Documentation — August 09, 2026
8 files changed, 197 insertions, 140 deletions — view the commit on the mirror.
Cribl gains a generic-UUID onboarding workflow; dev tenant now syncs case fields and layouts
Cortex XSIAM data-source docs got one substantial new workflow and one small feature note; the rest of the day’s docs changes were formatting cleanup with no content change.
- Cribl generic UUID ingestion: a new step-by-step section explains how to onboard a data source that isn’t in Cribl’s dedicated UUID catalog — create a pipeline, set
__sourceIdentifier/__vendor/__productfields, and route the data to the XSIAM destination. - Dev tenant sync: “Case fields and layouts” joins the list of content types Cortex XSIAM can push/pull with a remote repository.
- Syslog Collector applet: its content-pack/integration links table now scopes itself to integrations “onboarded prior to July 26, 2026”.
- Three broker VM applet pages (DSPM Fileshare, Local Agent Settings, Network Mapper) were reformatted into call-out boxes with bolded UI labels — the instructions themselves did not change.
- The Cribl UUID reference table’s cross-links were rewritten from opaque short links to descriptive relative paths pointing at the actual vendor pages.
Highlights
-
Cribl gains a generic-UUID onboarding workflow
New "Apply XSIAM pack using generic UUID collector" section walks through creating a dedicated pipeline, setting __sourceIdentifier/__vendor/__product fields, and building a route — for data sources not in Cribl's dedicated UUID catalog.
-
Case fields and layouts now sync via remote repository
Added to the list of push/pull-supported content types on the Cortex XSIAM development tenant page.
-
Syslog Collector applet scopes its content-pack links to a cutoff date
The integration-links table header now reads "Links to content pack/integration details (onboarded prior to July 26, 2026)".
-
Three broker VM applet pages reformatted, not rewritten
DSPM Fileshare, Local Agent Settings, and Network Mapper pages now wrap License/Prerequisite notes in call-out boxes and bold UI labels; the instructions themselves are unchanged.
Changes
8 files listed, 8 written up and shaded below.
-
▸ ▾ Activate DSPM Fileshare modified +13 −9 Reformats the License and Prerequisite sections into call-out boxes and bolds UI labels; no content change.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-dspm-fileshareRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,51 +1,55 @@# Activate DSPM Fileshare# Activate DSPM Fileshare### License typehint infoLicenseThis feature is included with a Cortex XSIAM Premium license. It is also included with a Cortex XSIAM NG SIEM and Cortex XSIAM Enterprise license that has the Cloud Posture Security or Cloud Runtime Security add-on.This feature is included with a Cortex XSIAM Premium license. It is also included with a Cortex XSIAM NG SIEM and Cortex XSIAM Enterprise license that has the Cloud Posture Security or Cloud Runtime Security add-on.endhint### Prerequisitehint warningPrerequisite• Set up and configure Broker VM• Set up and configure Broker VM• Know the complete path to the files and folders that you want Cortex XSIAM to monitor.• Know the complete path to the files and folders that you want Cortex XSIAM to monitor.• Necessary user permissions to access the network shares. For the SMB connection type, you need the user name and password.• Necessary user permissions to access the network shares. For the SMB connection type, you need the user name and password.endhint### How to activate the DSPM Fileshare applet### How to activate the DSPM Fileshare applet1. Select Settings → Configurations → Data Broker → Broker VMs.1. Select Settings → Configurations → Data Broker → Broker VMs.2. On the Brokers tab, find Broker VM, and in the APPS column, click + ADD. In the list of applets, click DSPM Fileshare.2. On the Brokers tab, find Broker VM, and in the APPS column, click + ADD. In the list of applets, click DSPM Fileshare.<div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>The applet list displays only the applets for which you have permissions.</p></div><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>The applet list displays only the applets for which you have permissions.</p></div>3. Configure the DSPM Fileshare settings according to the following steps.3. Configure the DSPM Fileshare settings according to the following steps.#### File Share Connection#### File Share ConnectionField│DescriptionField│Description| --------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || --------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Connection Type│* NFS (Network File System): A distributed file system protocol that lets networked computers share files remotely, making them appear as if they're stored locally. Operating at the application layer, it uses Remote Procedure Calls (RPCs) for clients to access a server's files and directories.
* SMB (Server Message Block): A network file-sharing protocol that provides shared access to resources like files, printers, and serial ports across a network. It enables client applications to remotely interact with files and other assets stored on a server. It is the default file-sharing protocol for Microsoft Windows operating systems. This connection type requires a username and a password.Connection Type│* NFS (Network File System): A distributed file system protocol that lets networked computers share files remotely, making them appear as if they're stored locally. Operating at the application layer, it uses Remote Procedure Calls (RPCs) for clients to access a server's files and directories.
* SMB (Server Message Block): A network file-sharing protocol that provides shared access to resources like files, printers, and serial ports across a network. It enables client applications to remotely interact with files and other assets stored on a server. It is the default file-sharing protocol for Microsoft Windows operating systems. This connection type requires a username and a password.Path│Specify the host and path to the folder containing the files that you want Cortex Cloud Data Security to monitor.Path│Specify the host and path to the folder containing the files that you want Cortex Cloud Data Security to monitor.Username│For the SMB connection type only.Username│For the SMB connection type only.Password│For the SMB connection type only.Password│For the SMB connection type only.Test Connection│Select to validate the connection permissions.Test Connection│Select to validate the connection permissions.<div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>By default, all configured connections are saved.</p></div><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>By default, all configured connections are saved.</p></div>4. On the File Share Connection screen, click + Add a Connection.4. On the File Share Connection screen, click + Add a Connection.<div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>For details regarding the connection fields, see the table above under File Share Connection.</p></div><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>For details regarding the connection fields, see the table above under File Share Connection.</p></div>5. In the File Share Connection field, replace the text with a name for the new connection.5. In the File Share Connection field, replace the text with a name for the new connection.6. Select a connection type.6. Select a connection type.7. Provide the path to the shared folder (the host and path).7. Provide the path to the shared folder (the host and path).8. For SMB connections only, provide a username and password.8. For SMB connections only, provide a username and password.9. Optionally, do the following:9. Optionally, do the following:1. Turn on the Classification toggle. This enables 2,500 random files to be scanned and classified each time.1. Turn on the Classification toggle. This enables 2,500 random files to be scanned and classified each time.2. In the Scan every list, select the cadence of how often the files are to be scanned. If you want the scans to occur less frequently, choose the Custom option and enter the amount of days, weeks, or months that you require.2. In the Scan every list, select the cadence of how often the files are to be scanned. If you want the scans to occur less frequently, choose the Custom option and enter the amount of days, weeks, or months that you require.10. Click Test Connection to ensure the connection works properly.10. Click Test Connection to ensure the connection works properly.11. Click Save.11. Click Save.hint infohint infoNoteNoteYou can add multiple connections under a single instance of the DSPM Fileshare applet by returning to the File Share Connection screen and clicking Add Connection. Each new connection can be of either the NFS or SMB connection type.You can add multiple connections under a single instance of the DSPM Fileshare applet by returning to the File Share Connection screen and clicking Add Connection. Each new connection can be of either the NFS or SMB connection type.endhintendhint### Other actions### Other actions@@ -53,9 +57,9 @@ You can add multiple connections under a single instance of the DSPM Fileshare aOnce the DSPM Fileshare applet is activated, you can perform the following actions:Once the DSPM Fileshare applet is activated, you can perform the following actions:• Edit• Edit• Deactivate: On the Broker VMs screen, in the ADD column, in the context menu, click Deactivate.• Deactivate: On the Broker VMs screen, in the ADD column, in the context menu, click Deactivate.• Delete: On the File Share Connection screen, click the Delete icon next to the connection you want to remove.• Delete: On the File Share Connection screen, click the Delete icon next to the connection you want to remove.### Inventory list### Inventory listEach new connection that is created correlates to an asset in the inventory. You can see the connections by clicking Inventory → All Assets → Data → Storage Buckets.Each new connection that is created correlates to an asset in the inventory. You can see the connections by clicking Inventory → All Assets → Data → Storage Buckets.Show markdown source
@@ -1,51 +1,55 @@ # Activate DSPM Fileshare -### License type +{% hint style="info" %} +**License** This feature is included with a Cortex XSIAM Premium license. It is also included with a Cortex XSIAM NG SIEM and Cortex XSIAM Enterprise license that has the Cloud Posture Security or Cloud Runtime Security add-on. +{% endhint %} -### Prerequisite +{% hint style="warning" %} +Prerequisite * [Set up and configure Broker VM](../../../data-management/broker-vm/set-up-and-configure-broker-vm) * Know the complete path to the files and folders that you want Cortex XSIAM to monitor. * Necessary user permissions to access the network shares. For the SMB connection type, you need the user name and password. +{% endhint %} ### How to activate the DSPM Fileshare applet -1. Select Settings → Configurations → Data Broker → Broker VMs. -2. On the Brokers tab, find Broker VM, and in the APPS column, click + ADD. In the list of applets, click DSPM Fileshare. +1. Select **Settings** → **Configurations** → **Data Broker** → **Broker VMs**. +2. On the **Brokers** tab, find Broker VM, and in the **APPS** column, click **+ ADD**. In the list of applets, click **DSPM Fileshare**. <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>The applet list displays only the applets for which you have permissions.</p></div> 3. Configure the DSPM Fileshare settings according to the following steps. #### File Share Connection | Field | Description | | --------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Connection Type | <p>* <strong>NFS (Network File System):</strong> A distributed file system protocol that lets networked computers share files remotely, making them appear as if they're stored locally. Operating at the application layer, it uses Remote Procedure Calls (RPCs) for clients to access a server's files and directories.<br><br>* <strong>SMB (Server Message Block):</strong> A network file-sharing protocol that provides shared access to resources like files, printers, and serial ports across a network. It enables client applications to remotely interact with files and other assets stored on a server. It is the default file-sharing protocol for Microsoft Windows operating systems. This connection type requires a username and a password.</p> | | Path | Specify the host and path to the folder containing the files that you want Cortex Cloud Data Security to monitor. | | Username | For the SMB connection type only. | | Password | For the SMB connection type only. | | Test Connection | Select to validate the connection permissions. | <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>By default, all configured connections are saved.</p></div> -4. On the File Share Connection screen, click + Add a Connection. +4. On the **File Share Connection** screen, click **+ Add a Connection**. <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>For details regarding the connection fields, see the table above under File Share Connection.</p></div> -5. In the File Share Connection field, replace the text with a name for the new connection. +5. In the **File Share Connection** field, replace the text with a name for the new connection. 6. Select a connection type. 7. Provide the path to the shared folder (the host and path). 8. For SMB connections only, provide a username and password. 9. Optionally, do the following: 1. Turn on the Classification toggle. This enables 2,500 random files to be scanned and classified each time. 2. In the Scan every list, select the cadence of how often the files are to be scanned. If you want the scans to occur less frequently, choose the Custom option and enter the amount of days, weeks, or months that you require. -10. Click Test Connection to ensure the connection works properly. -11. Click Save. +10. Click **Test Connection** to ensure the connection works properly. +11. Click **Save**. {% hint style="info" %} **Note** You can add multiple connections under a single instance of the DSPM Fileshare applet by returning to the File Share Connection screen and clicking Add Connection. Each new connection can be of either the NFS or SMB connection type. {% endhint %} ### Other actions @@ -53,9 +57,9 @@ You can add multiple connections under a single instance of the DSPM Fileshare a Once the DSPM Fileshare applet is activated, you can perform the following actions: * Edit * **Deactivate:** On the Broker VMs screen, in the ADD column, in the context menu, click Deactivate. * **Delete:** On the File Share Connection screen, click the Delete icon next to the connection you want to remove. ### Inventory list -Each new connection that is created correlates to an asset in the inventory. You can see the connections by clicking Inventory → All Assets → Data → Storage Buckets. +Each new connection that is created correlates to an asset in the inventory. You can see the connections by clicking **Inventory** → **All Assets** → **Data** → **Storage Buckets**. -
▸ ▾ Activate Local Agent Settings modified +6 −4 Adds a bold "License" label inside the existing license call-out; no content change.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-local-agent-settingsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,11 +1,13 @@# Activate Local Agent Settings# Activate Local Agent Settingshint infohint infoLicenseThis feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM license that includes endpoints or Cortex Cloud Runtime Security.This feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM license that includes endpoints or Cortex Cloud Runtime Security.endhintendhintThe Local Agent Settings applet on the Palo Alto Networks Broker VM enables you to:The Local Agent Settings applet on the Palo Alto Networks Broker VM enables you to:Deploy the Broker VM proxyDeploy the Broker VM proxy@@ -80,18 +82,18 @@ The broker needs to communicate with the same URLs that the agents communicate w</details></details>How to activate the Local Agent Settings appletHow to activate the Local Agent Settings appletAfter you configure and register your Palo Alto Networks Broker VM, proceed to set up your Local Agent Settings applet.After you configure and register your Palo Alto Networks Broker VM, proceed to set up your Local Agent Settings applet.1. Select Settings → Configurations → Data Broker → Broker VMs.1. Select Settings → Configurations → Data Broker → Broker VMs.2. In either the Brokers tab or the Clusters tab, locate your Broker VM.2. In either the Brokers tab or the Clusters tab, locate your Broker VM.3. (Optional) To set up the Agent Proxy:3. (Optional) To set up the Agent Proxy:a. Right-click the Broker VM and select **Configure**.a. Right-click the Broker VM and select **Configure**.Ensure your proxy server is configured. If not, add it as described in Set up and configure Broker VM.Ensure your proxy server is configured. If not, add it as described in Set up and configure Broker VM.b. In the **APPS** column, select **Add** → **Local Agent Settings**.b. In the **APPS** column, select **Add** → **Local Agent Settings**.@@ -120,12 +122,12 @@ After you configure and register your Palo Alto Networks Broker VM, proceed to s<div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p><strong>Important</strong></p><p>You can enable Agent Installer and Content Caching only after uploading a signed SSL Server Certificate and key, and setting the FQDN. For more information, see the Agent Installer and Content Caching requirements above.</p></div><div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p><strong>Important</strong></p><p>You can enable Agent Installer and Content Caching only after uploading a signed SSL Server Certificate and key, and setting the FQDN. For more information, see the Agent Installer and Content Caching requirements above.</p></div>e. To enable agents to use Broker VM caching, add the Broker VM as a download source in your Agent Settings profile. Select the Broker VMs to use. Ensure the profile is associated with a policy for your target agents.e. To enable agents to use Broker VM caching, add the Broker VM as a download source in your Agent Settings profile. Select the Broker VMs to use. Ensure the profile is associated with a policy for your target agents.5. After a successful activation, the APPS field displays Local Agent Settings with a green dot indicating a successful connection. Left-click the Local Agent Settings connection to view the applet status and resource usage.\5. After a successful activation, the APPS field displays Local Agent Settings with a green dot indicating a successful connection. Left-click the Local Agent Settings connection to view the applet status and resource usage.\To help you easily troubleshoot connectivity issues for a Local Agent Settings applet on the Palo Alto Networks Broker VM, Cortex XSIAM displays a list of Denied URLs. These URLs are displayed when you left-click the Local Agent Settings applet to view the Connectivity Status. As a result, in a situation where the Local Agent Settings applet is reported as activated with a failed connection, you can easily determine the URLs that need to be allowed in your network environment.To help you easily troubleshoot connectivity issues for a Local Agent Settings applet on the Palo Alto Networks Broker VM, Cortex XSIAM displays a list of Denied URLs. These URLs are displayed when you left-click the Local Agent Settings applet to view the Connectivity Status. As a result, in a situation where the Local Agent Settings applet is reported as activated with a failed connection, you can easily determine the URLs that need to be allowed in your network environment.6. Manage the local agent settings. After the local agent settings have been activated, left-click the Local Agent Settings connection in the APPS column to display the settings, and select:6. Manage the local agent settings. After the local agent settings have been activated, left-click the Local Agent Settings connection in the APPS column to display the settings, and select:• Configure to change your settings.• Configure to change your settings.• Deactivate to disable the local agent settings altogether.• Deactivate to disable the local agent settings altogether.</details></details>Show markdown source
