Documentation — August 18, 2026
47 files changed, 99 insertions, 129 deletions — view the commit on the mirror.
Unlinking every issue deletes the case; XDR agent 9.3 and 9.2 added to the mobile support tables
- Linking issues to cases gains a warning: unlink the last issue and the case itself is deleted.
- Mobile operating systems supported with Cortex XDR adds Cortex XDR agent 9.3 and 9.2 columns to both the Android and the iOS/iPadOS table.
- CSP onboarding now lists manual onboarding for Azure alongside AWS and GCP, and renames the automated path to Infrastructure as Code.
- The remaining two changes are housekeeping: a duplicated icon table removed and a link title typo fixed.
- Five pages in total, none added, removed or renamed.
Highlights
-
Unlinking all issues from a case deletes the case
A new warning hint on the link/unlink page states the case is deleted once its last issue is unlinked, which the page did not previously say.
-
Manual CSP onboarding is now available for Azure
The note limiting manual onboarding to AWS and GCP now reads AWS, Azure and GCP, and the automated alternative is described as provisioning resources from an Infrastructure as Code template.
-
Cortex XDR agent 9.3 and 9.2 join the mobile compatibility tables
Both tables gain two columns; Android 26 and iOS 26 are marked supported on 9.3 and 9.2, and the existing 9.1 through 8.8 rows are unchanged.
Changes
47 files listed.
-
▸ ▾ Navigation manifest (xsiam) modified +24 −24
.meta/xsiamThe book's page tree and ordering — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Cortex XDR Mobile Patch Releases modified +2 −0
agent-releases/cortex-xdr-mobile-patch-releasesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -5,16 +5,17 @@ description: View the list of Cortex XDR agent releases for iOS and Android devi# Cortex XDR Mobile Patch Releases# Cortex XDR Mobile Patch ReleasesPalo Alto Networks has introduced the following Cortex XDR mobile patch releases.Palo Alto Networks has introduced the following Cortex XDR mobile patch releases.### iOS patch releases### iOS patch releasesRelease│Description│Release dateRelease│Description│Release date| --------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------ || --------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------ |@@ -37,16 +38,17 @@ Palo Alto Networks has introduced the following Cortex XDR mobile patch releasesiOS agent 8.0.2│Bug and stability fixes.│June 8, 2023iOS agent 8.0.2│Bug and stability fixes.│June 8, 2023iOS agent 8.0.1│Improved handling of upgrade from previous versions.│April 30, 2023iOS agent 8.0.1│Improved handling of upgrade from previous versions.│April 30, 2023iOS agent 7.9.1│Bug and stability fixes.│January 11, 2023iOS agent 7.9.1│Bug and stability fixes.│January 11, 2023### Android patch releases### Android patch releasesRelease│Description│Release dateRelease│Description│Release date| ------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------ || ------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------ |Show markdown source
@@ -5,16 +5,17 @@ description: View the list of Cortex XDR agent releases for iOS and Android devi # Cortex XDR Mobile Patch Releases Palo Alto Networks has introduced the following Cortex XDR mobile patch releases. ### iOS patch releases | **Release** | **Description** | **Release date** | | --------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------ | +| iOS agent 9.3 | See [Cortex XDR agent 9.3 for iOS Admin Guide](https://app.gitbook.com/s/SWFPEIBoXldQgCVj3v2G/get-started/release-notes-for-cortex-xdr-agent-app-for-ios) | August 17, 2026 | | iOS agent 9.2.1 | See [Cortex XDR agent 9.2.1 for iOS Admin Guide](https://app.gitbook.com/s/F35cjNUN0gfmSMoHZaoZ/get-started/release-notes-for-cortex-xdr-agent-app-for-ios) | June 21, 2026 | | iOS agent 9.2 | See [Cortex XDR agent 9.2 for iOS Admin Guide](https://app.gitbook.com/s/F35cjNUN0gfmSMoHZaoZ/get-started/cortex-xdr-agent-app-for-ios-overview) | June 1, 2026 | | iOS agent 9.1 | See [Cortex XDR agent 9.1 for iOS Admin Guide](https://app.gitbook.com/s/5fxpS5AyVNn00U58Dbvo/get-started/cortex-xdr-agent-app-for-ios-overview) | February 22, 2026 | | iOS agent 9.0.2 | See [Cortex XDR agent 9.0 for iOS Admin Guide](https://app.gitbook.com/s/oSF8DwbRhPf4a1dbxU7k/get-started/cortex-xdr-agent-app-for-ios-overview) | January 7, 2026 | | iOS agent 9.0.1 | See [Cortex XDR agent 9.0 for iOS Admin Guide](https://app.gitbook.com/s/oSF8DwbRhPf4a1dbxU7k/get-started/cortex-xdr-agent-app-for-ios-overview) | December 10, 2025 | | iOS agent 9.0 | See [Cortex XDR agent 9.0 for iOS Admin Guide](https://app.gitbook.com/s/oSF8DwbRhPf4a1dbxU7k/get-started/cortex-xdr-agent-app-for-ios-overview) | November 16, 2025 | | iOS agent 8.9.2 | See [Cortex XDR agent 8.9 for iOS Admin Guide](https://app.gitbook.com/s/J2tiBT5tFuevmxUOHJKw/get-started/cortex-xdr-agent-app-for-ios-overview) | September 8, 2025 | | iOS agent 8.9.1 | See [Cortex XDR agent 8.9 for iOS Admin Guide](https://app.gitbook.com/s/J2tiBT5tFuevmxUOHJKw/get-started/cortex-xdr-agent-app-for-ios-overview) | August 14, 2025 | @@ -37,16 +38,17 @@ Palo Alto Networks has introduced the following Cortex XDR mobile patch releases | iOS agent 8.0.2 | Bug and stability fixes. | June 8, 2023 | | iOS agent 8.0.1 | Improved handling of upgrade from previous versions. | April 30, 2023 | | iOS agent 7.9.1 | Bug and stability fixes. | January 11, 2023 | ### Android patch releases | Release | Description | Release date | | ------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------ | +| Android agent 9.3 | See [Cortex XDR agent 9.3 for Android Admin Guide](https://app.gitbook.com/s/nEfCCoGvJviwT2qZg51w/release-notes-for-cortex-xdr-app-for-android) | August 17, 2026 | | Android agent 9.2 | See [Cortex XDR agent 9.2 for Android Admin Guide](https://app.gitbook.com/s/xwubWOQcxXUOPZsR9Uht/) | June 14, 2026 | | Android agent 9.1 | See [Cortex XDR agent 9.1 for Android Admin Guide](https://app.gitbook.com/s/UeC5Yo1VlRfI7KCnJy58/) | March 8, 2026 | | Android agent 9.0.2 | See [Cortex XDR agent 9.0 for Android Admin Guide](https://app.gitbook.com/s/6ETa5ce6hEj1jPE5qXtg/) | January 7, 2026 | | Android agent 9.0.1 | See [Cortex XDR agent 9.0 for Android Admin Guide](https://app.gitbook.com/s/6ETa5ce6hEj1jPE5qXtg/) | December 10, 2025 | | Android agent 9.0 | See [Cortex XDR agent 9.0 for Android Admin Guide](https://app.gitbook.com/s/6ETa5ce6hEj1jPE5qXtg/) | November 16, 2025 | | Android agent 8.9.4 | See [Cortex XDR agent 8.9 for Android Admin Guide](https://app.gitbook.com/s/UCCIJMbptMcUnxRSFOk5/) | October 26, 2025 | | Android agent 8.9.3 | See [Cortex XDR agent 8.9 for Android Admin Guide](https://app.gitbook.com/s/UCCIJMbptMcUnxRSFOk5/) | October 20, 2025 | | Android agent 8.9.2 | See [Cortex XDR agent 8.9 for Android Admin Guide](https://app.gitbook.com/s/UCCIJMbptMcUnxRSFOk5/) | September 11, 2025 |
-
▸ ▾ Linux modified +1 −1
compatibility/where-can-i-install-the-cortex-xdr-agent/endpoint-operating-systems-supported/linuxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -101,9 +101,9 @@ RHEL 9.3 and later requires Cortex XDR agent version 8.2 or later.Server 16.0│✓│✓│✓From content release 2280-36261
│✓From content release 2280-36261
│—│—Server 16.0│✓│✓│✓From content release 2280-36261
│✓From content release 2280-36261
│—│—Server 15 SP7│✓│✓│✓│✓│✓│✓From content release 1940-22526
Server 15 SP7│✓│✓│✓│✓│✓│✓From content release 1940-22526
Server 15 SP0-SP6│✓│✓│✓│✓│✓│✓Server 15 SP0-SP6│✓│✓│✓│✓│✓│✓Server 12 SP4-SP5│✓│✓│✓│✓│✓│✓Server 12 SP4-SP5│✓│✓│✓│✓│✓│✓Server 11 SP4│Async mode only│Async mode only│✓│✓│✓│✓Server 11 SP4│Async mode only│Async mode only│✓│✓│✓│✓### Ubuntu### UbuntuCortex XDR agent 9.3 9.2 9.1-CE 9.1 9.0 8.7-CE 24.04 LTS x86_64 ✓ ✓ ✓ ✓ ✓ ✓ 24.04 LTS aarch64 ✓ ✓ ✓ ✓ ✓ ✓ 22.04 LTS x86_64 ✓ ✓ ✓ ✓ ✓ ✓ 22.04 LTS aarch64 ✓ ✓ ✓ ✓ ✓ ✓ 20.04 LTS ✓ ✓ ✓ ✓ ✓ ✓ 20.04 LTS aarch64 ✓ ✓ ✓ ✓ ✓ ✓ 18.04 LTS ✓ ✓ ✓ ✓ ✓ ✓ 18.04 LTS aarch64 ✓ ✓ ✓ ✓ ✓ ✓ 16.04 LTS ✓ ✓ ✓ ✓ ✓ ✓ 14.04 LTS Async mode only Async mode only ✓ ✓ ✓ ✓ 12.04 LTS Async mode only Async mode only ✓ ✓ ✓ ✓ Cortex XDR agent 9.3 9.2 9.1-CE 9.1 9.0 8.7-CE 26.04 LTS x86_64 ✓ ✓ ✓ ✓ — — 26.04 LTS aarch64 ✓ ✓ ✓ ✓ — — 24.04 LTS x86_64 ✓ ✓ ✓ ✓ ✓ ✓ 24.04 LTS aarch64 ✓ ✓ ✓ ✓ ✓ ✓ 22.04 LTS x86_64 ✓ ✓ ✓ ✓ ✓ ✓ 22.04 LTS aarch64 ✓ ✓ ✓ ✓ ✓ ✓ 20.04 LTS ✓ ✓ ✓ ✓ ✓ ✓ 20.04 LTS aarch64 ✓ ✓ ✓ ✓ ✓ ✓ 18.04 LTS ✓ ✓ ✓ ✓ ✓ ✓ 18.04 LTS aarch64 ✓ ✓ ✓ ✓ ✓ ✓ 16.04 LTS ✓ ✓ ✓ ✓ ✓ ✓ 14.04 LTS Async mode only Async mode only ✓ ✓ ✓ ✓ 12.04 LTS Async mode only Async mode only ✓ ✓ ✓ ✓ Show markdown source
@@ -101,9 +101,9 @@ RHEL 9.3 and later requires Cortex XDR agent version 8.2 or later. | Server 16.0 | ✓ | ✓ | <p>✓</p><p>From content release 2280-36261</p> | <p>✓</p><p>From content release 2280-36261</p> | — | — | | Server 15 SP7 | ✓ | ✓ | ✓ | ✓ | ✓ | <p>✓</p><p>From content release 1940-22526</p> | | Server 15 SP0-SP6 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | | Server 12 SP4-SP5 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | | Server 11 SP4 | Async mode only | Async mode only | ✓ | ✓ | ✓ | ✓ | ### Ubuntu -<table data-search="false"><thead><tr><th></th><th>Cortex XDR agent</th><th></th><th></th><th></th><th></th><th></th></tr></thead><tbody><tr><td></td><td>9.3</td><td>9.2</td><td>9.1-CE</td><td>9.1</td><td>9.0</td><td>8.7-CE</td></tr><tr><td>24.04 LTS x86_64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>24.04 LTS aarch64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>22.04 LTS x86_64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>22.04 LTS aarch64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>20.04 LTS</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>20.04 LTS aarch64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>18.04 LTS</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>18.04 LTS aarch64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>16.04 LTS</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>14.04 LTS</td><td>Async mode only</td><td>Async mode only</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>12.04 LTS</td><td>Async mode only</td><td>Async mode only</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr></tbody></table> +<table data-search="false"><thead><tr><th></th><th>Cortex XDR agent</th><th></th><th></th><th></th><th></th><th></th></tr></thead><tbody><tr><td></td><td>9.3</td><td>9.2</td><td>9.1-CE</td><td>9.1</td><td>9.0</td><td>8.7-CE</td></tr><tr><td>26.04 LTS x86_64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>—</td><td>—</td></tr><tr><td>26.04 LTS aarch64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>—</td><td>—</td></tr><tr><td>24.04 LTS x86_64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>24.04 LTS aarch64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>22.04 LTS x86_64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>22.04 LTS aarch64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>20.04 LTS</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>20.04 LTS aarch64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>18.04 LTS</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>18.04 LTS aarch64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>16.04 LTS</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>14.04 LTS</td><td>Async mode only</td><td>Async mode only</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>12.04 LTS</td><td>Async mode only</td><td>Async mode only</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr></tbody></table>
-
▸ ▾ Onboard Aha.io modified +1 −1
