsiam/enable-access-to-required-panw-resources/engine-ip-addresses-outboundRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -22,16 +22,17 @@ APP-ID: NoneNetherlands/Europe (EU)
│34.147.67.188, 34.90.16.31Netherlands/Europe (EU)
│34.147.67.188, 34.90.16.31Poland (PL)│34.118.92.214, 34.116.223.119Poland (PL)│34.118.92.214, 34.116.223.119Qatar (QT)│34.18.39.0, 34.18.32.96Qatar (QT)│34.18.39.0, 34.18.32.96Saudi Arabia (SA)│34.166.58.243, 34.166.54.238Saudi Arabia (SA)│34.166.58.243, 34.166.54.238South Africa (ZA)│34.35.70.193, 34.35.80.189South Africa (ZA)│34.35.70.193, 34.35.80.189Spain (ES)│34.175.255.99, 34.175.230.35Spain (ES)│34.175.255.99, 34.175.230.35Switzerland (CH)│34.65.222.25, 34.65.233.60Switzerland (CH)│34.65.222.25, 34.65.233.60United Kingdom (UK)│34.142.3.42, 34.142.44.136United Kingdom (UK)│34.142.3.42, 34.142.44.136Finland (FI)│35.228.175.228, 35.228.44.44JPAC (Asia-Pacific)JPAC (Asia-Pacific)Region│IP AddressesRegion│IP Addresses| ---------------- | ----------------------------- || ---------------- | ----------------------------- |Australia (AU)│35.244.73.76, 35.201.22.63Australia (AU)│35.244.73.76, 35.201.22.63India (IN)│35.244.5.205, 34.93.118.113India (IN)│35.244.5.205, 34.93.118.113Indonesia (ID)│34.101.125.66, 34.101.218.184Indonesia (ID)│34.101.125.66, 34.101.218.184Show markdown source
@@ -22,16 +22,17 @@ APP-ID: None | <p>Netherlands/</p><p>Europe (EU)</p> | 34.147.67.188, 34.90.16.31 | | Poland (PL) | 34.118.92.214, 34.116.223.119 | | Qatar (QT) | 34.18.39.0, 34.18.32.96 | | Saudi Arabia (SA) | 34.166.58.243, 34.166.54.238 | | South Africa (ZA) | 34.35.70.193, 34.35.80.189 | | Spain (ES) | 34.175.255.99, 34.175.230.35 | | Switzerland (CH) | 34.65.222.25, 34.65.233.60 | | United Kingdom (UK) | 34.142.3.42, 34.142.44.136 | +| Finland (FI) | 35.228.175.228, 35.228.44.44 | **JPAC (Asia-Pacific)** | Region | IP Addresses | | ---------------- | ----------------------------- | | Australia (AU) | 35.244.73.76, 35.201.22.63 | | India (IN) | 35.244.5.205, 34.93.118.113 | | Indonesia (ID) | 34.101.125.66, 34.101.218.184 |
-
▸ ▾ Inbound source resources modified +1 −0 Adds an inbound row for the new region, labelled "Finland (F)" rather than (FI).
xsiam/onboard-cortex-xsiam/deployment-steps/activate-cortex-xsiam/enable-access-to-required-panw-resources/inbound-source-resourcesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -28,16 +28,17 @@ Service definitionsNetherlands/Europe (EU)
│34.147.107.51, 34.91.26.125│34.90.70.107, 35.204.129.196Netherlands/Europe (EU)
│34.147.107.51, 34.91.26.125│34.90.70.107, 35.204.129.196Poland (PL)│34.118.48.171, 34.116.202.235│34.118.71.237, 34.118.124.130Poland (PL)│34.118.48.171, 34.116.202.235│34.118.71.237, 34.118.124.130Qatar (QT)│34.18.34.118, 34.18.39.155│34.18.44.71, 34.18.30.132Qatar (QT)│34.18.34.118, 34.18.39.155│34.18.44.71, 34.18.30.132Saudi Arabia (SA)│34.166.61.81, 34.166.58.213│34.166.59.20, 34.166.53.242Saudi Arabia (SA)│34.166.61.81, 34.166.58.213│34.166.59.20, 34.166.53.242South Africa (ZA)│34.35.42.196, 34.35.79.219│34.35.69.156, 34.35.60.86South Africa (ZA)│34.35.42.196, 34.35.79.219│34.35.69.156, 34.35.60.86Spain (ES)│34.175.46.46, 34.175.80.182│34.175.27.251, 34.175.198.50Spain (ES)│34.175.46.46, 34.175.80.182│34.175.27.251, 34.175.198.50Switzerland (CH)│34.65.108.153, 34.65.155.169│34.65.225.124, 34.65.89.6Switzerland (CH)│34.65.108.153, 34.65.155.169│34.65.225.124, 34.65.89.6United Kingdom (UK)│35.242.180.163, 34.105.173.229│34.105.227.146, 34.105.137.22United Kingdom (UK)│35.242.180.163, 34.105.173.229│34.105.227.146, 34.105.137.22Finland (F)│34.88.97.182, 34.88.189.1│35.228.192.167, 34.88.193.126JPAC (Asia-Pacific)JPAC (Asia-Pacific)Region│Infrastructure IP Addresses (allow inbound)│Data Collection IP Addresses (allow inbound)Region│Infrastructure IP Addresses (allow inbound)│Data Collection IP Addresses (allow inbound)| ---------------- | ------------------------------------------- | -------------------------------------------- || ---------------- | ------------------------------------------- | -------------------------------------------- |Australia (AU)│34.151.83.236, 34.116.67.90│35.197.181.108, 35.197.175.44Australia (AU)│34.151.83.236, 34.116.67.90│35.197.181.108, 35.197.175.44India (IN)│35.200.175.78, 34.93.9.198│34.93.3.196, 34.93.175.218India (IN)│35.200.175.78, 34.93.9.198│34.93.3.196, 34.93.175.218Indonesia (ID)│34.128.126.138, 34.128.82.158│34.101.158.32, 34.101.79.159Indonesia (ID)│34.128.126.138, 34.128.82.158│34.101.158.32, 34.101.79.159Show markdown source
@@ -28,16 +28,17 @@ Service definitions | <p>Netherlands/</p><p>Europe (EU)</p> | 34.147.107.51, 34.91.26.125 | 34.90.70.107, 35.204.129.196 | | Poland (PL) | 34.118.48.171, 34.116.202.235 | 34.118.71.237, 34.118.124.130 | | Qatar (QT) | 34.18.34.118, 34.18.39.155 | 34.18.44.71, 34.18.30.132 | | Saudi Arabia (SA) | 34.166.61.81, 34.166.58.213 | 34.166.59.20, 34.166.53.242 | | South Africa (ZA) | 34.35.42.196, 34.35.79.219 | 34.35.69.156, 34.35.60.86 | | Spain (ES) | 34.175.46.46, 34.175.80.182 | 34.175.27.251, 34.175.198.50 | | Switzerland (CH) | 34.65.108.153, 34.65.155.169 | 34.65.225.124, 34.65.89.6 | | United Kingdom (UK) | 35.242.180.163, 34.105.173.229 | 34.105.227.146, 34.105.137.22 | +| Finland (F) | 34.88.97.182, 34.88.189.1 | 35.228.192.167, 34.88.193.126 | **JPAC (Asia-Pacific)** | Region | Infrastructure IP Addresses (allow inbound) | Data Collection IP Addresses (allow inbound) | | ---------------- | ------------------------------------------- | -------------------------------------------- | | Australia (AU) | 34.151.83.236, 34.116.67.90 | 35.197.181.108, 35.197.175.44 | | India (IN) | 35.200.175.78, 34.93.9.198 | 34.93.3.196, 34.93.175.218 | | Indonesia (ID) | 34.128.126.138, 34.128.82.158 | 34.101.158.32, 34.101.79.159 |
-
▸ ▾ Regional egress resources modified +4 −25 Adds Finland (FI) with five of six addresses; the Broker VM column is empty. Both region tables and the service table became HTML.
xsiam/onboard-cortex-xsiam/deployment-steps/activate-cortex-xsiam/enable-access-to-required-panw-resources/regional-egress-resourcesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,36 +1,23 @@# Regional egress resources# Regional egress resourcesThese are the core resources specific to your selected deployment region (for example, US, EU, JP). They handle the primary communication between your agents and your specific tenant (API, Heartbeats, Live Terminal, and EDR data uploads).These are the core resources specific to your selected deployment region (for example, US, EU, JP). They handle the primary communication between your agents and your specific tenant (API, Heartbeats, Live Terminal, and EDR data uploads).The following table describes the service definition, FQDNs, and App-ID coverage for your deployment. Unless specified, all ports are 443 (TCP). Select your region and allow outbound traffic to the corresponding FQDNs and IPs.The following table describes the service definition, FQDNs, and App-ID coverage for your deployment. Unless specified, all ports are 443 (TCP). Select your region and allow outbound traffic to the corresponding FQDNs and IPs.Service definitions and regionsService definitions and regionsService Definition│FQDN│APP-IDService Definition FQDN APP-ID Egress tenant
Connects to the Cortex XSIAM tenant.