@@ -1,11 +1,13 @@ # Activate Local Agent Settings {% hint style="info" %} +**License** + This feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM license that includes endpoints or Cortex Cloud Runtime Security. {% endhint %} The Local Agent Settings applet on the Palo Alto Networks Broker VM enables you to: <details> <summary>Deploy the Broker VM proxy</summary> @@ -80,18 +82,18 @@ The broker needs to communicate with the same URLs that the agents communicate w </details> <details> <summary>How to activate the Local Agent Settings applet</summary> After you configure and register your Palo Alto Networks Broker VM, proceed to set up your Local Agent Settings applet. -1. Select Settings → Configurations → Data Broker → Broker VMs. -2. In either the Brokers tab or the Clusters tab, locate your Broker VM. +1. Select **Settings** → **Configurations** → **Data Broker** → **Broker VMs**. +2. In either the **Brokers** tab or the **Clusters** tab, locate your Broker VM. 3. (Optional) To set up the Agent Proxy: a. Right-click the Broker VM and select **Configure**. Ensure your proxy server is configured. If not, add it as described in Set up and configure Broker VM. b. In the **APPS** column, select **Add** → **Local Agent Settings**. @@ -120,12 +122,12 @@ After you configure and register your Palo Alto Networks Broker VM, proceed to s <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p><strong>Important</strong></p><p>You can enable Agent Installer and Content Caching only after uploading a signed SSL Server Certificate and key, and setting the FQDN. For more information, see the Agent Installer and Content Caching requirements above.</p></div> e. To enable agents to use Broker VM caching, add the Broker VM as a download source in your Agent Settings profile. Select the Broker VMs to use. Ensure the profile is associated with a policy for your target agents. 5. After a successful activation, the APPS field displays Local Agent Settings with a green dot indicating a successful connection. Left-click the Local Agent Settings connection to view the applet status and resource usage.\ To help you easily troubleshoot connectivity issues for a Local Agent Settings applet on the Palo Alto Networks Broker VM, Cortex XSIAM displays a list of Denied URLs. These URLs are displayed when you left-click the Local Agent Settings applet to view the Connectivity Status. As a result, in a situation where the Local Agent Settings applet is reported as activated with a failed connection, you can easily determine the URLs that need to be allowed in your network environment. 6. Manage the local agent settings. After the local agent settings have been activated, left-click the Local Agent Settings connection in the APPS column to display the settings, and select: -* Configure to change your settings. -* Deactivate to disable the local agent settings altogether. +* **Configure** to change your settings. +* **Deactivate** to disable the local agent settings altogether. </details> -
▸ ▾ Activate Network Mapper modified +14 −12 Wraps the Prerequisite note in a call-out box and bolds UI labels; no content change.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-network-mapperRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,51 +1,53 @@# Activate Network Mapper# Activate Network Mapperhint infohint infoThis feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM license that includes endpoints or Cortex Cloud Runtime Security.This feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM license that includes endpoints or Cortex Cloud Runtime Security.endhintendhinthint warning### Prerequisite### PrerequisiteAfter you have configured and registered your Broker VM, you can choose to activate the Network Mapper application.After you have configured and registered your Broker VM, you can choose to activate the Network Mapper application.endhintThe Network Mapper allows you to scan your network to detect and identify unmanaged hosts in your environment according to defined IP address ranges. The Network Mapper configurations are used to locate unmanaged assets that appear in the Assets table. For more information, see All assets.The Network Mapper allows you to scan your network to detect and identify unmanaged hosts in your environment according to defined IP address ranges. The Network Mapper configurations are used to locate unmanaged assets that appear in the Assets table. For more information, see All assets.1. Select Settings → Configurations → Data Broker → Broker VMs.1. Select Settings → Configurations → Data Broker → Broker VMs.2. Do one of the following:2. Do one of the following:• On the Brokers tab, find the Broker VM, and in the APPS column, left-click Add → Network Mapper.• On the Brokers tab, find the Broker VM, and in the APPS column, left-click Add → Network Mapper.• On the Clusters tab, find the Broker VM, and in the APPS column, left-click Add → Network Mapper.• On the Clusters tab, find the Broker VM, and in the APPS column, left-click Add → Network Mapper.3. In the Activate Network Mapper window, define the following parameters:3. In the Activate Network Mapper window, define the following parameters:Field│DescriptionField│Description| ------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Scan Method│Select the either ICMP echo or TCP SYN scan method to identify your network hosts. When selecting TCP SYN you can enter single ports and ranges together, for example80-83, 443.Scan Method│Select the either ICMP echo or TCP SYN scan method to identify your network hosts. When selecting TCP SYN you can enter single ports and ranges together, for example80-83, 443.Scan Requests per Second│Define the maximum number of scan requests you want to send on your network per second. By default, the number of scan requests are defined as 1000.Each IP address range can receive multiple scan requests based on it's availability.
Scan Requests per Second│Define the maximum number of scan requests you want to send on your network per second. By default, the number of scan requests are defined as 1000.Each IP address range can receive multiple scan requests based on it's availability.
Scanning Scheduler│Define when you want to run the network mapper scan. You can select either daily, weekly, or monthly at a specific time.Scanning Scheduler│Define when you want to run the network mapper scan. You can select either daily, weekly, or monthly at a specific time.4. Activate the applet.4. Activate the applet.After a successful activation, the APPS field displays Network Mapper with a green dot indicating a successful connection.After a successful activation, the **APPS** field displays **Network Mapper** with a green dot indicating a successful connection.5. In the APPS field, left-click the Network Mapper connection to view the following scan and applet metrics:5. In the APPS field, left-click the Network Mapper connection to view the following scan and applet metrics:**Scan Details****Scan Details**Field│DescriptionField│Description| ------------------- | --------------------------------------------------------------------------- || ------------------- | --------------------------------------------------------------------------- |Connectivity Status│Whether the applet is connected to Cortex XSIAM .Connectivity Status│Whether the applet is connected to Cortex XSIAM .Scan Status│State of the scan.Scan Status│State of the scan.Scan Start Time│Timestamp of when the scan started.Scan Start Time│Timestamp of when the scan started.Scan Duration│Period of time in minutes and seconds the scan is running.Scan Duration│Period of time in minutes and seconds the scan is running.Scan Progress│How much of the scan has been completed in percentage and IP address ratio.Scan Progress│How much of the scan has been completed in percentage and IP address ratio.Detected Hosts│Number of hosts identified from within the IP address ranges.Detected Hosts│Number of hosts identified from within the IP address ranges.Scan Rate│Number of IP addresses scanned per second.Scan Rate│Number of IP addresses scanned per second.**Applet Metrics****Applet Metrics**Resources: Displays the amount of CPU, Memory, and Disk space the applet is using.**Resources**: Displays the amount of CPU, Memory, and Disk space the applet is using.6. Manage the Network Mapper.6. Manage the Network Mapper.After the network mapper has been activated, left-click the Network Mapper connection in the APPS column to display the Network Mapper settings, and select:After the network mapper has been activated, left-click the **Network Mapper** connection in the **APPS** column to display the Network Mapper settings, and select:• Configure to redefine the network mapper configurations.• Configure to redefine the network mapper configurations.• Scan Now to initiate a scan.• Scan Now to initiate a scan.• Deactivate to disable the network mapper.• Deactivate to disable the network mapper.Show markdown source
@@ -1,51 +1,53 @@ # Activate Network Mapper {% hint style="info" %} This feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM license that includes endpoints or Cortex Cloud Runtime Security. {% endhint %} +{% hint style="warning" %} ### Prerequisite After you have configured and registered your Broker VM, you can choose to activate the Network Mapper application. +{% endhint %} The Network Mapper allows you to scan your network to detect and identify unmanaged hosts in your environment according to defined IP address ranges. The Network Mapper configurations are used to locate unmanaged assets that appear in the Assets table. For more information, see [All assets](../../../../detect-investigate-and-respond-to-threats/asset-management/all-assets). -1. Select Settings → Configurations → Data Broker → Broker VMs. +1. Select **Settings** → **Configurations** → **Data Broker** → **Broker VMs**. 2. Do one of the following: - * On the Brokers tab, find the Broker VM, and in the APPS column, left-click Add → Network Mapper. - * On the Clusters tab, find the Broker VM, and in the APPS column, left-click Add → Network Mapper. -3. In the Activate Network Mapper window, define the following parameters: + * On the **Brokers** tab, find the Broker VM, and in the **APPS** column, left-click **Add** → **Network Mapper**. + * On the **Clusters** tab, find the Broker VM, and in the **APPS** column, left-click **Add** → Network Mapper. +3. In the **Activate Network Mapper** window, define the following parameters: | Field | Description | | ------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Scan Method | Select the either ICMP echo or TCP SYN scan method to identify your network hosts. When selecting TCP SYN you can enter single ports and ranges together, for example **`80-83, 443`**. | | Scan Requests per Second | <p>Define the maximum number of scan requests you want to send on your network per second. By default, the number of scan requests are defined as 1000.</p><p>Each IP address range can receive multiple scan requests based on it's availability.</p> | | Scanning Scheduler | Define when you want to run the network mapper scan. You can select either daily, weekly, or monthly at a specific time. | | Scanned Ranges | <p>Select from the list of exiting IP address ranges to scan. Make sure to <a href="https://docs-cortex.paloaltonetworks.com/viewer/attachment/5CAbsl8idaK8R43ZLhoTOw/VCjuKTJTAMzK0ZPB8J~ndQ-5CAbsl8idaK8R43ZLhoTOw"><img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABcAAAATCAYAAAB7u5a2AAAACXBIWXMAABJ0AAASdAHeZh94AAAAB3RJTUUH5AgMCAMAHpkFNgAAAAd0RVh0QXV0aG9yAKmuzEgAAAAMdEVYdERlc2NyaXB0aW9uABMJISMAAAAKdEVYdENvcHlyaWdodACsD8w6AAAADnRFWHRDcmVhdGlvbiB0aW1lADX3DwkAAAAJdEVYdFNvZnR3YXJlAF1w/zoAAAALdEVYdERpc2NsYWltZXIAt8C0jwAAAAh0RVh0V2FybmluZwDAG+aHAAAAB3RFWHRTb3VyY2UA9f+D6wAAAAh0RVh0Q29tbWVudAD2zJa/AAAABnRFWHRUaXRsZQCo7tInAAAAuUlEQVQ4je3UoQ7CMBSF4b+wDDWFIkheAIFE8S4DjeAVMDgk7wBBYEdCgmcGN1EDamqCMLEVMQltMrKbIDimSW/ytTlJq4wxBqG0pOA/LouvTjDZCOFJCtlTCLfFie+vMFrDWTeMX+6wPIJSMOh+h3u2weIApQHfg9nWjaSPmnheVGtRQpa7cb8NveB9X9n+lvgG4Q4UEE0h6LgP+BRr58M+zMdVNVFSHwbHzZvI7z9/K661FsNFO38BxLk0cB8P23EAAAAASUVORK5CYII=" alt="network-mapper-enter.png"></a> after each selection.</p><p>IP address ranges are displayed according to what you defined as your Network Parameters.</p> | -4. Activate the applet. +4. **Activate** the applet. - After a successful activation, the APPS field displays Network Mapper with a green dot indicating a successful connection. -5. In the APPS field, left-click the Network Mapper connection to view the following scan and applet metrics: + After a successful activation, the **APPS** field displays **Network Mapper** with a green dot indicating a successful connection. +5. In the **APPS** field, left-click the **Network Mapper** connection to view the following scan and applet metrics: **Scan Details** | Field | Description | | ------------------- | --------------------------------------------------------------------------- | | Connectivity Status | Whether the applet is connected to Cortex XSIAM . | | Scan Status | State of the scan. | | Scan Start Time | Timestamp of when the scan started. | | Scan Duration | Period of time in minutes and seconds the scan is running. | | Scan Progress | How much of the scan has been completed in percentage and IP address ratio. | | Detected Hosts | Number of hosts identified from within the IP address ranges. | | Scan Rate | Number of IP addresses scanned per second. | **Applet Metrics** - Resources: Displays the amount of CPU, Memory, and Disk space the applet is using. + **Resources**: Displays the amount of CPU, Memory, and Disk space the applet is using. 6. Manage the Network Mapper. - After the network mapper has been activated, left-click the Network Mapper connection in the APPS column to display the Network Mapper settings, and select: + After the network mapper has been activated, left-click the **Network Mapper** connection in the **APPS** column to display the Network Mapper settings, and select: - * Configure to redefine the network mapper configurations. - * Scan Now to initiate a scan. - * Deactivate to disable the network mapper. + * **Configure** to redefine the network mapper configurations. + * **Scan Now** to initiate a scan. + * **Deactivate** to disable the network mapper. -
▸ ▾ Syslog Collector applet modified +6 −6 Content pack/integration links table now notes it covers sources onboarded prior to July 26, 2026.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-appletRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@# Syslog Collector applet# Syslog Collector appletThe Syslog Collector applet on a Broker VM enables you to collect Syslog data from an external source:The Syslog Collector applet on a Broker VM enables you to collect Syslog data from an external source:Syslog Collector applet│DescriptionSyslog Collector applet│Description| ------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ---------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |How to activate Syslog Collector?│Activate Syslog CollectorHow to activate Syslog Collector?│Activate Syslog CollectorHow to ingest logs from a Syslog receiver?│Ingest logs from a Syslog receiverHow to ingest logs from a Syslog receiver?│Ingest logs from a Syslog receiverDifferent types of vendor logs to ingest with a Syslog Collector applet:│Different types of vendor logs to ingest with a Syslog Collector applet:│Links to content pack/integration details│The Syslog content pack enables automated issue creation by acting as a Syslog server for incoming logs, while also allowing the platform to act as a Syslog client to send messages and mirror investigation activities to external Syslog destinations. It contains the following integrations:
- Syslog Sender: Use this integration to send messages in RFC 5424 message format and mirror incident War Room entries to Syslog. It includes the
mirror-investigation,send-notification, andsyslog-sendcommands. - Syslog v2: Use this integration to act as a long-running Syslog server, supporting RFC3164, RFC5424, and RFC6587 formats, which enables automatically opening issues from Syslog clients. This integration is configured using parameters such as Port mapping, Certificate, Private Key, and a Message Regex Filter for issue creation.