xsiam/cloud-security/cortex-cloud-saas-security/onboard-a-supported-saas-application/onboard-aha.ioRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -4,17 +4,17 @@ description: Onboard Aha.io to track misconfigurations and monitor application c# Onboard Aha.io# Onboard Aha.ioFor SaaS Security to detect posture risks in your Aha.io instance, you must onboard your Aha.io instance to SaaS Security. Through the onboarding process, SaaS Security logs in to Aha.io using administrator account credentials. This account is used to scan your Aha.io instance for misconfigured settings. If there are misconfigured settings, SaaS Security suggests a remediation action based on best practices.For SaaS Security to detect posture risks in your Aha.io instance, you must onboard your Aha.io instance to SaaS Security. Through the onboarding process, SaaS Security logs in to Aha.io using administrator account credentials. This account is used to scan your Aha.io instance for misconfigured settings. If there are misconfigured settings, SaaS Security suggests a remediation action based on best practices.SaaS Security gets access to your Aha.io instance by using Okta SSO or Microsoft Azure credentials that you provide during the onboarding process. For this reason, your organization must be using Okta or Microsoft Azure as an identity provider. The Okta or Microsoft Azure account must be configured for multi-factor authentication (MFA) using one-time passcodes.SaaS Security gets access to your Aha.io instance by using Okta SSO or Microsoft Azure credentials that you provide during the onboarding process. For this reason, your organization must be using Okta or Microsoft Azure as an identity provider. The Okta or Microsoft Azure account must be configured for multi-factor authentication (MFA) using one-time passcodes.\\To onboard your Aha.io instance, you complete the following actions:To onboard your Aha.io instance, you must complete the following actions:1. Collect information for accessing your Aha.io instance.1. Collect information for accessing your Aha.io instance.To access your Aha.io instance, you will need the following information, which you will specify during the onboarding process:To access your Aha.io instance, you will need the following information, which you will specify during the onboarding process:• User email: The login email address of the account that SSPM will use to access your Aha.io instance. Required Permissions: The user account must be assigned to both the Account and Billing administrator roles in Aha.io.• User email: The login email address of the account that SSPM will use to access your Aha.io instance. Required Permissions: The user account must be assigned to both the Account and Billing administrator roles in Aha.io.• Password: The password for the login account.• Password: The password for the login account.• Instance Host: The custom domain for accessing your organization's Aha.io account. You specify this domain when you sign up for an Aha.io account, and it is included as part of the URL that you use to access the account.• Instance Host: The custom domain for accessing your organization's Aha.io account. You specify this domain when you sign up for an Aha.io account, and it is included as part of the URL that you use to access the account.Show markdown source
@@ -4,17 +4,17 @@ description: Onboard Aha.io to track misconfigurations and monitor application c # Onboard Aha.io For SaaS Security to detect posture risks in your Aha.io instance, you must onboard your [Aha.io](http://aha.io) instance to SaaS Security. Through the onboarding process, SaaS Security logs in to Aha.io using administrator account credentials. This account is used to scan your Aha.io instance for misconfigured settings. If there are misconfigured settings, SaaS Security suggests a remediation action based on best practices.  SaaS Security gets access to your Aha.io instance by using Okta SSO or Microsoft Azure credentials that you provide during the onboarding process. For this reason, your organization must be using Okta or Microsoft Azure as an identity provider. The Okta or Microsoft Azure account must be configured for multi-factor authentication (MFA) using one-time passcodes.  \ -To onboard your Aha.io instance, you complete the following actions:  +To onboard your Aha.io instance, you must complete the following actions:  1. Collect information for accessing your Aha.io instance.  To access your Aha.io instance, you will need the following information, which you will specify during the onboarding process: * User email: The login email address of the account that SSPM will use to access your Aha.io instance. Required Permissions: The user account must be assigned to both the Account and Billing administrator roles in Aha.io. * Password: The password for the login account. * Instance Host: The custom domain for accessing your organization's Aha.io account. You specify this domain when you sign up for an Aha.io account, and it is included as part of the URL that you use to access the account.
-
▸ ▾ Prerequisites for onboarding Alibaba Cloud modified +5 −3
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/alibaba-cloud-cloud-onboarding/prerequisites-for-onboarding-alibaba-cloudRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -68,24 +68,26 @@ Use the following template to create a custom policy with the permissions requirIn order to establish trust between Cortex XSIAM and Alibaba Cloud, you must add an OpenID Connect (OIDC) provider. If you already have an existing OIDC provider foraccounts.google.com, you can add Cortex XSIAM as an audience to the existing provider. Otherwise, create a new OIDC provider.In order to establish trust between Cortex XSIAM and Alibaba Cloud, you must add an OpenID Connect (OIDC) provider. If you already have an existing OIDC provider foraccounts.google.com, you can add Cortex XSIAM as an audience to the existing provider. Otherwise, create a new OIDC provider.#### Add the audience to an existing OIDC provider#### Add the audience to an existing OIDC provider1. In Alibaba Cloud Console, navigate to RAM → Integrations → SSO.1. In Alibaba Cloud Console, navigate to RAM → Integrations → SSO.2. In SSO, select the OIDC tab.2. In SSO, select the OIDC tab.3. In the list of IdPs, identify the existing entry for GCP (accounts.google.com) and click it.3. In the list of IdPs, identify the existing entry for GCP (accounts.google.com) and click it.4. Under Client ID, click Add.4. Under Client ID, click Add.5. Enteralibaba-cortex-wifas the audience value for the new client ID and save the changes.5. Enter alibaba-cortex-wif- as the audience value for the new client ID where corresponds to the Cortex XSIAM Project ID. Save the changes.#### Create a new OIDC provider#### Create a new OIDC providerBefore you begin, obtain the Cortex XSIAM Project ID of your tenant by clicking on the User menu and then selecting About.Before you begin, obtain the Cortex XSIAM Project ID of your tenant by clicking on the User menu and then selecting About.1. In Alibaba Cloud Console, navigate to RAM → Integrations → SSO.1. In Alibaba Cloud Console, navigate to RAM → Integrations → SSO.2. In SSO, select the OIDC tab.2. In SSO, select the OIDC tab.3. Click Create IdP.3. Click Create IdP.4. In Create IdP, enter the IdP Name. For example,CortexGCPProvider.4. In Create IdP, enter the IdP Name. For example,CortexGCPProvider.5. In Issuer URL, enter the GCP IdP URL:https://accounts.google.com.5. In Issuer URL, enter the GCP IdP URL:https://accounts.google.com.6. In Client ID, enter:alibaba-cortex-wif-<accountID>where<accountID>corresponds to the Cortex XSIAM Project ID.6. In Client ID, enter:alibaba-cortex-wif-<accountID>where<accountID>corresponds to the Cortex XSIAM Project ID.7. In Fingerprint, enter the SHA1 fingerprint of the signing certificate foraccounts.google.com. Note that this fingerprint changes periodically and must be kept up-to-date.7. In Fingerprint, click Auto-add to automatically retrieve and add the signing certificate fingerprint foraccounts.google.com.8. Save the changes.8. (cn-hongkong accounts only) In Fingerprint, click Add and enter the following SHA1 fingerprint:932bed339aa69212c89375b79304b475490b89a0.9. Click Add Fingerprint.10. Save the changes.####
####
Show markdown source
@@ -68,24 +68,26 @@ Use the following template to create a custom policy with the permissions requir In order to establish trust between Cortex XSIAM and Alibaba Cloud, you must add an OpenID Connect (OIDC) provider. If you already have an existing OIDC provider for `accounts.google.com`, you can add Cortex XSIAM as an audience to the existing provider. Otherwise, create a new OIDC provider. #### Add the audience to an existing OIDC provider 1. In Alibaba Cloud Console, navigate to **RAM → Integrations → SSO**. 2. In **SSO**, select the **OIDC** tab. 3. In the list of IdPs, identify the existing entry for GCP (`accounts.google.com`) and click it. 4. Under **Client ID**, click **Add**. -5. Enter `alibaba-cortex-wif` as the audience value for the new client ID and save the changes. +5. Enter alibaba-cortex-wif- as the audience value for the new client ID where corresponds to the Cortex XSIAM Project ID. Save the changes. #### Create a new OIDC provider Before you begin, obtain the Cortex XSIAM Project ID of your tenant by clicking on the User menu and then selecting About. 1. In Alibaba Cloud Console, navigate to **RAM → Integrations → SSO**. 2. In **SSO**, select the **OIDC** tab. 3. Click **Create IdP**. 4. In **Create IdP**, enter the **IdP Name**. For example, `CortexGCPProvider`. 5. In **Issuer URL**, enter the GCP IdP URL: `https://accounts.google.com`. 6. In **Client ID**, enter: `alibaba-cortex-wif-<accountID>` where `<accountID>` corresponds to the Cortex XSIAM Project ID. -7. In **Fingerprint**, enter the SHA1 fingerprint of the signing certificate for `accounts.google.com`. Note that this fingerprint changes periodically and must be kept up-to-date. -8. Save the changes. +7. In **Fingerprint**, click **Auto-add** to automatically retrieve and add the signing certificate fingerprint for `accounts.google.com`. +8. (cn-hongkong accounts only) In **Fingerprint**, click **Add** and enter the following SHA1 fingerprint: `932bed339aa69212c89375b79304b475490b89a0`. +9. Click **Add Fingerprint**. +10. Save the changes. #### <br>
-
▸ ▾ Amazon Cloud Watch modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-cloud-watchRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@# Amazon Cloud Watch# Amazon Cloud WatchYou can configure collecting Amazon CloudWatch logs and data using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):You can configure collecting Amazon CloudWatch logs and data using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):Amazon CloudWatch vendor│DescriptionCollection Method│Description| ---------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ---------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Standard data source overview│Forward generic and Elastic Kubernetes Service (EKS) logs to Cortex XSIAM from Amazon CloudWatch using the Amazon CloudWatch data source.Standard data source overview│Forward generic and Elastic Kubernetes Service (EKS) logs to Cortex XSIAM from Amazon CloudWatch using the Amazon CloudWatch data source.Link to standard data source instructions│The following types of data can be ingested from Amazon CloudWatch:- Generic logs of the raw data or in a JSON format from Amazon Kinesis Firehose
- EKS logs are automatically ingested in a JSON format from Amazon Kinesis Firehose
For more information, see Ingest logs from Amazon CloudWatch.