<tenant-name>.xdr.<region>.paloaltonetworks.comcortex-xdrLive Terminal
Used in live terminal flow for real-time shell sessions
https://lrc-<region>.paloaltonetworks.comwss://lrc-<region>.paloaltonetworks.comcortex-xdrEndpoint Detection and Response (EDR)
Used for EDR data upload. Includes telemetry logs, process executions, and security events that the Cortex XDR agent captures and sends to the cloud for analysis
dc-<tenant-name>.traps.paloaltonetworks.comtraps-management-serviceHeartbeat
Used for all other requests between the XDR agent and the tenant, including heartbeat, uploads, action results, and scan reports.
ch-<tenant-name>.traps.paloaltonetworks.comtraps-management-serviceAPI Access
Used for API requests and responses and to connect to an engine.
api-<tenant-name>.xdr.<region>.paloaltonetworks.comN/a Indicator
Used to download the IOC indicators from the tenant. Downloading lists of bad IPs, domains, or hashes to block locally.
xdr-<region>-<project ID>-tim-indicators.storage.googleapis.comtraps-management-serviceVerdict requests
Used for get-verdict requests. For example, checking if a specific file hash is known to be malware.
cc-<tenant-name>.traps.paloaltonetworks.comtraps-management-serviceBroker VM
Connection for the Broker VM
br-<tenant-name>.xdr.<region>.paloaltonetworks.comN/a | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | -------------------------- |Egress tenantConnects to the Cortex XSIAM tenant.
│<tenant-name>.xdr.<region>.paloaltonetworks.com│cortex-xdrLive TerminalUsed in live terminal flow for real-time shell sessions
│https://lrc-<region>.paloaltonetworks.com
│wss://lrc-<region>.paloaltonetworks.comcortex-xdrEndpoint Detection and Response (EDR)Used for EDR data upload. Includes telemetry logs, process executions, and security events that the Cortex XDR agent captures and sends to the cloud for analysis
│dc-<tenant-name>.traps.paloaltonetworks.com│traps-management-serviceHeartbeatUsed for all other requests between the XDR agent and the tenant, including heartbeat, uploads, action results, and scan reports.
│ch-<tenant-name>.traps.paloaltonetworks.com│traps-management-serviceAPI AccessUsed for API requests and responses and to connect to an engine.
│api-<tenant-name>.xdr.<region>.paloaltonetworks.com│N/aIndicatorUsed to download the IOC indicators from the tenant. Downloading lists of bad IPs, domains, or hashes to block locally.
│xdr-<region>-<project ID>-tim-indicators.storage.googleapis.com│traps-management-serviceVerdict requestsUsed for get-verdict requests. For example, checking if a specific file hash is known to be malware.
│cc-<tenant-name>.traps.paloaltonetworks.com│traps-management-serviceBroker VMConnection for the Broker VM
│br-<tenant-name>.xdr.<region>.paloaltonetworks.com│N/aThe following tables list the required resources by region. Unless specified, all ports are 443 (TCP).The following tables list the required resources by region. Unless specified, all ports are 443 (TCP).AmericasAmericasRegion│Egress (tenant)│Live Terminal│EDR & Heartbeat│API Access│Indicator & Verdict requests│Broker VMRegion Egress (tenant) Live Terminal EDR & Heartbeat API Access Indicator & Verdict requests Broker VM United States (US) 35.244.250.18 35.190.88.43 34.98.77.231 35.222.81.194 35.224.140.142 104.155.131.72 Brazil (BR) 34.96.83.202 34.151.236.197 136.110.146.246 34.39.136.78 34.39.195.104 35.198.38.182 Canada (CA) 34.120.31.199 35.203.99.74 34.96.120.25 35.203.82.121 35.203.35.23 34.95.8.232 | ------------------ | --------------- | -------------- | --------------- | ------------- | ---------------------------- | -------------- |United