Links to content pack/integration details (onboarded prior to July 26, 2026)│The Syslog content pack enables automated issue creation by acting as a Syslog server for incoming logs, while also allowing the platform to act as a Syslog client to send messages and mirror investigation activities to external Syslog destinations. It contains the following integrations:
- Syslog Sender: Use this integration to send messages in RFC 5424 message format and mirror incident War Room entries to Syslog. It includes the
mirror-investigation,send-notification, andsyslog-sendcommands. - Syslog v2: Use this integration to act as a long-running Syslog server, supporting RFC3164, RFC5424, and RFC6587 formats, which enables automatically opening issues from Syslog clients. This integration is configured using parameters such as Port mapping, Certificate, Private Key, and a Message Regex Filter for issue creation.
Show markdown source
@@ -1,10 +1,10 @@ # Syslog Collector applet The Syslog Collector applet on a Broker VM enables you to collect Syslog data from an external source: -| Syslog Collector applet | Description | -| ------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| How to activate Syslog Collector? | [Activate Syslog Collector](syslog-collector-applet/activate-syslog-collector) | -| How to ingest logs from a Syslog receiver? | [Ingest logs from a Syslog receiver](syslog-collector-applet/ingest-logs-from-a-syslog-receiver) | -| Different types of vendor logs to ingest with a Syslog Collector applet: | <ul><li><a href="syslog-collector-applet/check-point-fw1-vpn1">Check Point FW1/VPN1</a></li><li><a href="syslog-collector-applet/cisco-asa-firewalls-and-anyconnect">Cisco ASA firewalls and AnyConnect</a></li><li><a href="syslog-collector-applet/corelight-zeek">Corelight Zeek</a></li><li><a href="syslog-collector-applet/forcepoint-dlp">Forcepoint DLP</a></li><li><a href="syslog-collector-applet/fortinet-fortigate">Fortinet Fortigate</a></li><li><a href="syslog-collector-applet/next-generation-firewall">Next-Generation Firewall</a></li><li><a href="syslog-collector-applet/pingfederate">PingFederate</a></li><li><a href="syslog-collector-applet/zscaler-internet-access">Zscaler Internet Access</a></li><li><a href="syslog-collector-applet/zscaler-private-access">Zscaler Private Access</a></li></ul> | -| Links to content pack/integration details | <p>The <a href="https://xsoar.pan.dev/docs/reference/integrations/syslog-v2">Syslog</a> content pack enables automated issue creation by acting as a Syslog server for incoming logs, while also allowing the platform to act as a Syslog client to send messages and mirror investigation activities to external Syslog destinations. It contains the following integrations:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/syslog-sender">Syslog Sender</a>: Use this integration to send messages in RFC 5424 message format and mirror incident War Room entries to Syslog. It includes the <strong><code>mirror-investigation</code></strong>, <strong><code>send-notification</code></strong>, and <strong><code>syslog-send</code></strong> commands.</li><li><a href="https://xsoar.pan.dev/docs/reference/integrations/syslog-v2">Syslog v2</a>: Use this integration to act as a long-running Syslog server, supporting RFC3164, RFC5424, and RFC6587 formats, which enables automatically opening issues from Syslog clients. This integration is configured using parameters such as Port mapping, Certificate, Private Key, and a Message Regex Filter for issue creation.</li></ul> | +| Syslog Collector applet | Description | +| ---------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| How to activate Syslog Collector? | [Activate Syslog Collector](syslog-collector-applet/activate-syslog-collector) | +| How to ingest logs from a Syslog receiver? | [Ingest logs from a Syslog receiver](syslog-collector-applet/ingest-logs-from-a-syslog-receiver) | +| Different types of vendor logs to ingest with a Syslog Collector applet: | <ul><li><a href="syslog-collector-applet/check-point-fw1-vpn1">Check Point FW1/VPN1</a></li><li><a href="syslog-collector-applet/cisco-asa-firewalls-and-anyconnect">Cisco ASA firewalls and AnyConnect</a></li><li><a href="syslog-collector-applet/corelight-zeek">Corelight Zeek</a></li><li><a href="syslog-collector-applet/forcepoint-dlp">Forcepoint DLP</a></li><li><a href="syslog-collector-applet/fortinet-fortigate">Fortinet Fortigate</a></li><li><a href="syslog-collector-applet/next-generation-firewall">Next-Generation Firewall</a></li><li><a href="syslog-collector-applet/pingfederate">PingFederate</a></li><li><a href="syslog-collector-applet/zscaler-internet-access">Zscaler Internet Access</a></li><li><a href="syslog-collector-applet/zscaler-private-access">Zscaler Private Access</a></li></ul> | +| Links to content pack/integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://xsoar.pan.dev/docs/reference/integrations/syslog-v2">Syslog</a> content pack enables automated issue creation by acting as a Syslog server for incoming logs, while also allowing the platform to act as a Syslog client to send messages and mirror investigation activities to external Syslog destinations. It contains the following integrations:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/syslog-sender">Syslog Sender</a>: Use this integration to send messages in RFC 5424 message format and mirror incident War Room entries to Syslog. It includes the <strong><code>mirror-investigation</code></strong>, <strong><code>send-notification</code></strong>, and <strong><code>syslog-send</code></strong> commands.</li><li><a href="https://xsoar.pan.dev/docs/reference/integrations/syslog-v2">Syslog v2</a>: Use this integration to act as a long-running Syslog server, supporting RFC3164, RFC5424, and RFC6587 formats, which enables automatically opening issues from Syslog clients. This integration is configured using parameters such as Port mapping, Certificate, Private Key, and a Message Regex Filter for issue creation.</li></ul> |
- Syslog Sender: Use this integration to send messages in RFC 5424 message format and mirror incident War Room entries to Syslog. It includes the
-
▸ ▾ Ingest logs from a Syslog receiver modified +1 −1 Vendor-support cross-reference now points at the Syslog Collector applet page instead of an external GitBook link.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/ingest-logs-from-a-syslog-receiverRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,17 +1,17 @@------description: >-description: >-To extend visibility, Cortex XSIAM can receive Syslog from additional vendorsTo extend visibility, Cortex XSIAM can receive Syslog from additional vendorsthat use CEF or LEEF formatted over Syslog (TLS not supported).that use CEF or LEEF formatted over Syslog (TLS not supported).------# Ingest logs from a Syslog receiver# Ingest logs from a Syslog receiverCortex XSIAM can receive Syslog from a variety of supported vendors (see External data ingestion vendor support). In addition, Cortex XSIAM can receive Syslog from additional vendors that use CEF, LEEF, CISCO, CORELIGHT, or RAW formatted over Syslog.External data ingestion vendor supportCortex XSIAM can receive Syslog from a variety of supported vendors (see Syslog Collector applet). In addition, Cortex XSIAM can receive Syslog from additional vendors that use CEF, LEEF, CISCO, CORELIGHT, or RAW formatted over Syslog.External data ingestion vendor supportAfter Cortex XSIAM begins receiving logs from the third-party source, Cortex XSIAM automatically parses the logs in CEF, LEEF, CISCO, CORELIGHT, or RAW format and creates a dataset with the name<vendor>_<product>_raw. You can then use XQL Search queries to view logs and create new IOC, BIOC, and Correlation Rules.After Cortex XSIAM begins receiving logs from the third-party source, Cortex XSIAM automatically parses the logs in CEF, LEEF, CISCO, CORELIGHT, or RAW format and creates a dataset with the name<vendor>_<product>_raw. You can then use XQL Search queries to view logs and create new IOC, BIOC, and Correlation Rules.To receive Syslog from an external source:To receive Syslog from an external source:1. Set up your Syslog receiver to forward logs.1. Set up your Syslog receiver to forward logs.2. Activate the Syslog collector applet on a Broker VM within your network. For more information, see Activate the Syslog Collector.2. Activate the Syslog collector applet on a Broker VM within your network. For more information, see Activate the Syslog Collector.3. Use the XQL Search to search your logs.3. Use the XQL Search to search your logs.Show markdown source
@@ -1,17 +1,17 @@ --- description: >- To extend visibility, Cortex XSIAM can receive Syslog from additional vendors that use CEF or LEEF formatted over Syslog (TLS not supported). --- # Ingest logs from a Syslog receiver -Cortex XSIAM can receive Syslog from a variety of supported vendors (see [External data ingestion vendor support](https://app.gitbook.com/s/FOhYBYLdbwpnbJgr6uaX/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion-vendor-support)). In addition, Cortex XSIAM can receive Syslog from additional vendors that use CEF, LEEF, CISCO, CORELIGHT, or RAW formatted over Syslog.External data ingestion vendor support +Cortex XSIAM can receive Syslog from a variety of supported vendors (see [Syslog Collector applet]()). In addition, Cortex XSIAM can receive Syslog from additional vendors that use CEF, LEEF, CISCO, CORELIGHT, or RAW formatted over Syslog.External data ingestion vendor support After Cortex XSIAM begins receiving logs from the third-party source, Cortex XSIAM automatically parses the logs in CEF, LEEF, CISCO, CORELIGHT, or RAW format and creates a dataset with the name `<vendor>_<product>_raw`. You can then use XQL Search queries to view logs and create new IOC, BIOC, and Correlation Rules. To receive Syslog from an external source: 1. Set up your Syslog receiver to forward logs. 2. Activate the Syslog collector applet on a Broker VM within your network. For more information, see [Activate the Syslog Collector](activate-syslog-collector). 3. Use the XQL Search to search your logs.