Link to standard data source instructions│The following types of data can be ingested from Amazon CloudWatch:- Generic logs of the raw data or in a JSON format from Amazon Kinesis Firehose
- EKS logs are automatically ingested in a JSON format from Amazon Kinesis Firehose
For more information, see Ingest logs from Amazon CloudWatch.
Links to content pack/integration details (onboarded prior to July 26, 2026)│The AWS - CloudWatchLogs content pack facilitates interaction with the Amazon Web Services CloudWatch Logs service. It contains the following integration:- AWS - CloudWatchLogs: Use this integration to monitor, store, and access your log files from AWS Elastic Compute Cloud (Amazon EC2) instances, AWS CloudTrail, AWS Route 53, and other sources. You can then retrieve the associated log data from CloudWatch Logs. It contains commands for managing log streams and log groups, including creating, deleting, filtering, and describing log streams and log groups.
For detailed instructions about setting up authentication, see AWS Integrations - Authentication.
Links to content pack/integration details (onboarded prior to July 26, 2026)│The AWS - CloudWatchLogs content pack facilitates interaction with the Amazon Web Services CloudWatch Logs service. It contains the following integration:- AWS - CloudWatchLogs: Use this integration to monitor, store, and access your log files from AWS Elastic Compute Cloud (Amazon EC2) instances, AWS CloudTrail, AWS Route 53, and other sources. You can then retrieve the associated log data from CloudWatch Logs. It contains commands for managing log streams and log groups, including creating, deleting, filtering, and describing log streams and log groups.
For detailed instructions about setting up authentication, see AWS Integrations - Authentication.
Link to connector (onboarded after July 26, 2026)│AWS Automation and CollectionLink to connector (onboarded after July 26, 2026)│AWS Automation and CollectionShow markdown source
@@ -1,10 +1,10 @@ # Amazon Cloud Watch You can configure collecting Amazon CloudWatch logs and data using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026): -| Amazon CloudWatch vendor | Description | +| Collection Method | Description | | ---------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Standard data source overview | Forward generic and Elastic Kubernetes Service (EKS) logs to Cortex XSIAM from Amazon CloudWatch using the Amazon CloudWatch data source. | | Link to standard data source instructions | <p>The following types of data can be ingested from Amazon CloudWatch:</p><ul><li>Generic logs of the raw data or in a JSON format from Amazon Kinesis Firehose</li><li>EKS logs are automatically ingested in a JSON format from Amazon Kinesis Firehose</li></ul><p>For more information, see <a href="amazon-cloud-watch/ingest-logs-from-amazon-cloudwatch">Ingest logs from Amazon CloudWatch</a>.</p> | | Links to content pack/integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/AWSCloudWatchLogs">AWS - CloudWatchLogs</a> content pack facilitates interaction with the Amazon Web Services CloudWatch Logs service. It contains the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/aws---cloud-watch-logs">AWS - CloudWatchLogs</a>: Use this integration to monitor, store, and access your log files from AWS Elastic Compute Cloud (Amazon EC2) instances, AWS CloudTrail, AWS Route 53, and other sources. You can then retrieve the associated log data from CloudWatch Logs. It contains commands for managing log streams and log groups, including creating, deleting, filtering, and describing log streams and log groups.</li></ul><p>For detailed instructions about setting up authentication, see <a href="https://xsoar.pan.dev/docs/reference/articles/aws-integrations---authentication">AWS Integrations - Authentication</a>.</p> | | Link to connector (onboarded after July 26, 2026) | [AWS Automation and Collection](aws-automation-and-collection) |
-
▸ ▾ Amazon S3 modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-s3Read it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@# Amazon S3# Amazon S3You can configure collecting Amazon S3 logs using a standard using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):You can configure collecting Amazon S3 logs using a standard using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):Amazon S3 vendor│DescriptionCollection Method│Description| ---------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ || ---------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |Standard data source overview│Forward different types of logs to Cortex XSIAM from Amazon Simple Storage Service (Amazon S3) using the Amazon S3 data source.Standard data source overview│Forward different types of logs to Cortex XSIAM from Amazon Simple Storage Service (Amazon S3) using the Amazon S3 data source.Links to standard data source instructions│The following types of logs can be ingested from Amazon S3:
- Audit logs: See Ingest audit logs from AWS Cloud Trail
- Flow logs: See Ingest network flow logs from Amazon S3
Generic logs: See Ingest generic logs from Amazon S3
- BeyondTust Privilege Management Cloud logs: See BeyondTrust Privilege Management Cloud
- Route 53 logs: See Ingest network Route 53 logs from Amazon S3
Configuring these types of Amazon S3 logs can include following these instructions:
Links to standard data source instructions│The following types of logs can be ingested from Amazon S3:
- Audit logs: See Ingest audit logs from AWS Cloud Trail
- Flow logs: See Ingest network flow logs from Amazon S3
Generic logs: See Ingest generic logs from Amazon S3
- BeyondTust Privilege Management Cloud logs: See BeyondTrust Privilege Management Cloud
- Route 53 logs: See Ingest network Route 53 logs from Amazon S3
Configuring these types of Amazon S3 logs can include following these instructions:
Links to content pack/integration details (onboarded prior to July 26, 2026)│The AWS - S3 content pack provides integration with the Amazon Web Services Simple Storage Service (S3) for management, security controls, and visibility of stored objects. It includes the following integration:
- AWS - S3: Use this integration to manage Amazon Web Services Simple Storage Service (S3) objects and security configurations, including listing contents, setting encryption, and blocking public access. Commands are included for fetching bucket encryption status (
aws-s3-get-bucket-encryption), controlling public access settings (aws-s3-put-public-access-block,aws-s3-get-public-access-block), and listing objects within a bucket, with support for pagination, delimiters, and prefixes (aws-s3-list-objects), alongside core support for authentication using AWS STS session tokens.
- AWS - S3: Use this integration to manage Amazon Web Services Simple Storage Service (S3) objects and security configurations, including listing contents, setting encryption, and blocking public access. Commands are included for fetching bucket encryption status (
The AWS - Route53 content pack provides an interface to manage the Amazon Web Services managed Cloud DNS service. It includes the following integration:
- AWS - Route53: Use this integration to manage the Amazon Web Services managed Cloud DNS service. Commands included allow users to list resource record sets, address issues such as when a set is missing its TTL value, and manage configurations related to AWS authentication like STS endpoint resolution logic.
The AWS - CloudTrail content pack provides functionality for interacting with an AWS CloudTrail trail via automation and includes rules for parsing and modeling ingested audit logs. It also includes the following integration:
- AWS - CloudTrail: Use this integration to interact with a CloudTrail trail on AWS via playbooks and the Playground. It includes commands that enable retrieving information about the trail status using
aws-cloudtrail-get-trail-status, and manage authentication configurations like specifying the AWS STS endpoint resolution logic.
- AWS - CloudTrail: Use this integration to interact with a CloudTrail trail on AWS via playbooks and the Playground. It includes commands that enable retrieving information about the trail status using
Links to content pack/integration details (onboarded prior to July 26, 2026)│The AWS - S3 content pack provides integration with the Amazon Web Services Simple Storage Service (S3) for management, security controls, and visibility of stored objects. It includes the following integration:
- AWS - S3: Use this integration to manage Amazon Web Services Simple Storage Service (S3) objects and security configurations, including listing contents, setting encryption, and blocking public access. Commands are included for fetching bucket encryption status (
aws-s3-get-bucket-encryption), controlling public access settings (aws-s3-put-public-access-block,aws-s3-get-public-access-block), and listing objects within a bucket, with support for pagination, delimiters, and prefixes (aws-s3-list-objects), alongside core support for authentication using AWS STS session tokens.
- AWS - S3: Use this integration to manage Amazon Web Services Simple Storage Service (S3) objects and security configurations, including listing contents, setting encryption, and blocking public access. Commands are included for fetching bucket encryption status (
The AWS - Route53 content pack provides an interface to manage the Amazon Web Services managed Cloud DNS service. It includes the following integration:
- AWS - Route53: Use this integration to manage the Amazon Web Services managed Cloud DNS service. Commands included allow users to list resource record sets, address issues such as when a set is missing its TTL value, and manage configurations related to AWS authentication like STS endpoint resolution logic.
The AWS - CloudTrail content pack provides functionality for interacting with an AWS CloudTrail trail via automation and includes rules for parsing and modeling ingested audit logs. It also includes the following integration:
- AWS - CloudTrail: Use this integration to interact with a CloudTrail trail on AWS via playbooks and the Playground. It includes commands that enable retrieving information about the trail status using
aws-cloudtrail-get-trail-status, and manage authentication configurations like specifying the AWS STS endpoint resolution logic.