States (US)│35.244.250.18│35.190.88.43│34.98.77.231│35.222.81.194│35.224.140.142│104.155.131.72Brazil (BR)│34.96.83.202│34.151.236.197│136.110.146.246│34.39.136.78│34.39.195.104│35.198.38.182Canada (CA)│34.120.31.199│35.203.99.74│34.96.120.25│35.203.82.121│35.203.35.23│34.95.8.232EMEA (Europe, Middle East, Africa)EMEA (Europe, Middle East, Africa)Region│Egress (tenant)│Live Terminal│EDR & Heartbeat│API Access│Indicator & Verdict request│Broker VMRegion│Egress (tenant)│Live Terminal│EDR & Heartbeat│API Access│Indicator & Verdict request│Broker VM| ------------------------------------- | --------------- | -------------- | --------------- | -------------- | --------------------------- | -------------- || ------------------------------------- | --------------- | -------------- | --------------- | -------------- | --------------------------- | -------------- |France (FA)│34.111.134.57│34.163.57.57│34.36.155.211│34.155.222.152│34.155.110.169│34.155.90.61France (FA)│34.111.134.57│34.163.57.57│34.36.155.211│34.155.222.152│34.155.110.169│34.155.90.61Germany (DE)│34.98.68.183│34.107.61.141│34.107.161.143│34.107.57.23│35.242.201.199│35.198.112.13Germany (DE)│34.98.68.183│34.107.61.141│34.107.161.143│34.107.57.23│35.242.201.199│35.198.112.13Israel (IL)│34.111.129.144│34.165.43.106│34.128.157.130│34.165.156.139│34.165.2.110│34.165.24.222Israel (IL)│34.111.129.144│34.165.43.106│34.128.157.130│34.165.156.139│34.165.2.110│34.165.24.222@@ -38,21 +25,13 @@ The following tables list the required resources by region. Unless specified, alNetherlands/Europe (EU)
│35.227.237.180│35.244.251.25│34.102.140.103│34.90.67.58│34.90.71.103│34.91.128.226Netherlands/Europe (EU)
│35.227.237.180│35.244.251.25│34.102.140.103│34.90.67.58│34.90.71.103│34.91.128.226Poland (PL)│34.117.240.208│34.118.62.80│35.190.13.237│34.116.216.55│34.116.213.71│34.116.176.97Poland (PL)│34.117.240.208│34.118.62.80│35.190.13.237│34.116.216.55│34.116.213.71│34.116.176.97Qatar (QT)│35.190.0.180│34.18.34.73│34.107.129.254│34.18.46.240│34.18.53.229│34.18.37.73Qatar (QT)│35.190.0.180│34.18.34.73│34.107.129.254│34.18.46.240│34.18.53.229│34.18.37.73Saudi Arabia (SA)│35.244.157.127│34.166.54.6│34.107.213.85│34.166.58.79│34.166.53.160│34.166.55.153Saudi Arabia (SA)│35.244.157.127│34.166.54.6│34.107.213.85│34.166.58.79│34.166.53.160│34.166.55.153South Africa (ZA)│34.149.165.12│34.35.56.170│35.190.79.68│34.35.64.191│34.35.13.198│34.35.45.251South Africa (ZA)│34.149.165.12│34.35.56.170│35.190.79.68│34.35.64.191│34.35.13.198│34.35.45.251Spain (ES)│34.111.188.248│34.175.18.78│34.120.102.147│34.175.30.176│34.175.205.166│34.175.182.55Spain (ES)│34.111.188.248│34.175.18.78│34.120.102.147│34.175.30.176│34.175.205.166│34.175.182.55Switzerland (CH)│34.111.6.153│34.65.213.226│34.149.180.250│34.65.248.119│34.65.137.215│34.65.51.103Switzerland (CH)│34.111.6.153│34.65.213.226│34.149.180.250│34.65.248.119│34.65.137.215│34.65.51.103United Kingdom (UK)│34.120.87.77│35.242.159.176│35.244.133.254│34.89.56.78│34.89.42.214│35.197.219.110United Kingdom (UK)│34.120.87.77│35.242.159.176│35.244.133.254│34.89.56.78│34.89.42.214│35.197.219.110Finland (FI)│34.160.63.63│34.88.31.230│136.110.165.34│35.228.73.215│35.228.118.177│JPAC (Asia-Pacific)JPAC (Asia-Pacific)Region│Egress (tenant)│Live Terminal│EDR & Heartbeat│API Access│Indicator & Verdict Requests│Broker VMRegion Egress (tenant) Live Terminal EDR & Heartbeat API Access Indicator & Verdict Requests Broker VM Australia (AU) 34.120.229.65 35.244.66.177 34.102.237.151 35.189.18.208 35.201.23.188 35.244.93.0 Delhi (DL) 34.8.67.192 34.131.116.135 136.110.132.208 34.131.165.103 