-
▸ ▾ Ingest data from Cribl modified +78 −28 Adds a full "generic UUID collector" onboarding workflow for data sources outside Cribl's dedicated catalog, plus a relative link fix into the UUID table.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cribl/ingest-data-from-criblRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -21,90 +21,140 @@ Tasks 1 through 3 are typically performed once during the initial integration se#### Task 1. Create New Data Sources in Cribl#### Task 1. Create New Data Sources in CriblOnboard your data sources in Cribl following the standard Cribl documentation.Onboard your data sources in Cribl following the standard Cribl documentation.Ensure you have the necessary credentials and IDs for each source, such as Tenant ID, App ID, and Client Secret.Ensure you have the necessary credentials and IDs for each source, such as Tenant ID, App ID, and Client Secret.• Collector selection: Use specific collectors from the Cribl catalog when available. If a dedicated collector does not exist, use the generic UUID collector. In this case, verify the log collection method and ensure the data format aligns with Cortex XSIAM ingestion requirements.• Collector selection: Use specific collectors from the Cribl catalog when available. If a dedicated collector does not exist, use the generic UUID collector. In this case, verify the log collection method and ensure the data format aligns with Cortex XSIAM ingestion requirements.• Data segmentation: To ensure optimal performance, configure a separate Cribl source collector for each data type to make routing/filtering easier and more efficient. For example, configure separate collectors for Microsoft 365 users, groups, and contacts.• Data segmentation: To ensure optimal performance, configure a separate Cribl source collector for each data type to make routing/filtering easier and more efficient. For example, configure separate collectors for Microsoft 365 users, groups, and contacts.• Analytics support: Any data source can be ingested using the generic UUID collector with the correct vendor and product fields. Yet, while parsing and modeling rules can be applied to any source, out-of-the-box (OOTB) analytics are only available for data sources using dedicated UUIDs. For more information, see Data source UUIDs.• Analytics support: Any data source can be ingested using the generic UUID collector with the correct vendor and product fields. Yet, while parsing and modeling rules can be applied to any source, out-of-the-box (OOTB) analytics are only available for data sources using dedicated UUIDs. For more information, see Data source UUIDs.#### Task 2. Generate Credentials in Cortex XSIAM#### Task 2. Generate Credentials in Cortex XSIAMhint infohint infoOnly one Cribl data collector instance can be configured in Cortex XSIAM. All Cribl sources will share this single connection.Only one Cribl data collector instance can be configured in Cortex XSIAM. All Cribl sources will share this single connection.endhintendhint1. Select Settings → Data Sources & Integrations.1. Select Settings → Data Sources & Integrations.2. Search for Cribl, select the integration, and click Add Instance.2. Search for Cribl, select the integration, and click Add Instance.3. In the Name field, enter a descriptive name, and click Save & generate token.3. In the Name field, enter a descriptive name, and click Save & generate token.4. Copy the Authorization Token (by clicking the copy icon) and save it in a secure location immediately. You cannot access this token again once the dialog is closed.4. Copy the Authorization Token (by clicking the copy icon) and save it in a secure location immediately. You cannot access this token again once the dialog is closed.5. On the Data Sources & Integrations page, click the link icon for your Cribl instance to Copy API URL, and save it for future use.5. On the Data Sources & Integrations page, click the link icon for your Cribl instance to Copy API URL, and save it for future use.#### Task 3. Configure the Cortex XSIAM destination in Cribl#### Task 3. Configure the Cortex XSIAM destination in CriblUsing the credentials from Task 2, configure the Cortex XSIAM destination tile in Cribl.Using the credentials from Task 2, configure the Cortex XSIAM destination tile in Cribl.Item│Field│DetailsItem│Field│Details| ------------------- | ------------------- | ------------------ || ------------------- | ------------------- | ------------------ |Cortex XSIAM URL│XSIAM Endpoint│Paste the API URL.Cortex XSIAM URL│XSIAM Endpoint│Paste the API URL.Authorization Token│Authorization Token│Paste the token.Authorization Token│Authorization Token│Paste the token.For general destination configuration details, see Cribl documentation.For general destination configuration details, see Cribl documentation.#### Task 4. Apply the Palo Alto XSIAM pack and pipelines in Cribl#### Task 4. Apply the Palo Alto XSIAM pack and pipelines in CriblYou must apply the Palo Alto XSIAM pack and configure a dedicated pipeline for each data source.You must apply the Palo Alto XSIAM pack and configure a dedicated pipeline for each data source.These steps differ depending on whether you are connecting to a specific data source supported from the Cortex XSIAM Cribl catalog or another product using the generic UUID. For a complete list of the supported data sources in the catalog, see Data source UUIDs.These steps differ depending on whether you are connecting to a specific data source supported from the Cortex XSIAM Cribl catalog or another product using the generic UUID. For a complete list of the supported data sources in the catalog, see Data source UUIDs.Apply the XSIAM pack using a collector supported in the Cribl catalogApply the XSIAM pack using a collector supported in the Cribl catalog1. Install the Palo Alto XSIAM pack.1. Install the Palo Alto XSIAM pack.1. In Cribl, select Stream → Worker Groups, and select the default Worker Group that you want to add the pack to.1. In Cribl, select Stream → Worker Groups, and select the default Worker Group that you want to add the pack to.2. Select Processing → Packs.2. Select Processing → Packs.3. Select Add Pack → Add from Dispensary.3. Select Add Pack → Add from Dispensary.4. Search for XSIAM, and install the Palo Alto XSIAM pack.4. Search for XSIAM, and install the Palo Alto XSIAM pack.2. Connect the data source to the XSIAM destination to define the route.2. Connect the data source to the XSIAM destination to define the route.This step can be performed using either QuickConnect or Routes. The instructions below explain how to do this using QuickConnect.This step can be performed using either **QuickConnect** or **Routes**. The instructions below explain how to do this using **QuickConnect**.1. For the same default worker group, select the Overview tab.1. For the same default worker group, select the Overview tab.2. Under QuickConnect, click Source.2. Under QuickConnect, click Source.3. Under Source, find the data source that you onboarded in Task 1, and from the+icon drag and drop to the XSIAM destination to define the route.3. Under Source, find the data source that you onboarded in Task 1, and from the+icon drag and drop to the XSIAM destination to define the route.3. Assign the pack.3. Assign the pack.1. Click on the line connecting the data source to the XSIAM destination, and click Pack.1. Click on the line connecting the data source to the XSIAM destination, and click Pack.2. In the Add Pack to Connection window, select the Palo Alto XSIAM pack.2. In the Add Pack to Connection window, select the Palo Alto XSIAM pack.3. Click Save.3. Click Save.4. End-to-end connection.4. End-to-end connection.The pack includes built-in pipelines for supported sources. Each contains a specific UUID in the `__sourceIdentifier` parameter. This UUID signals to the XSIAM destination, which data source is streaming.The pack includes built-in pipelines for supported sources. Each contains a specific UUID in the `__sourceIdentifier` parameter. This UUID signals to the XSIAM destination, which data source is streaming.To enable the connection, the specific source must be enabled in the pack, and the pipeline must route the data using a filter using the format `__inputId=='data_source'`. These filters are usually specific to the environment and is how Cribl Stream is configured.To enable the connection, the specific source must be enabled in the pack, and the pipeline must route the data using a filter using the format `__inputId=='data_source'`. These filters are usually specific to the environment and is how Cribl Stream is configured.1. For the same default worker group, select Processing → Packs.1. For the same default worker group, select Processing → Packs.2. Under Display name, click Palo Alto XSIAM.2. Under Display name, click Palo Alto XSIAM.3. On the left pane, expand the third row.3. On the left pane, expand the third row.4. Scroll down to the data source that you connected to XSIAM, enable the toggle.4. Scroll down to the data source that you connected to XSIAM, enable the toggle.5. Click on the name of the data source under Route to display the routing information, including the configured route name, filter, and pipeline. The values displayed here must match the data source connected to XSIAM.5. Click on the name of the data source under Route to display the routing information, including the configured route name, filter, and pipeline. The values displayed here must match the data source connected to XSIAM.<div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>To view the configuration of the pipeline, select the attachment icon → Eval. Under Evaluate fields, you can see the _sourceIdentifier configured, where the Value Expression field should match the UUID for the specific collector from the Cribl catalog. This UUID is automatically configured once you've enabled the data source in the pack.</p></div><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>To view the configuration of the pipeline, select the <strong>attachment icon</strong> → <strong>Eval</strong>. Under <strong>Evaluate fields</strong>, you can see the <strong>_sourceIdentifier</strong> configured, where the <strong>Value Expression</strong> field should match the UUID for the specific collector from the Cribl catalog. This UUID is automatically configured once you've enabled the data source in the pack.</p></div>6. Click Save.6. Click Save.</details>Apply XSIAM pack using generic UUID collectorIf you wish to connect a data source not listed in the UUID Cribl catalog, use the generic UUID with the correct vendor and product fields. Make sure the vendor and the product match the existing content packs available in Cortex XSIAM.1. Install the Palo Alto XSIAM pack.1. In Cribl Stream → Worker Groups, select the default Worker Group that you want to add the pack to.2. Select Processing → Packs.3. Select Add Pack → Add from Dispensary.4. Search for XSIAM, and install the Palo Alto XSIAM pack.2. Create a dedicated pipeline for the new data source to the Palo Alto XSIAM pack, such as Fortinet Fortigate.1. For the same default worker group, select Processing → Pipelines.2. Select Add Pipeline → Add Pipeline.3. In the ID field, provide a name for this data source, such as GenericDataSource.4. Click Save.3. Add three additional fields to this pipeline.1. Click Add Function, search for Eval, and select Eval.2. Under Evaluate fields, select Add Field, and define the following fields:• Fields 1:• Name:__sourceIdentifier• Value Expression:'af01292940d7426594d3d3e55ae17ee0', which is the Generic UUID.• Field 2:• Name:__vendor• Value Expression:<name of vendor>, such as'fortinet'.• Field 3:• Name:__product• Value Expression:<name of product>, such as'fortigatehint infoNoteData streams into thevendor_product_rawdataset in Cortex XSIAM. It should match an existing Marketplace content pack.endhint4. Create a dedicated route between the data source and the newly-created pipeline.1. Select the Routes tab, and click Add Route.2. Configure the following:• Route name: Enter a distinct name for the route.• Filter: Enter or select a filter using the format__inputId=='data_source'so the the pipeline can route the data from the data source. These filters are usually specific to the environment and is how Cribl Stream is configured.• Pipeline: Enter the name of the pipeline that you created above for the new generic data source, such as GenericDataSource as created above.• Description (optional): Enter a description for this route.3. On the blue line of the new route, click the ellipse menu, and select Group Actions → Create Group.4. Define the following:• Group name: Enter a generic name for these types of generic data sources , such as "Generic Data Sources with PANW assigned UUID".• Description (optional): Enter a unique description.5. Click Save.</details></details>#### Task 5. Verification#### Task 5. VerificationVerify that data is streaming as expected from Cribl to Cortex XSIAM.Verify that data is streaming as expected from Cribl to Cortex XSIAM.• In Cribl:• In Cribl:1. Select Stream → Worker Groups, and select the default Worker Group that you want to add the pack to.1. Select Stream → Worker Groups, and select the default Worker Group that you want to add the pack to.2. In the Overview tab and under QuickConnect, click Source.2. In the Overview tab and under QuickConnect, click Source.3. Hover over the data source that you connected to Cortex XSIAM, and click Configure.3. Hover over the data source that you connected to Cortex XSIAM, and click Configure.4. In the Charts tab, verify that streaming is in progress.4. In the Charts tab, verify that streaming is in progress.• In Cortex XSIAM, on the Data Sources & Integrations page, when streaming begins, a green check mark appears below the Cribl configuration, along with the amount of data received.• In Cortex XSIAM, on the Data Sources & Integrations page, when streaming begins, a green check mark appears below the Cribl configuration, along with the amount of data received.\\\\
Show markdown source