- AWS - CloudTrail: Use this integration to interact with a CloudTrail trail on AWS via playbooks and the Playground. It includes commands that enable retrieving information about the trail status using
Link to connector (onboarded after July 26, 2026)│AWS Automation and CollectionLink to connector (onboarded after July 26, 2026)│AWS Automation and CollectionShow markdown source
@@ -1,10 +1,10 @@ # Amazon S3 You can configure collecting Amazon S3 logs using a standard using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026): -| Amazon S3 vendor | Description | +| Collection Method | Description | | ---------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | Standard data source overview | Forward different types of logs to Cortex XSIAM from Amazon Simple Storage Service (Amazon S3) using the Amazon S3 data source. | | Links to standard data source instructions | <p>The following types of logs can be ingested from Amazon S3:</p><ul><li><strong>Audit logs</strong>: See <a href="amazon-s3/ingest-audit-logs-from-aws-cloudtrail">Ingest audit logs from AWS Cloud Trail</a></li><li><strong>Flow logs</strong>: See <a href="amazon-s3/ingest-network-flow-logs-from-amazon-s3">Ingest network flow logs from Amazon S3</a></li><li><p><strong>Generic logs</strong>: See <a href="amazon-s3/ingest-generic-logs-from-amazon-s3">Ingest generic logs from Amazon S3</a></p><ul><li><strong>BeyondTust Privilege Management Cloud logs</strong>: See <a href="../beyondtrust/beyondtrust-privilege-management-cloud">BeyondTrust Privilege Management Cloud</a></li></ul></li><li><strong>Route 53 logs</strong>: See <a href="amazon-s3/ingest-network-route-53-logs-from-amazon-s3">Ingest network Route 53 logs from Amazon S3</a></li></ul><p>Configuring these types of Amazon S3 logs can include following these instructions:</p><ul><li><a href="amazon-s3/create-an-assumed-role">Create an assumed role</a></li><li><a href="amazon-s3/configure-data-collection-from-amazon-s3-manually">Configure data collection from Amazon S3 manually</a></li></ul> | | Links to content pack/integration details (onboarded prior to July 26, 2026) | <p></p><ul><li><p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/AWSS3">AWS - S3</a> content pack provides integration with the Amazon Web Services Simple Storage Service (S3) for management, security controls, and visibility of stored objects. It includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/aws---s3">AWS - S3</a>: Use this integration to manage Amazon Web Services Simple Storage Service (S3) objects and security configurations, including listing contents, setting encryption, and blocking public access. Commands are included for fetching bucket encryption status (<strong><code>aws-s3-get-bucket-encryption</code></strong>), controlling public access settings (<strong><code>aws-s3-put-public-access-block</code></strong>, <strong><code>aws-s3-get-public-access-block</code></strong>), and listing objects within a bucket, with support for pagination, delimiters, and prefixes (<strong><code>aws-s3-list-objects</code></strong>), alongside core support for authentication using AWS STS session tokens.</li></ul></li><li><p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/AWSRoute53">AWS - Route53</a> content pack provides an interface to manage the Amazon Web Services managed Cloud DNS service. It includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/aws---route53">AWS - Route53</a>: Use this integration to manage the Amazon Web Services managed Cloud DNS service. Commands included allow users to list resource record sets, address issues such as when a set is missing its TTL value, and manage configurations related to AWS authentication like STS endpoint resolution logic.</li></ul></li><li><p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/AWSCloudTrail">AWS - CloudTrail</a> content pack provides functionality for interacting with an AWS CloudTrail trail via automation and includes rules for parsing and modeling ingested audit logs. It also includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/aws---cloud-trail">AWS - CloudTrail</a>: Use this integration to interact with a CloudTrail trail on AWS via playbooks and the Playground. It includes commands that enable retrieving information about the trail status using <strong><code>aws-cloudtrail-get-trail-status</code></strong>, and manage authentication configurations like specifying the AWS STS endpoint resolution logic.</li></ul></li></ul> | | Link to connector (onboarded after July 26, 2026) | [AWS Automation and Collection](aws-automation-and-collection) |
-
▸ ▾ Amazon Web Services modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-web-servicesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,9 +1,9 @@# Amazon Web Services# Amazon Web ServicesYou can onboard your Amazon Web Services (AWS) environment using Cloud Service Provider (CSP) or configure collecting Amazon Web Services logs using a connector (onboarded after July 26, 2026):You can onboard your Amazon Web Services (AWS) environment using Cloud Service Provider (CSP) or configure collecting Amazon Web Services logs using a connector (onboarded after July 26, 2026):Amazon Web Services vendor│DescriptionCollection Method│Description| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- || ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- |Link to full configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XDR Premium license.│Onboard Amazon Web ServicesLink to full configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XDR Premium license.│Onboard Amazon Web ServicesLink to basic configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XSIAM NG SIEM, Cortex XSIAM Enterprise license, and Cortex XSIAM Enterprise+ licenses.│How to onboard Amazon Web ServicesLink to basic configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XSIAM NG SIEM, Cortex XSIAM Enterprise license, and Cortex XSIAM Enterprise+ licenses.│How to onboard Amazon Web ServicesLink to connector (onboarded after July 26, 2026)│AWS Automation and CollectionLink to connector (onboarded after July 26, 2026)│AWS Automation and CollectionShow markdown source
@@ -1,9 +1,9 @@ # Amazon Web Services You can onboard your Amazon Web Services (AWS) environment using Cloud Service Provider (CSP) or configure collecting Amazon Web Services logs using a connector (onboarded after July 26, 2026): -| Amazon Web Services vendor | Description | +| Collection Method | Description | | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- | | Link to full configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XDR Premium license. | [Onboard Amazon Web Services](../../cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/onboard-amazon-web-services) | | Link to basic configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XSIAM NG SIEM, Cortex XSIAM Enterprise license, and Cortex XSIAM Enterprise+ licenses. | [How to onboard Amazon Web Services](../../cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/how-to-onboard-amazon-web-services) | | Link to connector (onboarded after July 26, 2026) | [AWS Automation and Collection](aws-automation-and-collection) |
-
▸ ▾ API Security modified +5 −5
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/api-securityRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,38 +1,38 @@# API Security# API SecurityYou can configure retrieving and collecting API data for further analysis by Cortex's comprehensive API Security capabilities using the following standard data sources:You can configure retrieving and collecting API data for further analysis by Cortex's comprehensive API Security capabilities using the following standard data sources:AWS API Gateway vendorAWS API Gateway vendorAWS API Gateway vendor│DescriptionCollection Method│Description| ----------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- || ----------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- |Standard data source overview│Integrate AWS API Gateway with the Cortex XSIAM AWS API Gateway data source to begin scanning the APIs for potential threats and vulnerabilities.Standard data source overview│Integrate AWS API Gateway with the Cortex XSIAM AWS API Gateway data source to begin scanning the APIs for potential threats and vulnerabilities.Link to standard data source instructions│Ingest AWS API GatewayLink to standard data source instructions│Ingest AWS API GatewayAzure APIM vendorAzure APIM vendorAzure APIM vendor│DescriptionCollection Method│Description| ----------------------------------------- | --------------------------------------------------------------------------------- || ----------------------------------------- | --------------------------------------------------------------------------------- |Standard data source overview│Send HTTP request/response data to Cortex XSIAM using the Azure APIM data source.Standard data source overview│Send HTTP request/response data to Cortex XSIAM using the Azure APIM data source.Link to standard data source instructions│Ingest Azure APIMLink to standard data source instructions│Ingest Azure APIMF5 vendorF5 vendorF5 vendor│DescriptionCollection Method│Description| ----------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ----------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Standard data source overview│Integrate a dedicated F5 log plugin to enable seamless traffic ingestion from your F5 Gateway to Cortex XSIAM, allowing for comprehensive security measures, such as OWASP Top-10, bot detection, access control, and more.Standard data source overview│Integrate a dedicated F5 log plugin to enable seamless traffic ingestion from your F5 Gateway to Cortex XSIAM, allowing for comprehensive security measures, such as OWASP Top-10, bot detection, access control, and more.Link to standard data source instructions│Ingest-F5Link to standard data source instructions│Ingest-F5GCP Apigee Proxy vendorGCP Apigee Proxy vendorGCP Apigee Proxy vendor│DescriptionCollection Method│Description| ----------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- || ----------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- |Standard data source overview│Integrate Apigee Proxy with Cortex XSIAM to begin scanning the APIs for potential threats and vulnerabilities using the Apigee’s JavaScript (JS) policy.Standard data source overview│Integrate Apigee Proxy with Cortex XSIAM to begin scanning the APIs for potential threats and vulnerabilities using the Apigee’s JavaScript (JS) policy.Link to standard data source instructions│Ingest Apigee ProxyLink to standard data source instructions│Ingest Apigee ProxyKong vendorKong vendorKong vendor│DescriptionCollection Method│Description| ----------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ----------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Standard data source overview│Integrate a dedicated Kong HTTP log plugin to enable seamless traffic ingestion from your Kong API gateway to Cortex XSIAM, allowing for comprehensive security measures, such as OWASP Top-10, bot detection, access control, and more.Standard data source overview│Integrate a dedicated Kong HTTP log plugin to enable seamless traffic ingestion from your Kong API gateway to Cortex XSIAM, allowing for comprehensive security measures, such as OWASP Top-10, bot detection, access control, and more.Link to standard data source instructions│Ingest KongLink to standard data source instructions│Ingest KongShow markdown source
@@ -1,38 +1,38 @@ # API Security You can configure retrieving and collecting API data for further analysis by Cortex's comprehensive API Security capabilities using the following standard data sources: AWS API Gateway vendor -| AWS API Gateway vendor | Description | +| Collection Method | Description | | ----------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | | Standard data source overview | Integrate AWS API Gateway with the Cortex XSIAM AWS API Gateway data source to begin scanning the APIs for potential threats and vulnerabilities. | | Link to standard data source instructions | [Ingest AWS API Gateway](api-security/ingest-data-for-api-security/ingest-aws-api-gateway) | Azure APIM vendor -| Azure APIM vendor | Description | +| Collection Method | Description | | ----------------------------------------- | --------------------------------------------------------------------------------- | | Standard data source overview | Send HTTP request/response data to Cortex XSIAM using the Azure APIM data source. | | Link to standard data source instructions | [Ingest Azure APIM](api-security/ingest-data-for-api-security/ingest-azure-apim) | F5 vendor -| F5 vendor | Description | +| Collection Method | Description | | ----------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Standard data source overview | Integrate a dedicated F5 log plugin to enable seamless traffic ingestion from your F5 Gateway to Cortex XSIAM, allowing for comprehensive security measures, such as OWASP Top-10, bot detection, access control, and more. | | Link to standard data source instructions | [Ingest-F5](api-security/ingest-data-for-api-security/ingest-f5) | GCP Apigee Proxy vendor -| GCP Apigee Proxy vendor | Description | +| Collection Method | Description | | ----------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- | | Standard data source overview | Integrate Apigee Proxy with Cortex XSIAM to begin scanning the APIs for potential threats and vulnerabilities using the Apigee’s JavaScript (JS) policy. | | Link to standard data source instructions | [Ingest Apigee Proxy](api-security/ingest-data-for-api-security/ingest-apigee-proxy) | Kong vendor -| Kong vendor | Description | +| Collection Method | Description | | ----------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Standard data source overview | Integrate a dedicated Kong HTTP log plugin to enable seamless traffic ingestion from your Kong API gateway to Cortex XSIAM, allowing for comprehensive security measures, such as OWASP Top-10, bot detection, access control, and more. | | Link to standard data source instructions | [Ingest Kong](api-security/ingest-data-for-api-security/ingest-kong) |
-
▸ ▾ BeyondTrust Privilege Management Cloud modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/beyondtrust/beyondtrust-privilege-management-cloudRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@# BeyondTrust Privilege Management Cloud# BeyondTrust Privilege Management CloudYou can configure collecting BeyondTrust Privilege Management Cloud logs using a standard data source or connector (onboarded after July 26, 2026):You can configure collecting BeyondTrust Privilege Management Cloud logs using a standard data source or connector (onboarded after July 26, 2026):BeyondTrust Privilege Management Cloud vendor│DescriptionCollection Method│Description| ------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Standard data source overview│Forward logs to Cortex XSIAM from BeyondTrust Privilege Management Cloud using an Amazon S3 data source for a generic log type using the Beyondtrust Cloud ECS log format.Standard data source overview│Forward logs to Cortex XSIAM from BeyondTrust Privilege Management Cloud using an Amazon S3 data source for a generic log type using the Beyondtrust Cloud ECS log format.Link to standard data source instructions│Ingest logs from BeyondTrust Privilege Management CloudLink to standard data source instructions│Ingest logs from BeyondTrust Privilege Management CloudLink to connector (onboarded after July 26, 2026)│BeyondTrustLink to connector (onboarded after July 26, 2026)│BeyondTrustShow markdown source
@@ -1,10 +1,10 @@ # BeyondTrust Privilege Management Cloud You can configure collecting BeyondTrust Privilege Management Cloud logs using a standard data source or connector (onboarded after July 26, 2026): -| BeyondTrust Privilege Management Cloud vendor | Description | +| Collection Method | Description | | ------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Standard data source overview | Forward logs to Cortex XSIAM from BeyondTrust Privilege Management Cloud using an Amazon S3 data source for a generic log type using the Beyondtrust Cloud ECS log format. | | Link to standard data source instructions | [Ingest logs from BeyondTrust Privilege Management Cloud](beyondtrust-privilege-management-cloud/ingest-logs-from-beyondtrust-privilege-management-cloud) | | Link to connector (onboarded after July 26, 2026) | [BeyondTrust](beyondtrust) |
-
▸ ▾ Box modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/boxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@# Box# BoxYou can configure collecting Box logs and data using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connectors:You can configure collecting Box logs and data using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connectors:Box vendor│DescriptionCollection Method│Description| ---------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ---------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Standard data source overview│Forward different types of data from Box enterprise accounts to Cortex XSIAM using the Box data source.Standard data source overview│Forward different types of data from Box enterprise accounts to Cortex XSIAM using the Box data source.Link to standard data source instructions│The following types of data can be ingested from Dropbox:Events and security alerts
- Events (admin_logs)
- Box Shield Alerts
Directory and metadata
- Users
- Groups
For more information, see Ingest logs and data from Box.