34.131.47.126 34.131.131.141 India (IN) 35.186.207.80 35.200.146.253 34.120.213.187 35.200.158.164 35.244.57.196 35.200.234.99 Indonesia (ID) 34.111.58.152 34.101.214.157 34.128.156.84 34.128.115.238 34.101.155.198 34.101.101.170 Japan (JP) 35.241.28.254 34.84.201.32 34.95.66.187 34.84.125.129 34.84.225.105 34.85.74.43 Singapore (SG) 34.117.211.129 34.87.61.186 34.120.142.18 34.87.83.144 35.247.161.94 34.87.167.125 South Korea (KR) 34.54.5.247 34.22.66.91 34.54.155.245 34.64.54.175 34.64.228.117 34.64.46.249 Taiwan (TW) 34.160.28.41 34.80.34.30 34.149.248.76 35.234.8.249 35.229.186.216 34.80.230.166 | ---------------- | --------------- | -------------- | --------------- | -------------- | ---------------------------- | -------------- |Australia (AU)│34.120.229.65│35.244.66.177│34.102.237.151│35.189.18.208│35.201.23.188│35.244.93.0Delhi (DL)│34.8.67.192│34.131.116.135│136.110.132.208│34.131.165.103│34.131.47.126│34.131.131.141India (IN)│35.186.207.80│35.200.146.253│34.120.213.187│35.200.158.164│35.244.57.196│35.200.234.99Indonesia (ID)│34.111.58.152│34.101.214.157│34.128.156.84│34.128.115.238│34.101.155.198│34.101.101.170Japan (JP)│35.241.28.254│34.84.201.32│34.95.66.187│34.84.125.129│34.84.225.105│34.85.74.43Singapore (SG)│34.117.211.129│34.87.61.186│34.120.142.18│34.87.83.144│35.247.161.94│34.87.167.125South Korea (KR)│34.54.5.247│34.22.66.91│34.54.155.245│34.64.54.175│34.64.228.117│34.64.46.249Taiwan (TW)│34.160.28.41│34.80.34.30│34.149.248.76│35.234.8.249│35.229.186.216│34.80.230.166Show markdown source
@@ -1,36 +1,23 @@ # Regional egress resources These are the core resources specific to your selected deployment region (for example, US, EU, JP). They handle the primary communication between your agents and your specific tenant (API, Heartbeats, Live Terminal, and EDR data uploads). The following table describes the service definition, FQDNs, and App-ID coverage for your deployment. Unless specified, all ports are 443 (TCP). Select your region and allow outbound traffic to the corresponding FQDNs and IPs. **Service definitions and regions** -| Service Definition | FQDN | APP-ID | -| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | -------------------------- | -| <p>Egress tenant</p><p>Connects to the Cortex XSIAM tenant.</p> | `<tenant-name>.xdr.<region>.paloaltonetworks.com` | `cortex-xdr` | -| <p>Live Terminal</p><p>Used in live terminal flow for real-time shell sessions</p> | <p><code>https://lrc-<region>.paloaltonetworks.com</code></p><p><code>wss://lrc-<region>.paloaltonetworks.com</code></p> | `cortex-xdr` | -| <p>Endpoint Detection and Response (EDR)</p><p>Used for EDR data upload. Includes telemetry logs, process executions, and security events that the Cortex XDR agent captures and sends to the cloud for analysis</p> | `dc-<tenant-name>.traps.paloaltonetworks.com` | `traps-management-service` | -| <p>Heartbeat</p><p>Used for all other requests between the XDR agent and the tenant, including heartbeat, uploads, action results, and scan reports.</p> | `ch-<tenant-name>.traps.paloaltonetworks.com` | `traps-management-service` | -| <p>API Access</p><p>Used for API requests and responses and to connect to an engine.</p> | `api-<tenant-name>.xdr.<region>.paloaltonetworks.com` | N/a | -| <p>Indicator</p><p>Used to download the IOC indicators from the tenant. Downloading lists of bad IPs, domains, or hashes to block locally.</p> | `xdr-<region>-<project ID>-tim-indicators.storage.googleapis.com` | `traps-management-service` | -| <p>Verdict requests</p><p>Used for get-verdict requests. For example, checking if a specific file hash is known to be malware.