@@ -21,90 +21,140 @@ Tasks 1 through 3 are typically performed once during the initial integration se #### Task 1. Create New Data Sources in Cribl Onboard your data sources in Cribl following the standard [Cribl documentation](https://docs.cribl.io/stream/collectors/). Ensure you have the necessary credentials and IDs for each source, such as Tenant ID, App ID, and Client Secret. * **Collector selection**: Use specific collectors from the Cribl catalog when available. If a dedicated collector does not exist, use the generic UUID collector. In this case, verify the log collection method and ensure the data format aligns with Cortex XSIAM ingestion requirements. * **Data segmentation**: To ensure optimal performance, configure a separate Cribl source collector for each data type to make routing/filtering easier and more efficient. For example, configure separate collectors for Microsoft 365 users, groups, and contacts. -* **Analytics support**: Any data source can be ingested using the generic UUID collector with the correct vendor and product fields. Yet, while parsing and modeling rules can be applied to any source, out-of-the-box (OOTB) analytics are only available for data sources using dedicated UUIDs. For more information, see [Data source UUIDs](https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/uyWqY4ELN5JI8Uh7pSKmFA). +* **Analytics support**: Any data source can be ingested using the generic UUID collector with the correct vendor and product fields. Yet, while parsing and modeling rules can be applied to any source, out-of-the-box (OOTB) analytics are only available for data sources using dedicated UUIDs. For more information, see [Data source UUIDs](ingest-data-from-cribl/data-souce-uuids). #### Task 2. Generate Credentials in Cortex XSIAM {% hint style="info" %} Only one Cribl data collector instance can be configured in Cortex XSIAM. All Cribl sources will share this single connection. {% endhint %} -1. Select Settings → Data Sources & Integrations. -2. Search for Cribl, select the integration, and click Add Instance. -3. In the Name field, enter a descriptive name, and click Save & generate token. +1. Select **Settings** → **Data Sources & Integrations**. +2. Search for **Cribl**, select the integration, and click **Add Instance**. +3. In the **Name** field, enter a descriptive name, and click **Save & generate token**. 4. Copy the Authorization Token (by clicking the copy icon) and save it in a secure location immediately. You cannot access this token again once the dialog is closed. -5. On the Data Sources & Integrations page, click the link icon for your Cribl instance to Copy API URL, and save it for future use. +5. On the **Data Sources & Integrations** page, click the link icon for your Cribl instance to **Copy API URL**, and save it for future use. #### Task 3. Configure the Cortex XSIAM destination in Cribl Using the credentials from Task 2, configure the Cortex XSIAM destination tile in Cribl. | Item | Field | Details | | ------------------- | ------------------- | ------------------ | | Cortex XSIAM URL | XSIAM Endpoint | Paste the API URL. | | Authorization Token | Authorization Token | Paste the token. | For general destination configuration details, see [Cribl documentation.](https://docs.cribl.io/stream/destinations-xsiam/) #### Task 4. Apply the Palo Alto XSIAM pack and pipelines in Cribl You must apply the Palo Alto XSIAM pack and configure a dedicated pipeline for each data source. -These steps differ depending on whether you are connecting to a specific data source supported from the Cortex XSIAM Cribl catalog or another product using the generic UUID. For a complete list of the supported data sources in the catalog, see [Data source UUIDs](https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/uyWqY4ELN5JI8Uh7pSKmFA). +These steps differ depending on whether you are connecting to a specific data source supported from the Cortex XSIAM Cribl catalog or another product using the generic UUID. For a complete list of the supported data sources in the catalog, see [Data source UUIDs](ingest-data-from-cribl/data-souce-uuids). <details> <summary>Apply the XSIAM pack using a collector supported in the Cribl catalog</summary> 1. Install the Palo Alto XSIAM pack. - 1. In Cribl, select Stream → Worker Groups, and select the default Worker Group that you want to add the pack to. - 2. Select Processing → Packs. - 3. Select Add Pack → Add from Dispensary. - 4. Search for XSIAM, and install the Palo Alto XSIAM pack. + 1. In Cribl, select **Stream** → **Worker Groups**, and select the default Worker Group that you want to add the pack to. + 2. Select **Processing** → **Packs**. + 3. Select **Add Pack** → **Add from Dispensary**. + 4. Search for **XSIAM**, and install the **Palo Alto XSIAM** pack. 2. Connect the data source to the XSIAM destination to define the route. - This step can be performed using either QuickConnect or Routes. The instructions below explain how to do this using QuickConnect. + This step can be performed using either **QuickConnect** or **Routes**. The instructions below explain how to do this using **QuickConnect**. - 1. For the same default worker group, select the Overview tab. - 2. Under QuickConnect, click Source. - 3. Under Source, find the data source that you onboarded in Task 1, and from the `+` icon drag and drop to the XSIAM destination to define the route. + 1. For the same default worker group, select the **Overview** tab. + 2. Under **QuickConnect**, click **Source**. + 3. Under **Source**, find the data source that you onboarded in Task 1, and from the `+` icon drag and drop to the **XSIAM** destination to define the route. 3. Assign the pack. - 1. Click on the line connecting the data source to the XSIAM destination, and click Pack. - 2. In the Add Pack to Connection window, select the Palo Alto XSIAM pack. - 3. Click Save. + 1. Click on the line connecting the data source to the **XSIAM** destination, and click **Pack**. + 2. In the **Add Pack to Connection** window, select the **Palo Alto XSIAM** pack. + 3. Click **Save**. 4. End-to-end connection. The pack includes built-in pipelines for supported sources. Each contains a specific UUID in the `__sourceIdentifier` parameter. This UUID signals to the XSIAM destination, which data source is streaming. To enable the connection, the specific source must be enabled in the pack, and the pipeline must route the data using a filter using the format `__inputId=='data_source'`. These filters are usually specific to the environment and is how Cribl Stream is configured. - 1. For the same default worker group, select Processing → Packs. - 2. Under Display name, click Palo Alto XSIAM. + 1. For the same default worker group, select **Processing** → **Packs**. + 2. Under **Display name**, click **Palo Alto XSIAM**. 3. On the left pane, expand the third row. - 4. Scroll down to the data source that you connected to XSIAM, enable the toggle. - 5. Click on the name of the data source under Route to display the routing information, including the configured route name, filter, and pipeline. The values displayed here must match the data source connected to XSIAM. + 4. Scroll down to the data source that you connected to **XSIAM**, enable the toggle. + 5. Click on the name of the data source under **Route** to display the routing information, including the configured route name, filter, and pipeline. The values displayed here must match the data source connected to **XSIAM**. - <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>To view the configuration of the pipeline, select the attachment icon → Eval. Under Evaluate fields, you can see the _sourceIdentifier configured, where the Value Expression field should match the UUID for the specific collector from the Cribl catalog. This UUID is automatically configured once you've enabled the data source in the pack.</p></div> - 6. Click Save. + <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>To view the configuration of the pipeline, select the <strong>attachment icon</strong> → <strong>Eval</strong>. Under <strong>Evaluate fields</strong>, you can see the <strong>_sourceIdentifier</strong> configured, where the <strong>Value Expression</strong> field should match the UUID for the specific collector from the Cribl catalog. This UUID is automatically configured once you've enabled the data source in the pack.</p></div> + 6. Click **Save**. + +</details> + +<details> + +<summary>Apply XSIAM pack using generic UUID collector</summary> + +If you wish to connect a data source not listed in the UUID Cribl catalog, use the generic UUID with the correct vendor and product fields. Make sure the vendor and the product match the existing content packs available in Cortex XSIAM. + +1. Install the **Palo Alto XSIAM** pack. + 1. In Cribl **Stream** → **Worker Groups**, select the default Worker Group that you want to add the pack to. + 2. Select **Processing** → **Packs**. + 3. Select **Add Pack** → **Add from Dispensary**. + 4. Search for **XSIAM**, and install the **Palo Alto XSIAM** pack. +2. Create a dedicated pipeline for the new data source to the **Palo Alto XSIAM** pack, such as Fortinet Fortigate. + 1. For the same default worker group, select **Processing** → **Pipelines**. + 2. Select **Add Pipeline** → **Add Pipeline**. + 3. In the **ID** field, provide a name for this data source, such as **GenericDataSource**. + 4. Click **Save**. +3. Add three additional fields to this pipeline. + 1. Click **Add Function**, search for **Eval**, and select **Eval**. + 2. Under **Evaluate fields**, select **Add Field**, and define the following fields: + * Fields 1: + * **Name**: `__sourceIdentifier` + * **Value Expression**: `'af01292940d7426594d3d3e55ae17ee0'`, which is the Generic UUID. + * Field 2: + * **Name**: `__vendor` + * **Value Expression**: `<name of vendor>`, such as `'fortinet'`. + * Field 3: + * **Name**: `__product` + * **Value Expression**: `<name of product>`, such as `'fortigate` + +{% hint style="info" %} +**Note** + +Data streams into the `vendor_product_raw` dataset in Cortex XSIAM. It should match an existing Marketplace content pack. +{% endhint %} + +4. Create a dedicated route between the data source and the newly-created pipeline. + 1. Select the **Routes** tab, and click **Add Route**. + 2. Configure the following: + * **Route name**: Enter a distinct name for the route. + * **Filter**: Enter or select a filter using the format `__inputId=='data_source'` so the the pipeline can route the data from the data source. These filters are usually specific to the environment and is how Cribl Stream is configured. + * **Pipeline**: Enter the name of the pipeline that you created above for the new generic data source, such as **GenericDataSource** as created above. + * **Description** (optional): Enter a description for this route. + 3. On the blue line of the new route, click the ellipse menu, and select **Group Actions** → **Create Group**. + 4. Define the following: + * **Group name**: Enter a generic name for these types of generic data sources , such as "Generic Data Sources with PANW assigned UUID". + * **Description** (optional): Enter a unique description. + 5. Click **Save**. </details> #### Task 5. Verification Verify that data is streaming as expected from Cribl to Cortex XSIAM. * In Cribl: - 1. Select Stream → Worker Groups, and select the default Worker Group that you want to add the pack to. - 2. In the Overview tab and under QuickConnect, click Source. - 3. Hover over the data source that you connected to Cortex XSIAM, and click Configure. - 4. In the Charts tab, verify that streaming is in progress. -* In Cortex XSIAM, on the Data Sources & Integrations page, when streaming begins, a green check mark appears below the Cribl configuration, along with the amount of data received. + 1. Select **Stream** → **Worker Groups**, and select the default Worker Group that you want to add the pack to. + 2. In the **Overview** tab and under **QuickConnect**, click **Source**. + 3. Hover over the data source that you connected to Cortex XSIAM, and click **Configure**. + 4. In the **Charts** tab, verify that streaming is in progress. +* In Cortex XSIAM, on the **Data Sources & Integrations** page, when streaming begins, a green check mark appears below the Cribl configuration, along with the amount of data received. \ \ <br> -
▸ ▾ Data souce UUIDs modified +78 −80 Cross-reference links for each vendor UUID now point at the actual doc pages instead of opaque short links.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cribl/ingest-data-from-cribl/data-souce-uuidsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -7,130 +7,128 @@ Any data source can be ingested using the generic UUID collector with the correc### Indicate specific vendor name as not listed below (Generic)### Indicate specific vendor name as not listed below (Generic)Product│UUID│Datasets│Collection MethodProduct│UUID│Datasets│Collection Method| ------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------- | -------------------------- | ----------------- || ------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------- | -------------------------- | ----------------- |Indicate specific product name as not listed below (Generic)│af01292940d7426594d3d3e55ae17ee0Do not use this generic UUID when your data source is listed in this table.
│<Vendor>_<Product>_raw│Indicate specific product name as not listed below (Generic)│af01292940d7426594d3d3e55ae17ee0Do not use this generic UUID when your data source is listed in this table.
│<Vendor>_<Product>_raw│### Amazon### AmazonProduct│UUID│Datasets│Collection MethodProduct│UUID│Datasets│Collection Method| ----------------- | -------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ----------------- | -------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |AWS audit logs│c19f87b6262f48259b3d5d2a2c691802│amazon_aws_raw│These AWS logs are collected via Amazon S3. To ensure compatibility, see Ingest audit logs from AWS Cloud Trail.AWS audit logs│c19f87b6262f48259b3d5d2a2c691802│amazon_aws_raw│These AWS logs are collected via Amazon S3. To ensure compatibility, see Ingest audit logs from AWS Cloud Trail.AWS EKS│fb8a9d4922cb4095b76d71e921d2d999│amazon_eks_raw│These AWS logs are collected via Amazon CloudWatch. To ensure collector compatibility, see Ingest logs from Amazon CloudWatch.AWS EKS│fb8a9d4922cb4095b76d71e921d2d999│amazon_eks_raw│These AWS logs are collected via Amazon CloudWatch. To ensure collector compatibility, see Ingest logs from Amazon CloudWatch.AWS flow logs│667083aa68544eee8b67cdd2d4cc327b│amazon_aws_raw│These logs are collected via Amazon S3. To ensure collector compatibility, see Ingest network flow logs from Amazon S3.AWS flow logs│667083aa68544eee8b67cdd2d4cc327b│amazon_aws_raw│These logs are collected via Amazon S3. To ensure collector compatibility, see Ingest network flow logs from Amazon S3.AWS generic logs│0498f8a24de04b3e85102e742f6783f8│amazon_aws_raw│These logs are collected via Amazon S3. To ensure collector compatibility, see Ingest generic logs from Amazon S3.AWS generic logs│0498f8a24de04b3e85102e742f6783f8│amazon_aws_raw│These logs are collected via Amazon S3. To ensure collector compatibility, see Ingest generic logs from Amazon S3.AWS prompt logs│a53edad7ef0c46ffb5037fb2e21520cb│amazon_aws_raw│For setup details, see Prompt log collection in AWS.AWS prompt logs│a53edad7ef0c46ffb5037fb2e21520cb│amazon_aws_raw│For setup details, see Prompt log collection in AWS.AWS Route 53 logs│- d57ae82c1e2a4d138fc34084d159b09e (old)
- 0a7544038b444998a20e698669817e3d (new)
amazon_route53_raw(via old UUID)amazon_route53_raw(via new UUID)
AWS Route 53 logs│- d57ae82c1e2a4d138fc34084d159b09e (old)
- 0a7544038b444998a20e698669817e3d (new)
amazon_route53_raw(via old UUID)amazon_route53_raw(via new UUID)
### Box### BoxProduct│UUID│Datasets│Collection MethodProduct│UUID│Datasets│Collection Method| ------- | -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ------- | -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |Box│3ef05d14ae9349f8bbd48c8a4797334a│- Events (admin_logs):
box_admin_logs_raw - Box Shield Alerts:
box_shield_alerts_raw - Users:
box_users_raw - Groups:
box_groups_raw
BOX_DIRECTORIESconnector queries the following Box API endpoints:Users
- Endpoint:
https://api.box.com/2.0/users - Purpose: To fetch the list of users in Box enterprise.