Link to standard data source instructions│The following types of data can be ingested from Dropbox:Events and security alerts
- Events (admin_logs)
- Box Shield Alerts
Directory and metadata
- Users
- Groups
For more information, see Ingest logs and data from Box.
Links to content pack integration details (onboarded prior to July 26, 2026)│The Box content pack contains classifiers, issue fields and types, and parsing and modeling rules to normalize Box data in Cortex XSIAM. It also includes the following integrations:
- Box Event Collector: Use this integration to collect events from Box's logs. It includes a command to get Box events.
- Box V2: Use this integration to manage Box users. It includes commands to search Box content and manage file folders and share links.
Links to content pack integration details (onboarded prior to July 26, 2026)│The Box content pack contains classifiers, issue fields and types, and parsing and modeling rules to normalize Box data in Cortex XSIAM. It also includes the following integrations:
- Box Event Collector: Use this integration to collect events from Box's logs. It includes a command to get Box events.
- Box V2: Use this integration to manage Box users. It includes commands to search Box content and manage file folders and share links.
Link to connectors│- Box Automation and Collection (onboarded after July 26, 2026)
- Box
Link to connectors│- Box Automation and Collection (onboarded after July 26, 2026)
- Box
Show markdown source
@@ -1,10 +1,10 @@ # Box You can configure collecting Box logs and data using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connectors: -| Box vendor | Description | +| Collection Method | Description | | ---------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Standard data source overview | Forward different types of data from Box enterprise accounts to Cortex XSIAM using the Box data source. | | Link to standard data source instructions | <p>The following types of data can be ingested from Dropbox:</p><ul><li><p>Events and security alerts</p><ul><li>Events (admin_logs)</li><li>Box Shield Alerts</li></ul></li><li><p>Directory and metadata</p><ul><li>Users</li><li>Groups</li></ul></li></ul><p>For more information, see <a href="box/ingest-logs-and-data-from-box">Ingest logs and data from Box</a>.</p> | | Links to content pack integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/Box">Box </a>content pack contains classifiers, issue fields and types, and parsing and modeling rules to normalize Box data in Cortex XSIAM. It also includes the following integrations:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/box-events-collector">Box Event Collector</a>: Use this integration to collect events from Box's logs. It includes a command to get Box events.</li><li><a href="https://xsoar.pan.dev/docs/reference/integrations/box-v2">Box V2</a>: Use this integration to manage Box users. It includes commands to search Box content and manage file folders and share links.</li></ul> | | Link to connectors | <ul><li><a href="box/box-automation-and-collection">Box Automation and Collection</a> (onboarded after July 26, 2026)</li><li><a href="box/box">Box</a></li></ul> |
-
▸ ▾ Check Point FW1/VPN1 modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/check-point/check-point-fw1-vpn1Read it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@# Check Point FW1/VPN1# Check Point FW1/VPN1You can configure collecting Check Point FW1/VPN1 logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):You can configure collecting Check Point FW1/VPN1 logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):Check Point FW1/VPN1 vendor│DescriptionCollection Method│Description| --------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || --------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Syslog Collector applet overview│If you use Check Point FW1/VPN1 firewalls, you can forward Check Point firewall logs to Cortex XSIAM using the Broker VM Syslog Collector applet in a CEF format.Syslog Collector applet overview│If you use Check Point FW1/VPN1 firewalls, you can forward Check Point firewall logs to Cortex XSIAM using the Broker VM Syslog Collector applet in a CEF format.Link to Syslog Collector applet instructions│Ingest logs from Check Point firewallsLink to Syslog Collector applet instructions│Ingest logs from Check Point firewallsLink to content pack/integration details (onboarded prior to July 26, 2026)│The Check Point Firewall content pack manages Check Point firewall devices via API, allowing the reading information, sending commands, and orchestrating configuration and blocking actions. It contains a modeling rule (
CheckPoint Firewall Collection) and several playbooks (for example Checkpoint - Block IP - Append Group, Checkpoint - Publish&Install configuration, Checkpoint - Block IP - Custom Block Rule, and Checkpoint - Block URL). It also includes the following integration:- CheckPoint Firewall v2: Use this integration to read information and send commands to the Check Point Firewall server. It includes commands for handling threat protection and profiles, such as
checkpoint-set-threat-protectionandcheckpoint-add-threat-profile.
Link to content pack/integration details (onboarded prior to July 26, 2026)│The Check Point Firewall content pack manages Check Point firewall devices via API, allowing the reading information, sending commands, and orchestrating configuration and blocking actions. It contains a modeling rule (
CheckPoint Firewall Collection) and several playbooks (for example Checkpoint - Block IP - Append Group, Checkpoint - Publish&Install configuration, Checkpoint - Block IP - Custom Block Rule, and Checkpoint - Block URL). It also includes the following integration:- CheckPoint Firewall v2: Use this integration to read information and send commands to the Check Point Firewall server. It includes commands for handling threat protection and profiles, such as
checkpoint-set-threat-protectionandcheckpoint-add-threat-profile.
Link to connector (onboarded after July 26, 2026)│Checkpoint FirewallLink to connector (onboarded after July 26, 2026)│Checkpoint FirewallShow markdown source
@@ -1,10 +1,10 @@ # Check Point FW1/VPN1 You can configure collecting Check Point FW1/VPN1 logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026): -| Check Point FW1/VPN1 vendor | Description | +| Collection Method | Description | | --------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Syslog Collector applet overview | If you use Check Point FW1/VPN1 firewalls, you can forward Check Point firewall logs to Cortex XSIAM using the Broker VM Syslog Collector applet in a CEF format. | | Link to Syslog Collector applet instructions | [Ingest logs from Check Point firewalls](../../generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/check-point-fw1-vpn1/ingest-logs-from-check-point-firewalls) | | Link to content pack/integration details (onboarded prior to July 26, 2026) | <p></p><p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/CheckpointFirewall/">Check Point Firewall</a> content pack manages Check Point firewall devices via API, allowing the reading information, sending commands, and orchestrating configuration and blocking actions. It contains a modeling rule (<strong><code>CheckPoint Firewall Collection</code></strong>) and several playbooks (for example Checkpoint - Block IP - Append Group, Checkpoint - Publish&Install configuration, Checkpoint - Block IP - Custom Block Rule, and Checkpoint - Block URL). It also includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/check-point-firewall-v2">CheckPoint Firewall v2</a>: Use this integration to read information and send commands to the Check Point Firewall server. It includes commands for handling threat protection and profiles, such as <strong><code>checkpoint-set-threat-protection</code></strong> and <strong><code>checkpoint-add-threat-profile</code></strong>.</li></ul> | | Link to connector (onboarded after July 26, 2026) | [Checkpoint Firewall](checkpoint-firewall) |
- CheckPoint Firewall v2: Use this integration to read information and send commands to the Check Point Firewall server. It includes commands for handling threat protection and profiles, such as
-
▸ ▾ Cisco ASA firewalls and AnyConnect` modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-asa-firewalls-and-anyconnectRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,12 +1,12 @@# Cisco ASA firewalls and AnyConnect`# Cisco ASA firewalls and AnyConnect`You can configure collecting Cisco ASA firewall and AnyConnect VPN logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):You can configure collecting Cisco ASA firewall and AnyConnect VPN logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):Cisco ASA firewalls and AnyConnect vendor│DescriptionCollection Method│Description| -------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || -------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Syslog Collector applet overview│If you use Cisco ASA firewalls or Cisco AnyConnect VPN, you can forward Cisco ASA firewall and AnyConnect VPN logs to Cortex XSIAM using the Broker VM Syslog Collector applet in a CISCO format.Syslog Collector applet overview│If you use Cisco ASA firewalls or Cisco AnyConnect VPN, you can forward Cisco ASA firewall and AnyConnect VPN logs to Cortex XSIAM using the Broker VM Syslog Collector applet in a CISCO format.Link to Syslog Collector applet instructions│Ingest logs from Cisco ASA firewalls and AnyConnectLink to Syslog Collector applet instructions│Ingest logs from Cisco ASA firewalls and AnyConnectLink to content pack/integration instructions (onboarded prior to July 26, 2026)│The Cisco ASA content pack interacts with the Cisco Adaptive Security Appliance Software via an API to manage interfaces, rules, and network objects. The content pack includes the following integration:
- Cisco Adaptive Security Appliance Software: Use this integration to manage interfaces, rules, and network objects on the Cisco Adaptive Security Appliance Software platform. This integration includes commands for listing and managing network object groups, local user groups, local users, time ranges, security object groups, user objects, interface information, configuration backup, and creating, listing, getting, editing, and deleting firewall rules, along with the command to save the running configuration to memory (
cisco-asa-write-memory).
Link to content pack/integration instructions (onboarded prior to July 26, 2026)│The Cisco ASA content pack interacts with the Cisco Adaptive Security Appliance Software via an API to manage interfaces, rules, and network objects. The content pack includes the following integration:
- Cisco Adaptive Security Appliance Software: Use this integration to manage interfaces, rules, and network objects on the Cisco Adaptive Security Appliance Software platform. This integration includes commands for listing and managing network object groups, local user groups, local users, time ranges, security object groups, user objects, interface information, configuration backup, and creating, listing, getting, editing, and deleting firewall rules, along with the command to save the running configuration to memory (
cisco-asa-write-memory).