</p> | `cc-<tenant-name>.traps.paloaltonetworks.com` | `traps-management-service` | -| <p>Broker VM</p><p>Connection for the Broker VM</p> | `br-<tenant-name>`_`.xdr.`_`<region>.paloaltonetworks.com` | N/a | +<table><thead><tr><th>Service Definition</th><th width="295">FQDN</th><th>APP-ID</th></tr></thead><tbody><tr><td><p>Egress tenant</p><p>Connects to the Cortex XSIAM tenant.</p></td><td><code><tenant-name>.xdr.<region>.paloaltonetworks.com</code></td><td><code>cortex-xdr</code></td></tr><tr><td><p>Live Terminal</p><p>Used in live terminal flow for real-time shell sessions</p></td><td><p><code>https://lrc-<region>.paloaltonetworks.com</code></p><p><code>wss://lrc-<region>.paloaltonetworks.com</code></p></td><td><code>cortex-xdr</code></td></tr><tr><td><p>Endpoint Detection and Response (EDR)</p><p>Used for EDR data upload. Includes telemetry logs, process executions, and security events that the Cortex XDR agent captures and sends to the cloud for analysis</p></td><td><code>dc-<tenant-name>.traps.paloaltonetworks.com</code></td><td><code>traps-management-service</code></td></tr><tr><td><p>Heartbeat</p><p>Used for all other requests between the XDR agent and the tenant, including heartbeat, uploads, action results, and scan reports.</p></td><td><code>ch-<tenant-name>.traps.paloaltonetworks.com</code></td><td><code>traps-management-service</code></td></tr><tr><td><p>API Access</p><p>Used for API requests and responses and to connect to an engine.</p></td><td><code>api-<tenant-name>.xdr.<region>.paloaltonetworks.com</code></td><td>N/a</td></tr><tr><td><p>Indicator</p><p>Used to download the IOC indicators from the tenant. Downloading lists of bad IPs, domains, or hashes to block locally.</p></td><td><code>xdr-<region>-<project ID>-tim-indicators.storage.googleapis.com</code></td><td><code>traps-management-service</code></td></tr><tr><td><p>Verdict requests</p><p>Used for get-verdict requests. For example, checking if a specific file hash is known to be malware.</p></td><td><code>cc-<tenant-name>.traps.paloaltonetworks.com</code></td><td><code>traps-management-service</code></td></tr><tr><td><p>Broker VM</p><p>Connection for the Broker VM</p></td><td><code>br-<tenant-name></code><em><code>.xdr.</code></em><code><region>.paloaltonetworks.com</code></td><td>N/a</td></tr></tbody></table> The following tables list the required resources by region. Unless specified, all ports are 443 (TCP). **Americas** -| Region | Egress (tenant) | Live Terminal | EDR & Heartbeat | API Access | Indicator & Verdict requests | Broker VM | -| ------------------ | --------------- | -------------- | --------------- | ------------- | ---------------------------- | -------------- | -| United States (US) | 35.244.250.18 | 35.190.88.43 | 34.98.77.231 | 35.222.81.194 | 35.224.140.142 | 104.155.131.72 | -| Brazil (BR) | 34.96.83.202 | 34.151.236.197 | 136.110.146.246 | 34.39.136.78 | 34.39.195.104 | 35.198.38.182 | -| Canada (CA) | 34.120.31.199 | 35.203.99.74 | 34.96.120.25 | 35.203.82.121 | 35.203.35.23 | 34.95.8.232 | +<table><thead><tr><th>Region</th><th>Egress (tenant)</th><th width="146">Live Terminal</th><th>EDR & Heartbeat</th><th>API Access</th><th>Indicator & Verdict requests</th><th>Broker VM</th></tr></thead><tbody><tr><td>United States (US)</td><td>35.244.250.18</td><td>35.190.88.43</td><td>34.98.77.231</td><td>35.222.81.194</td><td>35.224.140.142</td><td>104.155.131.72</td></tr><tr><td>Brazil (BR)</td><td>34.96.83.202</td><td>34.151.236.197</td><td>136.110.146.246</td><td>34.39.136.78</td><td>34.39.195.104</td><td>35.198.38.182</td></tr><tr><td>Canada (CA)</td><td>34.120.31.199</td><td>35.203.99.74</td><td>34.96.120.25</td><td>35.203.82.121</td><td>35.203.35.23</td><td>34.95.8.232</td></tr></tbody></table> **EMEA (Europe, Middle East, Africa)** | Region | Egress (tenant) | Live Terminal | EDR & Heartbeat | API Access | Indicator & Verdict request | Broker VM | | ------------------------------------- | --------------- | -------------- | --------------- | -------------- | --------------------------- | -------------- | | France (FA) | 34.111.134.57 | 34.163.57.57 | 34.36.155.211 | 34.155.222.152 | 34.155.110.169 | 34.155.90.61 | | Germany (DE) | 34.98.68.183 | 34.107.61.141 | 34.107.161.143 | 34.107.57.23 | 35.242.201.199 | 35.198.112.13 | | Israel (IL) | 34.111.129.144 | 34.165.43.106 | 34.128.157.130 | 34.165.156.139 | 34.165.2.110 | 34.165.24.222 | @@ -38,21 +25,13 @@ The following tables list the required resources by region. Unless specified, al | <p>Netherlands/</p><p>Europe (EU)</p> | 35.227.237.180 | 35.244.251.25 | 34.102.140.103 | 34.90.67.58 | 34.90.71.103 | 34.91.128.226 | | Poland (PL) | 34.117.240.208 | 34.118.62.80 | 35.190.13.237 | 34.116.216.55 | 34.116.213.71 | 34.116.176.97 | | Qatar (QT) | 35.190.0.180 | 34.18.34.73 | 34.107.129.254 | 34.18.46.240 | 34.18.53.229 | 34.18.37.73 | | Saudi Arabia (SA) | 35.244.157.127 | 34.166.54.6 | 34.107.213.85 | 34.166.58.79 | 34.166.53.160 | 34.166.55.153 | | South Africa (ZA) | 34.149.165.12 | 34.35.56.170 | 35.190.79.68 | 34.35.64.191 | 34.35.13.198 | 34.35.45.251 | | Spain (ES) | 34.111.188.248 | 34.175.18.78 | 34.120.102.147 | 34.175.30.176 | 34.175.205.166 | 34.175.182.55 | | Switzerland (CH) | 34.111.6.153 | 34.65.213.226 | 34.149.180.250 | 34.65.248.119 | 34.65.137.215 | 34.65.51.103 | | United Kingdom (UK) | 34.120.87.77 | 35.242.159.176 | 35.244.133.254 | 34.89.56.78 | 34.89.42.214 | 35.197.219.110 | +| Finland (FI) | 34.160.63.63 | 34.88.31.230 | 136.110.165.34 | 35.228.73.215 | 35.228.118.177 | | **JPAC (Asia-Pacific)** -| Region | Egress (tenant) | Live Terminal | EDR & Heartbeat | API Access | Indicator & Verdict Requests | Broker VM | -| ---------------- | --------------- | -------------- | --------------- | -------------- | ---------------------------- | -------------- | -| Australia (AU) | 34.120.229.65 | 35.244.66.177 | 34.102.237.151 | 35.189.18.208 | 35.201.23.188 | 35.244.93.0 | -| Delhi (DL) | 34.8.67.192 | 34.131.116.135 | 136.110.132.208 | 34.131.165.103 | 34.131.47.126 | 34.131.131.141 | -| India (IN) | 35.186.207.80 | 35.200.146.253 | 34.120.213.187 | 35.200.158.164 | 35.244.57.196 | 35.200.234.99 | -| Indonesia (ID) | 34.111.58.152 | 34.101.214.157 | 34.128.156.84 | 34.128.115.238 | 34.101.155.198 | 34.101.101.170 | -| Japan (JP) | 35.241.28.254 | 34.84.201.32 | 34.95.66.187 | 34.84.125.129 | 34.84.225.105 | 34.85.74.43 | -| Singapore (SG) | 34.117.211.129 | 34.87.61.186 | 34.120.142.18 | 34.87.83.144 | 35.247.161.94 | 34.87.167.125 | -| South Korea (KR) | 34.54.5.247 | 34.22.66.91 | 34.54.155.245 | 34.64.54.175 | 34.64.228.117 | 34.64.46.249 | -| Taiwan (TW) | 34.160.28.41 | 34.80.34.30 | 34.149.248.76 | 35.234.8.249 | 35.229.186.216 | 34.80.230.166 | +<table><thead><tr><th>Region</th><th>Egress (tenant)</th><th>Live Terminal</th><th width="143">EDR & Heartbeat</th><th>API Access</th><th>Indicator & Verdict Requests</th><th>Broker VM</th></tr></thead><tbody><tr><td>Australia (AU)</td><td>34.120.229.65</td><td>35.244.66.177</td><td>34.102.237.151</td><td>35.189.18.208</td><td>35.201.23.188</td><td>35.244.93.0</td></tr><tr><td>Delhi (DL)</td><td>34.8.67.192</td><td>34.131.116.135</td><td>136.110.132.208</td><td>34.131.165.103</td><td>34.131.47.126</td><td>34.131.131.141</td></tr><tr><td>India (IN)</td><td>35.186.207.80</td><td>35.200.146.253</td><td>34.120.213.187</td><td>35.200.158.164</td><td>35.244.57.196</td><td>35.200.234.99</td></tr><tr><td>Indonesia (ID)</td><td>34.111.58.152</td><td>34.101.214.157</td><td>34.128.156.84</td><td>34.128.115.238</td><td>34.101.155.198</td><td>34.101.101.170</td></tr><tr><td>Japan (JP)</td><td>35.241.28.254</td><td>34.84.201.32</td><td>34.95.66.187</td><td>34.84.125.129</td><td>34.84.225.105</td><td>34.85.74.43</td></tr><tr><td>Singapore (SG)</td><td>34.117.211.129</td><td>34.87.61.186</td><td>34.120.142.18</td><td>34.87.83.144</td><td>35.247.161.94</td><td>34.87.167.125</td></tr><tr><td>South Korea (KR)</td><td>34.54.5.247</td><td>34.22.66.91</td><td>34.54.155.245</td><td>34.64.54.175</td><td>34.64.228.117</td><td>34.64.46.249</td></tr><tr><td>Taiwan (TW)</td><td>34.160.28.41</td><td>34.80.34.30</td><td>34.149.248.76</td><td>35.234.8.249</td><td>35.229.186.216</td><td>34.80.230.166</td></tr></tbody></table>
-
▸ ▾ Integrate a syslog receiver modified +1 −0 Adds Finland (FI) syslog forwarding addresses 34.88.235.28 and 34.88.248.229.
xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xsiam-to-external-services/configure-external-applications-for-forwarding/integrate-a-syslog-receiverRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -16,16 +16,17 @@ Before you begin, enable access to the following Cortex XSIAM IP addresses for yUnited States - Government│104.198.222.185, 35.239.59.210United States - Government│104.198.222.185, 35.239.59.210Brazil (BR)│35.247.234.13, 34.39.178.116Brazil (BR)│35.247.234.13, 34.39.178.116Canada (CA)│35.203.54.204, 35.203.52.255Canada (CA)│35.203.54.204, 35.203.52.255endtabendtabtab EMEA (Europe, Middle East, Africa)tab EMEA (Europe, Middle East, Africa)Region│Log Forwarding IP AddressesRegion│Log Forwarding IP Addresses| ------------------------- | ------------------------------ || ------------------------- | ------------------------------ |Finland (FI)│34.88.235.28, 34.88.248.229France (FA)│34.163.100.253, 34.155.72.149France (FA)│34.163.100.253, 34.155.72.149Germany (DE)│35.234.95.96, 35.246.192.146Germany (DE)│35.234.95.96, 35.246.192.146Israel (IL)│34.165.194.4, 34.165.101.105Israel (IL)│34.165.194.4, 34.165.101.105Italy (IT)│34.154.0.173, 34.154.71.94Italy (IT)│34.154.0.173, 34.154.71.94Netherlands - Europe (EU)│34.90.202.186, 34.90.105.250Netherlands - Europe (EU)│34.90.202.186, 34.90.105.250Poland (PL)│34.118.45.145, 34.118.126.170Poland (PL)│34.118.45.145, 34.118.126.170Qatar (QT)│34.18.48.182, 34.18.43.40Qatar (QT)│34.18.48.182, 34.18.43.40Saudi Arabia (SA)│34.166.50.215, 34.166.55.72Saudi Arabia (SA)│34.166.50.215, 34.166.55.72Show markdown source
@@ -16,16 +16,17 @@ Before you begin, enable access to the following Cortex XSIAM IP addresses for y | United States - Government | 104.198.222.185, 35.239.59.210 | | Brazil (BR) | 35.247.234.13, 34.39.178.116 | | Canada (CA) | 35.203.54.204, 35.203.52.255 | {% endtab %} {% tab title="EMEA (Europe, Middle East, Africa)" %} | Region | Log Forwarding IP Addresses | | ------------------------- | ------------------------------ | +| Finland (FI) | 34.88.235.28, 34.88.248.229 | | France (FA) | 34.163.100.253, 34.155.72.149 | | Germany (DE) | 35.234.95.96, 35.246.192.146 | | Israel (IL) | 34.165.194.4, 34.165.101.105 | | Italy (IT) | 34.154.0.173, 34.154.71.94 | | Netherlands - Europe (EU) | 34.90.202.186, 34.90.105.250 | | Poland (PL) | 34.118.45.145, 34.118.126.170 | | Qatar (QT) | 34.18.48.182, 34.18.43.40 | | Saudi Arabia (SA) | 34.166.50.215, 34.166.55.72 |