- Endpoint:
Groups
- Endpoint:
https://api.box.com/2.0/groups - Purpose: To fetch the list of groups in Box enterprise.
- Endpoint:
For setup details, see Ingest logs and data from Box.
Box│3ef05d14ae9349f8bbd48c8a4797334a│- Events (admin_logs):
box_admin_logs_raw - Box Shield Alerts:
box_shield_alerts_raw - Users:
box_users_raw - Groups:
box_groups_raw
BOX_DIRECTORIESconnector queries the following Box API endpoints:Users
- Endpoint:
https://api.box.com/2.0/users - Purpose: To fetch the list of users in Box enterprise.
- Endpoint:
Groups
- Endpoint:
https://api.box.com/2.0/groups - Purpose: To fetch the list of groups in Box enterprise.
- Endpoint:
For setup details, see Ingest logs and data from Box.
### CrowdStrike### CrowdStrikeProduct│UUID│Datasets│Collection MethodProduct│UUID│Datasets│Collection Method| --------------- | -------------------------------- | --------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || --------------- | -------------------------------- | --------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Falcon incident│230b2b0233bf4327806af72e6e5769f3│crowdstrike_falcon_incident_raw│Currently not supported by CriblCrowdStrike Streaming API
Base URL:
https://api.crowdstrike.com(orapi.us-2.crowdstrike.com,api.eu-1.crowdstrike.com, etc.)GET /sensors/entities/datafeed/v2For setup details, see Ingest alerts and metadata from CrowdStrike APIs.
Falcon incident│230b2b0233bf4327806af72e6e5769f3│crowdstrike_falcon_incident_raw│Currently not supported by CriblCrowdStrike Streaming API
Base URL:
https://api.crowdstrike.com(orapi.us-2.crowdstrike.com,api.eu-1.crowdstrike.com, etc.)GET /sensors/entities/datafeed/v2For setup details, see Ingest alerts and metadata from CrowdStrike APIs.
Hosts│8b673ac8e2f34b4a8dc14c22f0e6063b│crowdstrike_hosts_raw│CrowdStrike Devices APIGET /devices/queries/devices-scroll/v1POST /devices/entities/devices/v2For setup details, see Ingest alerts and metadata from CrowdStrike APIs.
Hosts│8b673ac8e2f34b4a8dc14c22f0e6063b│crowdstrike_hosts_raw│CrowdStrike Devices APIGET /devices/queries/devices-scroll/v1POST /devices/entities/devices/v2For setup details, see Ingest alerts and metadata from CrowdStrike APIs.
### Dropbox### DropboxProduct│UUID│Datasets│Collection MethodProduct│UUID│Datasets│Collection Method| --------- | -------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || --------- | -------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |Directory│e8d2c52bc9594621924fab0507264586│dropbox_members_devices_rawdropbox_users_rawdropbox_groups_raw
https://api.dropboxapi.comUsers (dropbox_users_raw)
- Endpoint:
/2/team/members/list_v2
- Endpoint:
Groups (dropbox_groups_raw)
- Endpoint:
/2/team/groups/list
- Endpoint:
Devices (dropbox_member_devices_raw)
- Endpoint:
/2/team/devices/list_members_devices
- Endpoint:
For setup details, see Ingest logs and data from Dropbox.
Directory│e8d2c52bc9594621924fab0507264586│dropbox_members_devices_rawdropbox_users_rawdropbox_groups_raw
https://api.dropboxapi.comUsers (dropbox_users_raw)
- Endpoint:
/2/team/members/list_v2
- Endpoint:
Groups (dropbox_groups_raw)
- Endpoint:
/2/team/groups/list
- Endpoint:
Devices (dropbox_member_devices_raw)
- Endpoint:
/2/team/devices/list_members_devices
- Endpoint:
For setup details, see Ingest logs and data from Dropbox.
Events│a6322b2fd9e545e0a4223ba754c48fb9│dropbox_events_raw│Base URL:https://api.dropboxapi.comEndpoint:
/2/team_log/get_eventsFor setup details, see Ingest logs and data from Dropbox.
Events│a6322b2fd9e545e0a4223ba754c48fb9│dropbox_events_raw│Base URL:https://api.dropboxapi.comEndpoint:
/2/team_log/get_eventsFor setup details, see Ingest logs and data from Dropbox.
### Google### GoogleProduct│UUID│Datasets│Collection MethodProduct│UUID│Datasets│Collection Method| ------------------------------------ | -------------------------------- | ---------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ------------------------------------ | -------------------------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |Cloud Logging (audit logs/flow logs)│00a8322c85e14beabfa7ad5f3d62db73│google_cloud_logging_raw│For setup details, see Ingest logs and data from a GCP Pub/Sub.Cloud Logging (audit logs/flow logs)│00a8322c85e14beabfa7ad5f3d62db73│google_cloud_logging_raw│For setup details, see Ingest logs and data from a GCP Pub/Sub.Gmail│8607490288d1407ba82b5c5ad9dc64a0│google_gmail_raw│GET https://gmail.googleapis.com/gmail/v1/users/{userId}/messagesFor setup details, see Ingest logs and data from Google Workspace.
Gmail│8607490288d1407ba82b5c5ad9dc64a0│google_gmail_raw│GET https://gmail.googleapis.com/gmail/v1/users/{userId}/messagesFor setup details, see Ingest logs and data from Google Workspace.
Workspace alerts│4f263650cd29475c81f2ff953cf19827│google_workspace_alerts_raw│Description: Ingests security and system alerts from the Google Workspace Alert Center.API Details
- API Name: Google Alert Center API
- Version:
v1beta1 - Base URL:
https://alertcenter.googleapis.com - Endpoint:
/v1beta1/alerts - Method:
GET (List) - OAuth Scope:
https://www.googleapis.com/auth/apps.alerts
Request Parameters
- filter: Used for incremental ingestion based on
createTime. - Format:
createTime >= "[TIMESTAMP_START]" AND createTime < "[TIMESTAMP_END]" - orderBy:
createTime asc - pageToken: Used for pagination.
- filter: Used for incremental ingestion based on
Data Mapping
- Source: The full JSON response object from the
alertslist. - Destination: Each alert object is ingested as a single record.
- Source: The full JSON response object from the
For setup details, see Ingest logs and data from Google Workspace.
Workspace alerts│4f263650cd29475c81f2ff953cf19827│google_workspace_alerts_raw│Description: Ingests security and system alerts from the Google Workspace Alert Center.API Details
- API Name: Google Alert Center API
- Version:
v1beta1 - Base URL:
https://alertcenter.googleapis.com - Endpoint:
/v1beta1/alerts - Method:
GET (List) - OAuth Scope:
https://www.googleapis.com/auth/apps.alerts
Request Parameters
- filter: Used for incremental ingestion based on
createTime. - Format:
createTime >= "[TIMESTAMP_START]" AND createTime < "[TIMESTAMP_END]" - orderBy:
createTime asc - pageToken: Used for pagination.
- filter: Used for incremental ingestion based on
Data Mapping
- Source: The full JSON response object from the
alertslist. - Destination: Each alert object is ingested as a single record.
- Source: The full JSON response object from the
For setup details, see Ingest logs and data from Google Workspace.
Workspace ChromeOS devices│e82ae276e6b9442fa80920a03d2a38d6│google_workspace_chrome_raw│GET https://admin.googleapis.com/admin/directory/v1/customer/{customer}/devices/chromeosFor setup details, see Ingest logs and data from Google Workspace.
Workspace ChromeOS devices│e82ae276e6b9442fa80920a03d2a38d6│google_workspace_chrome_raw│GET https://admin.googleapis.com/admin/directory/v1/customer/{customer}/devices/chromeosFor setup details, see Ingest logs and data from Google Workspace.
Workspace groups│689ae8ef14e848e3855b81e91d8af9bc│google_workspace_enterprise_groups_raw│GET https://admin.googleapis.com/admin/directory/v1/groupsFor setup details, see Ingest logs and data from Google Workspace.
Workspace groups│689ae8ef14e848e3855b81e91d8af9bc│google_workspace_enterprise_groups_raw│GET https://admin.googleapis.com/admin/directory/v1/groupsFor setup details, see Ingest logs and data from Google Workspace.
Workspace rules│2621aaf3334a4147ae727afe84db31a9│google_workspace_rules_raw│GET https://gmail.googleapis.com/gmail/v1/users/{userId}/settings/filtersFor setup details, see Ingest logs and data from Google Workspace.
Workspace rules│2621aaf3334a4147ae727afe84db31a9│google_workspace_rules_raw│GET https://gmail.googleapis.com/gmail/v1/users/{userId}/settings/filtersFor setup details, see Ingest logs and data from Google Workspace.
Workspace users│359ecd845fa54caab6ddb4b7c7a2764d│google_workspace_user_acounts_raw│GET https://admin.googleapis.com/admin/directory/v1/users/{userKey}For setup details, see Ingest logs and data from Google Workspace.
Workspace users│359ecd845fa54caab6ddb4b7c7a2764d│google_workspace_user_acounts_raw│GET https://admin.googleapis.com/admin/directory/v1/users/{userKey}For setup details, see Ingest logs and data from Google Workspace.
### Microsoft### MicrosoftProduct│UUID│Datasets│Collection Method| ---------------------------- | -------------------------------- | --------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Azure│fce13a1d51294f84bae4a37851503060│msft_azure_raw│Azure Event Hubs SDK (AMQP): For setup details, see Ingest logs from Microsoft Azure Event Hub.Azure AD│c00d6d52e5b141a8baa8db9d9345423d│msft_azure_ad_raw│For set up details, see Ingest logs from Microsoft Office 365.Azure AD audit│0e076d5abe864bf78e8145ea9e0d749e│msft_azure_ad_audit_raw│Microsoft Graph API:GET /v1.0/auditLogs/directoryauditsFor set up details, see Ingest logs from Microsoft Office 365.
Azure AD sign-ins│f56dcfdf6bca43e793a4b6e9290e7b12│msft_azure_ad_raw│Microsoft Graph API:GET /v1.0/auditLogs/signInsFor set up details, see Ingest logs from Microsoft Office 365.
Defender│ce9e8cf36e0742c38aa89787a256855f│msft_defender_raw│Azure Event Hubs SDK (AMQP): For setup details, see Ingest raw EDR events from Microsoft Defender for Endpoint.To enable analytics, contact Customer Support.
DHCP│b55819e8959c49728d5d98a6d87eafb6│msft_dhcp_raw│File Collection: C:\Windows\System32\dhcp\DhcpSrvLog-*.logFor set up details, see Ingest logs from Windows DHCP using Elasticsearch Filebeat.
Graph security alerts│5619f2f691fc46c4b202587fdaa031c3│msft_graph_security_alerts_raw│Microsoft Graph API:/v1.0/security/alerts_v2For set up details, see Ingest logs from Microsoft Office 365.
Office 365 Azure AD│e1f109f886ea42fbb96be6ec0cc597a9│msft_o365_azure_ad_raw│The Base URLs for the APIs are (depending on the environment):Worldwide:
https://manage.office.comGCC:
https://manage-gcc.office.comGCC High:
https://manage.office365.usDoD:
https://manage.protection.apps.milEndpoints:
Start Subscription:
/api/v1.0/{tenantID}/activity/feed/subscriptions/start?contentType={type}List Available Content:
/api/v1.0/{tenantID}/activity/feed/subscriptions/content?contentType={type}Fetch Content Blob: Dynamic URI returned from the “List Available Content” call.
Content Types:
audit.exchange,audit.sharepoint,audit.general,audit.azureactivedirectory,dlp.all.For set up details, see Ingest logs from Microsoft Office 365.
Office 365 DLP│8f052782739d4b8389644cca23b994ac│msft_o365_dlp_raw│See Office 365 Azure AD.For set up details, see Ingest logs from Microsoft Office 365.
Office 365 domains│cae29fd87b554bd9a5694afb225e8dc9│msft_o365_domains_raw│Microsoft Graph API:GET /v1.0/domainsOffice 365 Exchange Online│dee8e85ce7db4573a8bc21b807e1d73a│msft_o365_exchange_online_raw│See Office 365 Azure AD.For set up details, see Ingest logs from Microsoft Office 365.
Office 365 General│c7655e83805b4a058e66043a6715156c│msft_o365_general_raw│See Office 365 Azure AD.For set up details, see Ingest logs from Microsoft Office 365.