Link to connector (onboarded after July 26, 2026)│Cisco ASALink to connector (onboarded after July 26, 2026)│Cisco ASAShow markdown source
@@ -1,12 +1,12 @@ # Cisco ASA firewalls and AnyConnect\` You can configure collecting Cisco ASA firewall and AnyConnect VPN logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026): -| Cisco ASA firewalls and AnyConnect vendor | Description | +| Collection Method | Description | | -------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Syslog Collector applet overview | If you use Cisco ASA firewalls or Cisco AnyConnect VPN, you can forward Cisco ASA firewall and AnyConnect VPN logs to Cortex XSIAM using the Broker VM Syslog Collector applet in a CISCO format. | | Link to Syslog Collector applet instructions | [Ingest logs from Cisco ASA firewalls and AnyConnect](../../generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/cisco-asa-firewalls-and-anyconnect/ingest-logs-from-cisco-asa-firewalls-and-anyconnect) | | Link to content pack/integration instructions (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/CiscoASA/">Cisco ASA</a> content pack interacts with the Cisco Adaptive Security Appliance Software via an API to manage interfaces, rules, and network objects. The content pack includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/cisco-asa">Cisco Adaptive Security Appliance Software</a>: Use this integration to manage interfaces, rules, and network objects on the Cisco Adaptive Security Appliance Software platform. This integration includes commands for listing and managing network object groups, local user groups, local users, time ranges, security object groups, user objects, interface information, configuration backup, and creating, listing, getting, editing, and deleting firewall rules, along with the command to save the running configuration to memory (<strong><code>cisco-asa-write-memory</code></strong>).</li></ul> | | Link to connector (onboarded after July 26, 2026) | [Cisco ASA](cisco-asa) |
- Cisco Adaptive Security Appliance Software: Use this integration to manage interfaces, rules, and network objects on the Cisco Adaptive Security Appliance Software platform. This integration includes commands for listing and managing network object groups, local user groups, local users, time ranges, security object groups, user objects, interface information, configuration backup, and creating, listing, getting, editing, and deleting firewall rules, along with the command to save the running configuration to memory (
-
▸ ▾ Corelight Zeek modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/corelight/corelight-zeekRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@# Corelight Zeek# Corelight ZeekYou can configure collecting Corelight Zeek logs using a Broker VM Syslog Collector applet or content pack integration (onboarded prior to July 26, 2026):You can configure collecting Corelight Zeek logs using a Broker VM Syslog Collector applet or content pack integration (onboarded prior to July 26, 2026):Corelight Zeek vendor│DescriptionCollection Method│Description| --------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || --------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Syslog Collector applet overview│If you use Corelight Zeek sensors for network monitoring, you can forward network connection logs to Cortex XSIAM using the Broker VM Syslog Collector applet with TCP as the transport Protocol and a Corelight format.Syslog Collector applet overview│If you use Corelight Zeek sensors for network monitoring, you can forward network connection logs to Cortex XSIAM using the Broker VM Syslog Collector applet with TCP as the transport Protocol and a Corelight format.Link to Syslog Collector applet instructions│Ingest logs from Corelight ZeekLink to Syslog Collector applet instructions│Ingest logs from Corelight ZeekLink to content pack/integration details (onboarded prior to July 26, 2026)│The Corelight Zeek content pack provides data normalization capabilities through rules for parsing and modeling network protocol logs that are ingested via a Syslog collector on the Broker VM into Cortex XSIAM. It includesCorelight Zeek Modeling RulesandCorelight Zeek Parsing Rules.Link to content pack/integration details (onboarded prior to July 26, 2026)│The Corelight Zeek content pack provides data normalization capabilities through rules for parsing and modeling network protocol logs that are ingested via a Syslog collector on the Broker VM into Cortex XSIAM. It includesCorelight Zeek Modeling RulesandCorelight Zeek Parsing Rules.Show markdown source
@@ -1,10 +1,10 @@ # Corelight Zeek You can configure collecting Corelight Zeek logs using a Broker VM Syslog Collector applet or content pack integration (onboarded prior to July 26, 2026): -| Corelight Zeek vendor | Description | +| Collection Method | Description | | --------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Syslog Collector applet overview | If you use Corelight Zeek sensors for network monitoring, you can forward network connection logs to Cortex XSIAM using the Broker VM Syslog Collector applet with TCP as the transport Protocol and a Corelight format. | | Link to Syslog Collector applet instructions | [Ingest logs from Corelight Zeek](../../generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/corelight-zeek/ingest-logs-from-corelight-zeek) | | Link to content pack/integration details (onboarded prior to July 26, 2026) | The [Corelight Zeek](https://cortex.marketplace.pan.dev/marketplace/details/CorelightZeek) content pack provides data normalization capabilities through rules for parsing and modeling network protocol logs that are ingested via a Syslog collector on the Broker VM into Cortex XSIAM. It includes **`Corelight Zeek Modeling Rules`** and **`Corelight Zeek Parsing Rules`**. |
-
▸ ▾ Crowdstrike APIs modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/crowdstrike/crowdstrike-apisRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,8 @@# Crowdstrike APIs# Crowdstrike APIsYou can configure collecting CrowdStrike API real-time alerts and logs using a standard collector:You can configure collecting CrowdStrike API real-time alerts and logs using a standard collector:CrowdStrike vendor│DescriptionCollection Method│Description| --------------------------------------- | --------------------------------------------------------------------------------------------------------------------- || --------------------------------------- | --------------------------------------------------------------------------------------------------------------------- |Standard collector overview│Forward CrowdStrike API real-time alerts and logs to Cortex XSIAM using the CrowdStrike Platform data source.Standard collector overview│Forward CrowdStrike API real-time alerts and logs to Cortex XSIAM using the CrowdStrike Platform data source.Link to standard collector instructions│Ingest alerts and metadata from CrowdStrike APIsLink to standard collector instructions│Ingest alerts and metadata from CrowdStrike APIsShow markdown source
@@ -1,8 +1,8 @@ # Crowdstrike APIs You can configure collecting CrowdStrike API real-time alerts and logs using a standard collector: -| CrowdStrike vendor | Description | +| Collection Method | Description | | --------------------------------------- | --------------------------------------------------------------------------------------------------------------------- | | Standard collector overview | Forward CrowdStrike API real-time alerts and logs to Cortex XSIAM using the CrowdStrike Platform data source. | | Link to standard collector instructions | [Ingest alerts and metadata from CrowdStrike APIs](crowdstrike-apis/ingest-alerts-and-metadata-from-crowdstrike-apis) |
-
▸ ▾ CrowdStrike Falcon Data Replicator modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/crowdstrike/crowdstrike-falcon-data-replicatorRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@# CrowdStrike Falcon Data Replicator# CrowdStrike Falcon Data ReplicatorYou can configure collecting raw EDR event data from CrowdStrike Falcon Data Replicator (FDR) using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):You can configure collecting raw EDR event data from CrowdStrike Falcon Data Replicator (FDR) using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):CrowdStrike Falcon Data Replicator vendor│DescriptionCollection Method│Description| ---------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ || ---------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |Standard collector overview│Forward raw EDR event data from CrowdStrike Falcon Data Replicator (FDR), streamed to Amazon S3, and Cortex XSIAM using the CrowdStrike Falcon Data Replicator data source. In addition to all standard SIEM capabilities, this integration unlocks some advanced Cortex XSIAM features, enabling comprehensive analysis of data from all sources, enhanced detection and response, and deeper visibility into CrowdStrike FDR data.Standard collector overview│Forward raw EDR event data from CrowdStrike Falcon Data Replicator (FDR), streamed to Amazon S3, and Cortex XSIAM using the CrowdStrike Falcon Data Replicator data source. In addition to all standard SIEM capabilities, this integration unlocks some advanced Cortex XSIAM features, enabling comprehensive analysis of data from all sources, enhanced detection and response, and deeper visibility into CrowdStrike FDR data.Link to standard collector instructions│Ingest raw EDR events from CrowdStrike Falcon Data ReplicatorLink to standard collector instructions│Ingest raw EDR events from CrowdStrike Falcon Data ReplicatorLinks to content pack integration details (onboarded prior to July 26, 2026)│The CrowdStrike Falcon content pack contains automations to load the CrowdStrike process file content and transform the data . It also includes the following integration:
- CrowdStrike Falcon: Use this integration to perform endpoint security operations such as fetching and resolving detections, searching devices, getting behaviors by ID, containing hosts, and lifting host containment. It includes commands for immediate actions, including searching devices, resolving detections, running remote commands on hosts, and managing custom Indicators of Compromise (IOCs).
Links to content pack integration details (onboarded prior to July 26, 2026)│The CrowdStrike Falcon content pack contains automations to load the CrowdStrike process file content and transform the data . It also includes the following integration:
- CrowdStrike Falcon: Use this integration to perform endpoint security operations such as fetching and resolving detections, searching devices, getting behaviors by ID, containing hosts, and lifting host containment. It includes commands for immediate actions, including searching devices, resolving detections, running remote commands on hosts, and managing custom Indicators of Compromise (IOCs).
Link to connector (onboarded after July 26, 2026)│CrowdStrikeLink to connector (onboarded after July 26, 2026)│CrowdStrikeShow markdown source
@@ -1,10 +1,10 @@ # CrowdStrike Falcon Data Replicator You can configure collecting raw EDR event data from CrowdStrike Falcon Data Replicator (FDR) using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026): -| CrowdStrike Falcon Data Replicator vendor | Description | +| Collection Method | Description | | ---------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | Standard collector overview | Forward raw EDR event data from CrowdStrike Falcon Data Replicator (FDR), streamed to Amazon S3, and Cortex XSIAM using the CrowdStrike Falcon Data Replicator data source. In addition to all standard SIEM capabilities, this integration unlocks some advanced Cortex XSIAM features, enabling comprehensive analysis of data from all sources, enhanced detection and response, and deeper visibility into CrowdStrike FDR data. | | Link to standard collector instructions | [Ingest raw EDR events from CrowdStrike Falcon Data Replicator](crowdstrike-falcon-data-replicator/ingest-raw-edr-events-from-crowdstrike-falcon-data-replicator) | | Links to content pack integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/CrowdStrikeFalcon">CrowdStrike Falcon</a> content pack contains automations to load the CrowdStrike process file content and transform the data . It also includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/crowdstrike-falcon">CrowdStrike Falcon</a>: Use this integration to perform endpoint security operations such as fetching and resolving detections, searching devices, getting behaviors by ID, containing hosts, and lifting host containment. It includes commands for immediate actions, including searching devices, resolving detections, running remote commands on hosts, and managing custom Indicators of Compromise (IOCs).</li></ul> | | Link to connector (onboarded after July 26, 2026) | [CrowdStrike](crowdstrike) |
-
▸ ▾ Dropbox modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/dropboxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@# Dropbox# DropboxYou can configure collecting Dropbox logs and data using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):You can configure collecting Dropbox logs and data using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):Dropbox vendor│DescriptionCollection Method│Description| ----------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ----------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Standard data source overview│Forward different types of data from Dropbox Business accounts to Cortex XSIAM using the Dropbox data source.Standard data source overview│Forward different types of data from Dropbox Business accounts to Cortex XSIAM using the Dropbox data source.Link to standard data source instructions│The following types of data can be ingested from Dropbox:Log collection
- Events
Directory and metadata
- Member Devices
- Users
- Groups
For more information, see Ingest logs and data from Dropbox.
Link to standard data source instructions│The following types of data can be ingested from Dropbox:Log collection
- Events
Directory and metadata
- Member Devices
- Users
- Groups
For more information, see Ingest logs and data from Dropbox.
Links to content pack/ integration details (onboarded prior to July 26, 2026)│The Dropbox content pack fetches and collects security events from Dropbox logs. It includes Correlation Rules, Modeling Rules, Parsing Rules, a Playbook, and a Cortex XSIAM Dashboard. It also includes the following integration:
- Dropbox Event Collector: Use this integration to collect events from Dropbox logs. It contains commands such as
dropbox-auth-startto initiate the authorization process,dropbox-auth-completeto finish authorization,dropbox-auth-testto check connectivity,dropbox-auth-resetto reset authentication, anddropbox-get-eventsto retrieve events.
Links to content pack/ integration details (onboarded prior to July 26, 2026)│The Dropbox content pack fetches and collects security events from Dropbox logs. It includes Correlation Rules, Modeling Rules, Parsing Rules, a Playbook, and a Cortex XSIAM Dashboard. It also includes the following integration:
- Dropbox Event Collector: Use this integration to collect events from Dropbox logs. It contains commands such as
dropbox-auth-startto initiate the authorization process,dropbox-auth-completeto finish authorization,dropbox-auth-testto check connectivity,dropbox-auth-resetto reset authentication, anddropbox-get-eventsto retrieve events.
Link to connector (onboarded after July 26, 2026)│DropboxLink to connector (onboarded after July 26, 2026)│DropboxShow markdown source
@@ -1,10 +1,10 @@ # Dropbox You can configure collecting Dropbox logs and data using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026): -| Dropbox vendor | Description | +| Collection Method | Description | | ----------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Standard data source overview | Forward different types of data from Dropbox Business accounts to Cortex XSIAM using the Dropbox data source. | | Link to standard data source instructions | <p>The following types of data can be ingested from Dropbox:</p><ul><li><p>Log collection</p><ul><li>Events</li></ul></li><li><p>Directory and metadata</p><ul><li>Member Devices</li><li>Users</li><li>Groups</li></ul></li></ul><p>For more information, see <a href="dropbox/ingest-logs-and-data-from-dropbox">Ingest logs and data from Dropbox</a>.</p> | | Links to content pack/ integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/Dropbox/">Dropbox</a> content pack fetches and collects security events from Dropbox logs. It includes Correlation Rules, Modeling Rules, Parsing Rules, a Playbook, and a Cortex XSIAM Dashboard. It also includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/dropbox-events-collector">Dropbox Event Collector</a>: Use this integration to collect events from Dropbox logs. It contains commands such as <strong><code>dropbox-auth-start</code></strong> to initiate the authorization process, <strong><code>dropbox-auth-complete</code></strong> to finish authorization, <strong><code>dropbox-auth-test</code></strong> to check connectivity, <strong><code>dropbox-auth-reset</code></strong> to reset authentication, and <strong><code>dropbox-get-events</code></strong> to retrieve events.</li></ul> | | Link to connector (onboarded after July 26, 2026) | [Dropbox](dropbox/dropbox) |
-
▸ ▾ Elasticsearch Filebeat modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/elastic/elasticsearch-filebeatRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -3,12 +3,12 @@hint infohint infoNoteNoteYou can configure collecting container logs from Google Kubernetes Engine using Elasticsearch Filebeat with a Custom - Filebeat based Collector or with a content pack Integration. For more information, see Google Kubernetes Engine.You can configure collecting container logs from Google Kubernetes Engine using Elasticsearch Filebeat with a Custom - Filebeat based Collector or with a content pack Integration. For more information, see Google Kubernetes Engine.endhintendhintYou can ingest logs related to file activity on your endpoints and servers without using the Cortex XDR agent by installing Elasticsearch Filebeat as a system logger and then forward those logs to Cortex XSIAM using a Custom - Filebeat based Collector.You can ingest logs related to file activity on your endpoints and servers without using the Cortex XDR agent by installing Elasticsearch Filebeat as a system logger and then forward those logs to Cortex XSIAM using a Custom - Filebeat based Collector.Collection Methods│DescriptionCollection Method│Description| ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------- || ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------- |Custom - Filebeat based Collector (standard data source) overview│Forward logs from Elasticsearch Filebeat to Cortex XSIAM using the Custom - Filebeat based Collector data source.Custom - Filebeat based Collector (standard data source) overview│Forward logs from Elasticsearch Filebeat to Cortex XSIAM using the Custom - Filebeat based Collector data source.Link to custom - Filebeat based Collector (standard data source) instructions│Ingest logs from Elasticsearch FilebeatLink to custom - Filebeat based Collector (standard data source) instructions│Ingest logs from Elasticsearch FilebeatShow markdown source
@@ -3,12 +3,12 @@ {% hint style="info" %} **Note** You can configure collecting container logs from Google Kubernetes Engine using Elasticsearch Filebeat with a Custom - Filebeat based Collector or with a content pack Integration. For more information, see [Google Kubernetes Engine](../google/google-kubernetes-engine). {% endhint %} You can ingest logs related to file activity on your endpoints and servers without using the Cortex XDR agent by installing Elasticsearch Filebeat as a system logger and then forward those logs to Cortex XSIAM using a Custom - Filebeat based Collector. -| Collection Methods | Description | +| Collection Method | Description | | ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------- | | Custom - Filebeat based Collector (standard data source) overview | Forward logs from Elasticsearch Filebeat to Cortex XSIAM using the Custom - Filebeat based Collector data source. | | Link to custom - Filebeat based Collector (standard data source) instructions | [Ingest logs from Elasticsearch Filebeat](elasticsearch-filebeat/ingest-logs-from-elasticsearch-filebeat) | -
▸ ▾ Windows DHCP via Elasticsearch Filebeat modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/elastic/windows-dhcp-via-elasticsearch-filebeatRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@# Windows DHCP via Elasticsearch Filebeat# Windows DHCP via Elasticsearch FilebeatYou can configure collecting Windows DHCP logs using a Standard Collector or content pack integration (onboarded prior to July 26, 2026):You can configure collecting Windows DHCP logs using a Standard Collector or content pack integration (onboarded prior to July 26, 2026):Windows DHCP vendor│DescriptionCollection Method│Description| --------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || --------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Standard Collector (basic) overview│Forward logs to Cortex XDR from Windows DHCP logs using Elasticsearch Filebeat with the Windows DHCP data source.Standard Collector (basic) overview│Forward logs to Cortex XDR from Windows DHCP logs using Elasticsearch Filebeat with the Windows DHCP data source.Link to Standard Collector instructions│Ingest logs from Windows DHCP using Elasticsearch FilebeatLink to Standard Collector instructions│Ingest logs from Windows DHCP using Elasticsearch FilebeatLink to content pack details (onboarded prior to July 26, 2026)│The Microsoft DHCP content pack processes and normalizes audit logs from the Dynamic Host Configuration Protocol (DHCP) service for security analysis in Cortex XSIAM. It includes modeling Rules and parsing rules for events collected using the XDR Collector via themicrosoft_dhcp_raw dataset.Link to content pack details (onboarded prior to July 26, 2026)│The Microsoft DHCP content pack processes and normalizes audit logs from the Dynamic Host Configuration Protocol (DHCP) service for security analysis in Cortex XSIAM. It includes modeling Rules and parsing rules for events collected using the XDR Collector via themicrosoft_dhcp_raw dataset.Show markdown source
@@ -1,10 +1,10 @@ # Windows DHCP via Elasticsearch Filebeat You can configure collecting Windows DHCP logs using a Standard Collector or content pack integration (onboarded prior to July 26, 2026): -| Windows DHCP vendor | Description | +| Collection Method | Description | | --------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Standard Collector (basic) overview | Forward logs to Cortex XDR from Windows DHCP logs using Elasticsearch Filebeat with the Windows DHCP data source. | | Link to Standard Collector instructions | [Ingest logs from Windows DHCP using Elasticsearch Filebeat](windows-dhcp-via-elasticsearch-filebeat/ingest-logs-from-windows-dhcp-using-elasticsearch-filebeat) | | Link to content pack details (onboarded prior to July 26, 2026) | The [Microsoft DHCP](https://cortex.marketplace.pan.dev/marketplace/details/MicrosoftDHCP) content pack processes and normalizes audit logs from the Dynamic Host Configuration Protocol (DHCP) service for security analysis in Cortex XSIAM. It includes modeling Rules and parsing rules for events collected using the XDR Collector via the **`microsoft_dhcp_raw dataset`**. |
-
▸ ▾ Fortinet Fortigate modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/fortinet/fortinet-fortigateRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@# Fortinet Fortigate# Fortinet FortigateYou can configure collecting Fortinet Fortigate firewall logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):You can configure collecting Fortinet Fortigate firewall logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):Fortinet Fortigate vendor│DescriptionCollection Method│Description| ---------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ---------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Syslog Collector applet overview│If you use Fortinet Fortigate firewalls, you can forward network connection logs to Cortex XSIAM using the Broker VM Syslog Collector applet in a CEF format.Syslog Collector applet overview│If you use Fortinet Fortigate firewalls, you can forward network connection logs to Cortex XSIAM using the Broker VM Syslog Collector applet in a CEF format.Link to Syslog Collector applet instructions│Ingest logs from Fortinet Fortigate firewallsLink to Syslog Collector applet instructions│Ingest logs from Fortinet Fortigate firewallsLinks to content pack/integration details (onboarded prior to July 26, 2026)│The FortiManager content pack enables managing Fortinet devices through a single console central management system and provides data normalization for FortiManager event logs ingested via Syslog into Cortex XSIAM. It contains the
Fortinet FortiManager Modeling Rule, theFortinet FortiManager Parsing Rule, and the FortiManager - Install Policy Package on Device playbook. It also includes the following integration:- FortiManager: Use this integration to manage Fortinet devices as a single console central management system. This integration enables executing the FortiManager - Install Policy Package on Device playbook, which installs a FortiManager firewall policy package on a given device.
The FortiGate content pack manages FortiGate firewalls, delivering convergence and deep security visibility across diverse network environments, and facilitating data normalization for ingested event logs. It contains the
Fortinet FortiGate Modeling Rule, and theFortiGate Parsing Rule. It also includes the following integration:- FortiGate: Use this integration to manage Fortinet FortiGate firewall devices, leveraging the Fortinet FortiOS operating system to provide deep visibility and consistent security across environments like remote offices, campuses, and data centers. It includes commands for listing, creating, updating, moving, and deleting firewall policies, addresses (IPv4 and IPv6, including multicasts), and service groups, alongside functionalities like banning and unbanning IPs.
Links to content pack/integration details (onboarded prior to July 26, 2026)│The FortiManager content pack enables managing Fortinet devices through a single console central management system and provides data normalization for FortiManager event logs ingested via Syslog into Cortex XSIAM. It contains the
Fortinet FortiManager Modeling Rule, theFortinet FortiManager Parsing Rule, and the FortiManager - Install Policy Package on Device playbook. It also includes the following integration:- FortiManager: Use this integration to manage Fortinet devices as a single console central management system. This integration enables executing the FortiManager - Install Policy Package on Device playbook, which installs a FortiManager firewall policy package on a given device.
The FortiGate content pack manages FortiGate firewalls, delivering convergence and deep security visibility across diverse network environments, and facilitating data normalization for ingested event logs. It contains the
Fortinet FortiGate Modeling Rule, and theFortiGate Parsing Rule. It also includes the following integration:- FortiGate: Use this integration to manage Fortinet FortiGate firewall devices, leveraging the Fortinet FortiOS operating system to provide deep visibility and consistent security across environments like remote offices, campuses, and data centers. It includes commands for listing, creating, updating, moving, and deleting firewall policies, addresses (IPv4 and IPv6, including multicasts), and service groups, alongside functionalities like banning and unbanning IPs.