@@ diff truncated @@Show markdown source
@@ -7,130 +7,128 @@ Any data source can be ingested using the generic UUID collector with the correc ### Indicate specific vendor name as not listed below (Generic) | Product | UUID | Datasets | Collection Method | | ------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------- | -------------------------- | ----------------- | | Indicate specific product name as not listed below (Generic) | <p>af01292940d7426594d3d3e55ae17ee0</p><p>Do not use this generic UUID when your data source is listed in this table.</p> | \<Vendor>\_\<Product>\_raw | | ### Amazon -| Product | UUID | Datasets | Collection Method | -| ----------------- | -------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| AWS audit logs | c19f87b6262f48259b3d5d2a2c691802 | `amazon_aws_raw` | These AWS logs are collected via Amazon S3. To ensure compatibility, see [Ingest audit logs from AWS Cloud Trail](https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/nXskEMdNsCYNkkZHbBxs_w). | -| AWS EKS | fb8a9d4922cb4095b76d71e921d2d999 | `amazon_eks_raw` | These AWS logs are collected via Amazon CloudWatch. To ensure collector compatibility, see [Ingest logs from Amazon CloudWatch](https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/DBkXbNS7bxJ1mtkvgrobZA). | -| AWS flow logs | 667083aa68544eee8b67cdd2d4cc327b | `amazon_aws_raw` | These logs are collected via Amazon S3. To ensure collector compatibility, see [Ingest network flow logs from Amazon S3](https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/lzxQ06vnZ7Kc0cNd99IiPg). | -| AWS generic logs | 0498f8a24de04b3e85102e742f6783f8 | `amazon_aws_raw` | These logs are collected via Amazon S3. To ensure collector compatibility, see [Ingest generic logs from Amazon S3](https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/AKgpHmq0rl24ZRJufz62gw). | -| AWS prompt logs | a53edad7ef0c46ffb5037fb2e21520cb | `amazon_aws_raw` | For setup details, see [Prompt log collection in AWS](https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/oaRb7tNRp_wNpBKBHR7obQ). | -| AWS Route 53 logs | <p></p><ul><li>d57ae82c1e2a4d138fc34084d159b09e (old)</li><li>0a7544038b444998a20e698669817e3d (new)</li></ul> | <ul><li><code>amazon_route53_raw</code> (via old UUID)</li><li><code>amazon_route53_raw</code> (via new UUID)</li></ul> | These logs are collected via Amazon S3. Using the old UUID routes data to the generic AWS dataset. For native routing to the Route 53 dataset, use the new dedicated UUID. To ensure collector compatibility, see [Ingest network Route 53 logs from Amazon S3](https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/KsSoSLNjgkNYgQA5wr2DZQ). | +| Product | UUID | Datasets | Collection Method | +| ----------------- | -------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| AWS audit logs | c19f87b6262f48259b3d5d2a2c691802 | `amazon_aws_raw` | These AWS logs are collected via Amazon S3. To ensure compatibility, see [Ingest audit logs from AWS Cloud Trail](../../amazon/amazon-s3/ingest-audit-logs-from-aws-cloudtrail). | +| AWS EKS | fb8a9d4922cb4095b76d71e921d2d999 | `amazon_eks_raw` | These AWS logs are collected via Amazon CloudWatch. To ensure collector compatibility, see [Ingest logs from Amazon CloudWatch](../../amazon/amazon-cloud-watch/ingest-logs-from-amazon-cloudwatch). | +| AWS flow logs | 667083aa68544eee8b67cdd2d4cc327b | `amazon_aws_raw` | These logs are collected via Amazon S3. To ensure collector compatibility, see [Ingest network flow logs from Amazon S3](../../amazon/amazon-s3/ingest-network-flow-logs-from-amazon-s3). | +| AWS generic logs | 0498f8a24de04b3e85102e742f6783f8 | `amazon_aws_raw` | These logs are collected via Amazon S3. To ensure collector compatibility, see [Ingest generic logs from Amazon S3](../../amazon/amazon-s3/ingest-generic-logs-from-amazon-s3). | +| AWS prompt logs | a53edad7ef0c46ffb5037fb2e21520cb | `amazon_aws_raw` | For setup details, see [Prompt log collection in AWS](../../../../../detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/prompt-log-collection-in-aws). | +| AWS Route 53 logs | <p></p><ul><li>d57ae82c1e2a4d138fc34084d159b09e (old)</li><li>0a7544038b444998a20e698669817e3d (new)</li></ul> | <ul><li><code>amazon_route53_raw</code> (via old UUID)</li><li><code>amazon_route53_raw</code> (via new UUID)</li></ul> | These logs are collected via Amazon S3. Using the old UUID routes data to the generic AWS dataset. For native routing to the Route 53 dataset, use the new dedicated UUID. To ensure collector compatibility, see [Ingest network Route 53 logs from Amazon S3](../../amazon/amazon-s3/ingest-network-route-53-logs-from-amazon-s3). | ### Box -| Product | UUID | Datasets | Collection Method | -| ------- | -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Box | 3ef05d14ae9349f8bbd48c8a4797334a | <ul><li>Events (admin_logs): <code>box_admin_logs_raw</code></li><li>Box Shield Alerts: <code>box_shield_alerts_raw</code></li><li>Users: <code>box_users_raw</code></li><li>Groups: <code>box_groups_raw</code></li></ul> | <p>The <code>BOX_DIRECTORIES</code> connector queries the following Box API endpoints:</p><ul><li><p><strong>Users</strong></p><ul><li>Endpoint: <code>https://api.box.com/2.0/users</code></li><li>Purpose: To fetch the list of users in Box enterprise.</li></ul></li><li><p><strong>Groups</strong></p><ul><li>Endpoint: <code>https://api.box.com/2.0/groups</code></li><li>Purpose: To fetch the list of groups in Box enterprise.</li></ul></li></ul><p>For setup details, see <a href="https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/fMYJ2Gv_VvAIZTUvaHV6Jw">Ingest logs and data from Box</a>.</p> | +| Product | UUID | Datasets | Collection Method | +| ------- | -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| Box | 3ef05d14ae9349f8bbd48c8a4797334a | <ul><li>Events (admin_logs): <code>box_admin_logs_raw</code></li><li>Box Shield Alerts: <code>box_shield_alerts_raw</code></li><li>Users: <code>box_users_raw</code></li><li>Groups: <code>box_groups_raw</code></li></ul> | <p>The <code>BOX_DIRECTORIES</code> connector queries the following Box API endpoints:</p><ul><li><p><strong>Users</strong></p><ul><li>Endpoint: <code>https://api.box.com/2.0/users</code></li><li>Purpose: To fetch the list of users in Box enterprise.</li></ul></li><li><p><strong>Groups</strong></p><ul><li>Endpoint: <code>https://api.box.com/2.0/groups</code></li><li>Purpose: To fetch the list of groups in Box enterprise.</li></ul></li></ul><p>For setup details, see <a href="../../box/ingest-logs-and-data-from-box">Ingest logs and data from Box</a>.</p> | ### CrowdStrike -| Product | UUID | Datasets | Collection Method | -| --------------- | -------------------------------- | --------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Falcon incident | 230b2b0233bf4327806af72e6e5769f3 | `crowdstrike_falcon_incident_raw` | <p>Currently not supported by Cribl</p><p>CrowdStrike Streaming API</p><p>Base URL: <code>https://api.crowdstrike.com</code> (or <code>api.us-2.crowdstrike.com</code>, <code>api.eu-1.crowdstrike.com</code>, etc.)</p><p><code>GET /sensors/entities/datafeed/v2</code></p><p>For setup details, see <a href="https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/TtLDsZ_A1Fl0nrH5Q73r1A">Ingest alerts and metadata from CrowdStrike APIs</a>.</p> | -| Hosts | 8b673ac8e2f34b4a8dc14c22f0e6063b | `crowdstrike_hosts_raw` | <p>CrowdStrike Devices API</p><p><code>GET /devices/queries/devices-scroll/v1</code></p><p><code>POST /devices/entities/devices/v2</code></p><p>For setup details, see <a href="https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/TtLDsZ_A1Fl0nrH5Q73r1A">Ingest alerts and metadata from CrowdStrike APIs</a>.</p> | +| Product | UUID | Datasets | Collection Method | +| --------------- | -------------------------------- | --------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| Falcon incident | 230b2b0233bf4327806af72e6e5769f3 | `crowdstrike_falcon_incident_raw` | <p>Currently not supported by Cribl</p><p>CrowdStrike Streaming API</p><p>Base URL: <code>https://api.crowdstrike.com</code> (or <code>api.us-2.crowdstrike.com</code>, <code>api.eu-1.crowdstrike.com</code>, etc.)</p><p><code>GET /sensors/entities/datafeed/v2</code></p><p>For setup details, see <a href="../../crowdstrike/crowdstrike-apis/ingest-alerts-and-metadata-from-crowdstrike-apis">Ingest alerts and metadata from CrowdStrike APIs</a>.</p> | +| Hosts | 8b673ac8e2f34b4a8dc14c22f0e6063b | `crowdstrike_hosts_raw` | <p>CrowdStrike Devices API</p><p><code>GET /devices/queries/devices-scroll/v1</code></p><p><code>POST /devices/entities/devices/v2</code></p><p>For setup details, see <a href="../../crowdstrike/crowdstrike-apis/ingest-alerts-and-metadata-from-crowdstrike-apis">Ingest alerts and metadata from CrowdStrike APIs</a>.</p> | ### Dropbox -| Product | UUID | Datasets | Collection Method | -| --------- | -------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Directory | e8d2c52bc9594621924fab0507264586 | <ul><li><code>dropbox_members_devices_raw</code></li><li><code>dropbox_users_raw</code></li><li><code>dropbox_groups_raw</code></li></ul> | <p>Base URL: <code>https://api.dropboxapi.com</code></p><ul><li><p>Users (dropbox_users_raw)</p><ul><li>Endpoint: <code>/2/team/members/list_v2</code></li></ul></li><li><p>Groups (dropbox_groups_raw)</p><ul><li>Endpoint: <code>/2/team/groups/list</code></li></ul></li><li><p>Devices (dropbox_member_devices_raw)</p><ul><li>Endpoint: <code>/2/team/devices/list_members_devices</code></li></ul></li></ul><p>For setup details, see <a href="https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/iDE0JM29xSB9vSLr9OHXpQ">Ingest logs and data from Dropbox</a>.</p> | -| Events | a6322b2fd9e545e0a4223ba754c48fb9 | `dropbox_events_raw` | <p>Base URL: <code>https://api.dropboxapi.com</code></p><p>Endpoint: <code>/2/team_log/get_events</code></p><p>For setup details, see <a href="https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/iDE0JM29xSB9vSLr9OHXpQ">Ingest logs and data from Dropbox</a>.</p> | +| Product | UUID | Datasets | Collection Method | +| --------- | -------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| Directory | e8d2c52bc9594621924fab0507264586 | <ul><li><code>dropbox_members_devices_raw</code></li><li><code>dropbox_users_raw</code></li><li><code>dropbox_groups_raw</code></li></ul> | <p>Base URL: <code>https://api.dropboxapi.com</code></p><ul><li><p>Users (dropbox_users_raw)</p><ul><li>Endpoint: <code>/2/team/members/list_v2</code></li></ul></li><li><p>Groups (dropbox_groups_raw)</p><ul><li>Endpoint: <code>/2/team/groups/list</code></li></ul></li><li><p>Devices (dropbox_member_devices_raw)</p><ul><li>Endpoint: <code>/2/team/devices/list_members_devices</code></li></ul></li></ul><p>For setup details, see <a href="../../dropbox/ingest-logs-and-data-from-dropbox">Ingest logs and data from Dropbox</a>.</p> | +| Events | a6322b2fd9e545e0a4223ba754c48fb9 | `dropbox_events_raw` | <p>Base URL: <code>https://api.dropboxapi.com</code></p><p>Endpoint: <code>/2/team_log/get_events</code></p><p>For setup details, see <a href="../../dropbox/ingest-logs-and-data-from-dropbox">Ingest logs and data from Dropbox</a>.</p> | ### Google -| Product | UUID | Datasets | Collection Method | -| ------------------------------------ | -------------------------------- | ---------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Cloud Logging (audit logs/flow logs) | 00a8322c85e14beabfa7ad5f3d62db73 | `google_cloud_logging_raw` | For setup details, see [Ingest logs and data from a GCP Pub/Sub](https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/SOO6SvoFIVuIyLqjQCd2aA). | -| Gmail | 8607490288d1407ba82b5c5ad9dc64a0 | `google_gmail_raw` | <p><code>GET https://gmail.googleapis.com/gmail/v1/users/{userId}/messages</code></p><p>For setup details, see <a href="https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/uDPSwq1lQQfl~wXgMGBlmQ">Ingest logs and data from Google Workspace</a>.</p> | -| Workspace alerts | 4f263650cd29475c81f2ff953cf19827 | `google_workspace_alerts_raw` | <p>Description: Ingests security and system alerts from the Google Workspace Alert Center.</p><ul><li><p>API Details</p><ul><li>API Name: Google Alert Center API</li><li>Version: <code>v1beta1</code></li><li>Base URL: <code>https://alertcenter.googleapis.com</code></li><li>Endpoint: <code>/v1beta1/alerts</code></li><li>Method: <code>GET (List)</code></li><li>OAuth Scope: <code>https://www.googleapis.com/auth/apps.alerts</code></li></ul></li><li><p>Request Parameters</p><ul><li>filter: Used for incremental ingestion based on <code>createTime</code>.</li><li>Format: <code>createTime >= "[TIMESTAMP_START]" AND createTime &#x3C; "[TIMESTAMP_END]"</code></li><li>orderBy: <code>createTime asc</code></li><li>pageToken: Used for pagination.</li></ul></li><li><p>Data Mapping</p><ul><li>Source: The full JSON response object from the <code>alerts</code> list.</li><li>Destination: Each alert object is ingested as a single record.</li></ul></li></ul><p>For setup details, see <a href="https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/uDPSwq1lQQfl~wXgMGBlmQ">Ingest logs and data from Google Workspace</a>.</p> | -| Workspace ChromeOS devices | e82ae276e6b9442fa80920a03d2a38d6 | `google_workspace_chrome_raw` | <p><code>GET https://admin.googleapis.com/admin/directory/v1/customer/{customer}/devices/chromeos</code></p><p>For setup details, see <a href="https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/uDPSwq1lQQfl~wXgMGBlmQ">Ingest logs and data from Google Workspace</a>.</p> | -| Workspace groups | 689ae8ef14e848e3855b81e91d8af9bc | `google_workspace_enterprise_groups_raw` | <p><code>GET https://admin.googleapis.com/admin/directory/v1/groups</code></p><p>For setup details, see <a href="https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/uDPSwq1lQQfl~wXgMGBlmQ">Ingest logs and data from Google Workspace</a>.</p> | -| Workspace rules | 2621aaf3334a4147ae727afe84db31a9 | `google_workspace_rules_raw` | <p><code>GET https://gmail.googleapis.com/gmail/v1/users/{userId}/settings/filters</code></p><p>For setup details, see <a href="https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/uDPSwq1lQQfl~wXgMGBlmQ">Ingest logs and data from Google Workspace</a>.</p> | -| Workspace users | 359ecd845fa54caab6ddb4b7c7a2764d | `google_workspace_user_acounts_raw` | <p><code>GET https://admin.googleapis.com/admin/directory/v1/users/{userKey}</code></p><p>For setup details, see <a href="https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/uDPSwq1lQQfl~wXgMGBlmQ">Ingest logs and data from Google Workspace</a>.</p> | +| Product | UUID | Datasets | Collection Method | +| ------------------------------------ | -------------------------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| Cloud Logging (audit logs/flow logs) | 00a8322c85e14beabfa7ad5f3d62db73 | `google_cloud_logging_raw` | For setup details, see [Ingest logs and data from a GCP Pub/Sub](../../google/google-cloud-platform/ingest-logs-and-data-from-a-gcp-pub-sub). | +| Gmail | 8607490288d1407ba82b5c5ad9dc64a0 | `google_gmail_raw` | <p><code>GET https://gmail.googleapis.com/gmail/v1/users/{userId}/messages</code></p><p>For setup details, see <a href="../../google/google-workspace/ingest-logs-and-data-from-google-workspace">Ingest logs and data from Google Workspace</a>.</p> | +| Workspace alerts | 4f263650cd29475c81f2ff953cf19827 | `google_workspace_alerts_raw` | <p>Description: Ingests security and system alerts from the Google Workspace Alert Center.</p><ul><li><p>API Details</p><ul><li>API Name: Google Alert Center API</li><li>Version: <code>v1beta1</code></li><li>Base URL: <code>https://alertcenter.googleapis.com</code></li><li>Endpoint: <code>/v1beta1/alerts</code></li><li>Method: <code>GET (List)</code></li><li>OAuth Scope: <code>https://www.googleapis.com/auth/apps.alerts</code></li></ul></li><li><p>Request Parameters</p><ul><li>filter: Used for incremental ingestion based on <code>createTime</code>.</li><li>Format: <code>createTime >= "[TIMESTAMP_START]" AND createTime &#x3C; "[TIMESTAMP_END]"</code></li><li>orderBy: <code>createTime asc</code></li><li>pageToken: Used for pagination.</li></ul></li><li><p>Data Mapping</p><ul><li>Source: The full JSON response object from the <code>alerts</code> list.</li><li>Destination: Each alert object is ingested as a single record.</li></ul></li></ul><p>For setup details, see <a href="../../google/google-workspace/ingest-logs-and-data-from-google-workspace">Ingest logs and data from Google Workspace</a>.</p> | +| Workspace ChromeOS devices | e82ae276e6b9442fa80920a03d2a38d6 | `google_workspace_chrome_raw` | <p><code>GET https://admin.googleapis.com/admin/directory/v1/customer/{customer}/devices/chromeos</code></p><p>For setup details, see <a href="../../google/google-workspace/ingest-logs-and-data-from-google-workspace">Ingest logs and data from Google Workspace</a>.</p> | +| Workspace groups | 689ae8ef14e848e3855b81e91d8af9bc | `google_workspace_enterprise_groups_raw` | <p><code>GET https://admin.googleapis.com/admin/directory/v1/groups</code></p><p>For setup details, see <a href="../../google/google-workspace/ingest-logs-and-data-from-google-workspace">Ingest logs and data from Google Workspace</a>.</p> | +| Workspace rules | 2621aaf3334a4147ae727afe84db31a9 | `google_workspace_rules_raw` | <p><code>GET https://gmail.googleapis.com/gmail/v1/users/{userId}/settings/filters</code></p><p>For setup details, see <a href="../../google/google-workspace/ingest-logs-and-data-from-google-workspace">Ingest logs and data from Google Workspace</a>.</p> | +| Workspace users | 359ecd845fa54caab6ddb4b7c7a2764d | `google_workspace_user_acounts_raw` | <p><code>GET https://admin.googleapis.com/admin/directory/v1/users/{userKey}</code></p><p>For setup details, see <a href="../../google/google-workspace/ingest-logs-and-data-from-google-workspace">Ingest logs and data from Google Workspace</a>.</p> | ### Microsoft -| Product | UUID | Datasets | Collection Method | -| ---------------------------- | -------------------------------- | --------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Azure | fce13a1d51294f84bae4a37851503060 | `msft_azure_raw` | Azure Event Hubs SDK (AMQP): For setup details, see [Ingest logs from Microsoft Azure Event Hub](https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/4LLXKzO36I20QQGrw1xxyA). | -| Azure AD | c00d6d52e5b141a8baa8db9d9345423d | `msft_azure_ad_raw` | For set up details, see [Ingest logs from Microsoft Office 365](https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/XheKsWe5S23TZn0CmNuvuw). | -| Azure AD audit | 0e076d5abe864bf78e8145ea9e0d749e | `msft_azure_ad_audit_raw` | <p>Microsoft Graph API: <code>GET /v1.0/auditLogs/directoryaudits</code></p><p>For set up details, see <a href="https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/XheKsWe5S23TZn0CmNuvuw">Ingest logs from Microsoft Office 365</a>.</p> | -| Azure AD sign-ins | f56dcfdf6bca43e793a4b6e9290e7b12 | `msft_azure_ad_raw` | <p>Microsoft Graph API: <code>GET /v1.0/auditLogs/signIns</code></p><p>For set up details, see <a href="https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/XheKsWe5S23TZn0CmNuvuw">Ingest logs from Microsoft Office 365</a>.</p> | -| Defender | ce9e8cf36e0742c38aa89787a256855f | `msft_defender_raw` | <p>Azure Event Hubs SDK (AMQP): For setup details, see <a href="https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/Cl6c95zSJucBCumV0Hw2oA">Ingest raw EDR events from Microsoft Defender for Endpoint</a>.</p><p>To enable analytics, contact <a href="https://support.paloaltonetworks.com/Support/Index">Customer Support</a>.</p> | -| DHCP | b55819e8959c49728d5d98a6d87eafb6 | `msft_dhcp_raw` | <p><code>File Collection: C:\Windows\System32\dhcp\DhcpSrvLog-*.log</code></p><p>For set up details, see <a href="https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/HEli8KQ0W3qDqnNUXBRegw">Ingest logs from Windows DHCP using Elasticsearch Filebeat</a>.</p> | -| Graph security alerts | 5619f2f691fc46c4b202587fdaa031c3 | `msft_graph_security_alerts_raw` | <p>Microsoft Graph API: <code>/v1.0/security/alerts_v2</code></p><p>For set up details, see <a href="https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/XheKsWe5S23TZn0CmNuvuw">Ingest logs from Microsoft Office 365</a>.</p> | -| Office 365 Azure AD | e1f109f886ea42fbb96be6ec0cc597a9 | `msft_o365_azure_ad_raw` | <p>The Base URLs for the APIs are (depending on the environment):</p><p>Worldwide: <code>https://manage.office.com</code></p><p>GCC: <code>https://manage-gcc.office.com</code></p><p>GCC High: <code>https://manage.office365.us</code></p><p>DoD: <code>https://manage.protection.apps.mil</code></p><p>Endpoints:</p><p>Start Subscription: <code>/api/v1.0/{tenantID}/activity/feed/subscriptions/start?contentType={type}</code></p><p>List Available Content: <code>/api/v1.0/{tenantID}/activity/feed/subscriptions/content?contentType={type}</code></p><p>Fetch Content Blob: Dynamic URI returned from the “List Available Content” call.</p><p>Content Types: <code>audit.exchange</code>, <code>audit.sharepoint</code>, <code>audit.general</code>, <code>audit.azureactivedirectory</code>, <code>dlp.all</code>.</p><p>For set up details, see <a href="https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/XheKsWe5S23TZn0CmNuvuw">Ingest logs from Microsoft Office 365</a>.</p> | -| Office 365 DLP | 8f052782739d4b8389644cca23b994ac | `msft_o365_dlp_raw` | <p>See Office 365 Azure AD.</p><p>For set up details, see <a href="https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/XheKsWe5S23TZn0CmNuvuw">Ingest logs from Microsoft Office 365</a>.</p> | -| Office 365 domains | cae29fd87b554bd9a5694afb225e8dc9 | `msft_o365_domains_raw` | Microsoft Graph API: `GET /v1.0/domains` | -| Office 365 Exchange Online | dee8e85ce7db4573a8bc21b807e1d73a | `msft_o365_exchange_online_raw` | <p>See Office 365 Azure AD.</p><p>For set up details, see <a href="https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/XheKsWe5S23TZn0CmNuvuw">Ingest logs from Microsoft Office 365</a>.</p> | -| Office 365 General | c7655e83805b4a058e66043a6715156c | `msft_o365_general_raw` | <p>See Office 365 Azure AD.</p><p>For set up details, see <a href="https://docs-cortex.paloaltonetworks.com/r/5CAbsl8idaK8R43ZLhoTOw/XheKsWe5S23TZn0CmNuvuw">Ingest logs from Microsoft Office 365</a>.</p> | @@ diff truncated @@ -
▸ ▾ Cortex XSIAM development tenant modified +1 −0 "Case fields and layouts" added to the list of content push/pull-supported between the dev tenant and a remote repository.
xsiam/configure-cortex-xsiam/remote-repository-management/cortex-xsiam-development-tenantRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -38,16 +38,17 @@ In a cluster of tenants that includes one production tenant and one or more deveOnly the development push tenant manages the system content and updates. Pull tenants cannot manage system content, meaning they cannot download, install, edit, create, or update system content; they are configured to only pull system content from the push tenant. Only the development push tenant has access to Marketplace, so system content updates from Marketplace are delivered only to the development push tenant. Pull tenants do not have Marketplace, so all system content must first be downloaded and installed on the push tenant, pushed to the remote repository, and then pulled into the pull tenants.Only the development push tenant manages the system content and updates. Pull tenants cannot manage system content, meaning they cannot download, install, edit, create, or update system content; they are configured to only pull system content from the push tenant. Only the development push tenant has access to Marketplace, so system content updates from Marketplace are delivered only to the development push tenant. Pull tenants do not have Marketplace, so all system content must first be downloaded and installed on the push tenant, pushed to the remote repository, and then pulled into the pull tenants.### Push and pull custom content### Push and pull custom contentNot all custom content can be pushed/pulled. Content that cannot be pushed/pulled can be developed wherever you prefer - in both the development and production tenants, or copied from the development tenant into the production tenant. For example, content that cannot be pushed/pulled includes dashboards and lists, parsing rules, data modeling rules, and correlation rules.Not all custom content can be pushed/pulled. Content that cannot be pushed/pulled can be developed wherever you prefer - in both the development and production tenants, or copied from the development tenant into the production tenant. For example, content that cannot be pushed/pulled includes dashboards and lists, parsing rules, data modeling rules, and correlation rules.The following system and user-defined content types are push/pull supported:The following system and user-defined content types are push/pull supported:• Case fields and layouts• Issue types and fields• Issue types and fields• Indicator types and fields• Indicator types and fields• Issue and indicator layouts• Issue and indicator layouts• Layouts• Layouts• Classifiers• Classifiers• Integrations• Integrations• Playbooks• Playbooks• Scripts• ScriptsShow markdown source
@@ -38,16 +38,17 @@ In a cluster of tenants that includes one production tenant and one or more deve Only the development push tenant manages the system content and updates. Pull tenants cannot manage system content, meaning they cannot download, install, edit, create, or update system content; they are configured to only pull system content from the push tenant. Only the development push tenant has access to Marketplace, so system content updates from Marketplace are delivered only to the development push tenant. Pull tenants do not have Marketplace, so all system content must first be downloaded and installed on the push tenant, pushed to the remote repository, and then pulled into the pull tenants. ### Push and pull custom content Not all custom content can be pushed/pulled. Content that cannot be pushed/pulled can be developed wherever you prefer - in both the development and production tenants, or copied from the development tenant into the production tenant. For example, content that cannot be pushed/pulled includes dashboards and lists, parsing rules, data modeling rules, and correlation rules. The following system and user-defined content types are push/pull supported: +* Case fields and layouts * Issue types and fields * Indicator types and fields * Issue and indicator layouts * Layouts * Classifiers * Integrations * Playbooks * Scripts