Link to connector (onboarded after July 26, 2026)│Fortinet FortiGate connectorLink to connector (onboarded after July 26, 2026)│Fortinet FortiGate connectorShow markdown source
@@ -1,10 +1,10 @@ # Fortinet Fortigate You can configure collecting Fortinet Fortigate firewall logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026): -| Fortinet Fortigate vendor | Description | +| Collection Method | Description | | ---------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Syslog Collector applet overview | If you use Fortinet Fortigate firewalls, you can forward network connection logs to Cortex XSIAM using the Broker VM Syslog Collector applet in a CEF format. | | Link to Syslog Collector applet instructions | [Ingest logs from Fortinet Fortigate firewalls](../../generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/fortinet-fortigate/ingest-logs-from-fortinet-fortigate-firewalls) | | Links to content pack/integration details (onboarded prior to July 26, 2026) | <p></p><ul><li><p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/FortiManager">FortiManager</a> content pack enables managing Fortinet devices through a single console central management system and provides data normalization for FortiManager event logs ingested via Syslog into Cortex XSIAM. It contains the <strong><code>Fortinet FortiManager Modeling Rule</code></strong>, the <strong><code>Fortinet FortiManager Parsing Rule</code></strong>, and the FortiManager - Install Policy Package on Device playbook. It also includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/forti-manager">FortiManager</a>: Use this integration to manage Fortinet devices as a single console central management system. This integration enables executing the FortiManager - Install Policy Package on Device playbook, which installs a FortiManager firewall policy package on a given device.</li></ul></li><li><p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/FortiGate">FortiGate</a> content pack manages FortiGate firewalls, delivering convergence and deep security visibility across diverse network environments, and facilitating data normalization for ingested event logs. It contains the <strong><code>Fortinet FortiGate Modeling Rule</code></strong>, and the <strong><code>FortiGate Parsing Rule</code></strong>. It also includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/forti-gate">FortiGate</a>: Use this integration to manage Fortinet FortiGate firewall devices, leveraging the Fortinet FortiOS operating system to provide deep visibility and consistent security across environments like remote offices, campuses, and data centers. It includes commands for listing, creating, updating, moving, and deleting firewall policies, addresses (IPv4 and IPv6, including multicasts), and service groups, alongside functionalities like banning and unbanning IPs.</li></ul></li></ul> | | Link to connector (onboarded after July 26, 2026) | [Fortinet FortiGate connector](fortinet-fortigate/fortinet-fortigate-connector) |
-
▸ ▾ Google Cloud Platform modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google/google-cloud-platformRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,12 +1,12 @@# Google Cloud Platform# Google Cloud PlatformYou can configure collecting Google Cloud Platform (GCP) logs using a standard data source, Cloud Service Provider (CSP) onboarding data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):You can configure collecting Google Cloud Platform (GCP) logs using a standard data source, Cloud Service Provider (CSP) onboarding data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):Google Cloud Platform vendor│DescriptionCollection Method│Description| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Standard data source overview│If you use the Pub/Sub messaging service from Google Cloud Platform (GCP), forward logs and data to Cortex XSIAM from your GCP instance using the Google Cloud Platform data source.Standard data source overview│If you use the Pub/Sub messaging service from Google Cloud Platform (GCP), forward logs and data to Cortex XSIAM from your GCP instance using the Google Cloud Platform data source.Link to standard data source instructions│The following types of logs can be ingested from Google Cloud Platform:- Audit logs, including Google Kubernetes Engine (GKE) audit logs.
- Generic logs
- Google Cloud DNS logs
- Network flow logs
For more information, see Ingest logs and data from a GCP Pub/Sub.
Link to standard data source instructions│The following types of logs can be ingested from Google Cloud Platform:- Audit logs, including Google Kubernetes Engine (GKE) audit logs.
- Generic logs
- Google Cloud DNS logs
- Network flow logs
For more information, see Ingest logs and data from a GCP Pub/Sub.
Link to full configuration Cloud Service Provider (CSP) onboarding data source instructions│Onboard Google Cloud PlatformLink to full configuration Cloud Service Provider (CSP) onboarding data source instructions│Onboard Google Cloud PlatformLink to basic configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XSIAM NG SIEM, Cortex XSIAM Enterprise license, and Cortex XSIAM Enterprise+ licenses.│How to onboard GCP with foundational configurationLink to basic configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XSIAM NG SIEM, Cortex XSIAM Enterprise license, and Cortex XSIAM Enterprise+ licenses.│How to onboard GCP with foundational configurationLinks to content pack/ integration details (onboarded prior to July 26, 2026)│The Google Cloud Pub / Sub content pack integrates with the Google Cloud Pub / Sub messaging service to enable you to send and receive messages between independent applications. It contains the following integration:- Google Cloud Pub/Sub: Use this integration to enable automated security operations and issue response through a series of dedicated commands that manage messaging topics, subscriptions, and message flow. For example, there are commands for listing, creating, updating, and deleting topics and subscriptions, publishing messages, and manually pulling or seeking messages for processing.
This integration requires specific elevated permissions such as Project-Owner or Pub/Sub Admin.
Links to content pack/ integration details (onboarded prior to July 26, 2026)│The Google Cloud Pub / Sub content pack integrates with the Google Cloud Pub / Sub messaging service to enable you to send and receive messages between independent applications. It contains the following integration:- Google Cloud Pub/Sub: Use this integration to enable automated security operations and issue response through a series of dedicated commands that manage messaging topics, subscriptions, and message flow. For example, there are commands for listing, creating, updating, and deleting topics and subscriptions, publishing messages, and manually pulling or seeking messages for processing.
This integration requires specific elevated permissions such as Project-Owner or Pub/Sub Admin.
Link to connector (onboarded after July 26, 2026)│Google CloudLink to connector (onboarded after July 26, 2026)│Google CloudShow markdown source
@@ -1,12 +1,12 @@ # Google Cloud Platform You can configure collecting Google Cloud Platform (GCP) logs using a standard data source, Cloud Service Provider (CSP) onboarding data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026): -| Google Cloud Platform vendor | Description | +| Collection Method | Description | | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Standard data source overview | If you use the Pub/Sub messaging service from Google Cloud Platform (GCP), forward logs and data to Cortex XSIAM from your GCP instance using the Google Cloud Platform data source. | | Link to standard data source instructions | <p>The following types of logs can be ingested from Google Cloud Platform:</p><ul><li>Audit logs, including Google Kubernetes Engine (GKE) audit logs.</li><li>Generic logs</li><li>Google Cloud DNS logs</li><li>Network flow logs</li></ul><p>For more information, see <a href="google-cloud-platform/ingest-logs-and-data-from-a-gcp-pub-sub">Ingest logs and data from a GCP Pub/Sub</a>.</p> | | Link to full configuration Cloud Service Provider (CSP) onboarding data source instructions | [Onboard Google Cloud Platform](../../cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/onboard-google-cloud-platform) | | Link to basic configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XSIAM NG SIEM, Cortex XSIAM Enterprise license, and Cortex XSIAM Enterprise+ licenses. | [How to onboard GCP with foundational configuration](../../cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/how-to-onboard-microsoft-azure-with-foundational-configuration) | | Links to content pack/ integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/GooglePubSub">Google Cloud Pub / Sub</a> content pack integrates with the Google Cloud Pub / Sub messaging service to enable you to send and receive messages between independent applications. It contains the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/google-pub-sub">Google Cloud Pub/Sub</a>: Use this integration to enable automated security operations and issue response through a series of dedicated commands that manage messaging topics, subscriptions, and message flow. For example, there are commands for listing, creating, updating, and deleting topics and subscriptions, publishing messages, and manually pulling or seeking messages for processing.</li></ul><p>This integration requires specific elevated permissions such as Project-Owner or Pub/Sub Admin.</p> | | Link to connector (onboarded after July 26, 2026) | [Google Cloud](google-cloud) |
-
▸ ▾ Google Workspace modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google/google-workspaceRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@# Google Workspace# Google WorkspaceYou can configure collecting Google Workspace logs and data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connectors:You can configure collecting Google Workspace logs and data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connectors:Google Workspace vendor│DescriptionCollection Method│Description| ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Standard Collector overview│Forward logs and data to Cortex XSIAM from Google Workspace using the Google Workspace data source.Standard Collector overview│Forward logs and data to Cortex XSIAM from Google Workspace using the Google Workspace data source.Link to Standard Collector instructions│The following types of data can be ingested from Google Workspace:- Google Chrome
- Admin Console
- Google Chat
- Enterprise Groups
- Login
- Rules
- Google drive
- Token
- User Accounts
- SAML
- Alerts
- Emails
For more information, see Ingest logs and data from Google Workspace.
Link to Standard Collector instructions│The following types of data can be ingested from Google Workspace:- Google Chrome
- Admin Console
- Google Chat
- Enterprise Groups
- Login
- Rules
- Google drive
- Token
- User Accounts
- SAML
- Alerts
- Emails
For more information, see Ingest logs and data from Google Workspace.
Links to content pack/ integration details (onboarded prior to July 26, 2026)│The G Suite Admin content pack integrates with Cortex XSIAM to handle various administrative tasks for G Suite or Google Workspace Admin environments. It contains the following integration:
- Google Workspace Admin: Use this integration to perform actions on IT infrastructure, create users, update settings, and manage other administrative duties. It includes commands for user management, device management (Chrome browser devices), policy management, and data transfer.
Links to content pack/ integration details (onboarded prior to July 26, 2026)│The G Suite Admin content pack integrates with Cortex XSIAM to handle various administrative tasks for G Suite or Google Workspace Admin environments. It contains the following integration:
- Google Workspace Admin: Use this integration to perform actions on IT infrastructure, create users, update settings, and manage other administrative duties. It includes commands for user management, device management (Chrome browser devices), policy management, and data transfer.
Link to connectors│- Google Workspace connector
- Google Workspace Automation and Collection (onboarded after July 26, 2026)
Link to connectors│- Google Workspace connector
- Google Workspace Automation and Collection (onboarded after July 26, 2026)
Show markdown source
@@ -1,10 +1,10 @@ # Google Workspace You can configure collecting Google Workspace logs and data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connectors: -| Google Workspace vendor | Description | +| Collection Method | Description | | ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Standard Collector overview | Forward logs and data to Cortex XSIAM from Google Workspace using the Google Workspace data source. | | Link to Standard Collector instructions | <p>The following types of data can be ingested from Google Workspace:</p><ul><li>Google Chrome</li><li>Admin Console</li><li>Google Chat</li><li>Enterprise Groups</li><li>Login</li><li>Rules</li><li>Google drive</li><li>Token</li><li>User Accounts</li><li>SAML</li><li>Alerts</li><li>Emails</li></ul><p>For more information, see <a href="google-workspace/ingest-logs-and-data-from-google-workspace">Ingest logs and data from Google Workspace</a>.</p> | | Links to content pack/ integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/GSuiteAdmin">G Suite Admin</a> content pack integrates with Cortex XSIAM to handle various administrative tasks for G Suite or Google Workspace Admin environments. It contains the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/g-suite-admin">Google Workspace Admin</a>: Use this integration to perform actions on IT infrastructure, create users, update settings, and manage other administrative duties. It includes commands for user management, device management (Chrome browser devices), policy management, and data transfer.</li></ul> | | Link to connectors | <ul><li><a href="google-workspace/google-workspace-connector">Google Workspace connector</a></li><li><a href="google-workspace/google-workspace-automation-and-collection">Google Workspace Automation and Collection</a> (onboarded after July 26, 2026)</li></ul> |
-
▸ ▾ HTTP log collector modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/http-log-collectorRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,9 +1,9 @@# HTTP log collector# HTTP log collectorYou can configure collecting any vendor logs over HTTP with a Custom - HTTP based Collector in a Raw, JSON, CEF, or LEEF format.You can configure collecting any vendor logs over HTTP with a Custom - HTTP based Collector in a Raw, JSON, CEF, or LEEF format.HTTP log collector│DescriptionCollection Method│Description| ------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- || ------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- |Custom - HTTP based Collector (standard data source) overview│Forward any vendor logs over HTTP in a Raw, JSON, CEF, or LEEF format to Cortex XSIAM using the Custom - HTTP data source.Custom - HTTP based Collector (standard data source) overview│Forward any vendor logs over HTTP in a Raw, JSON, CEF, or LEEF format to Cortex XSIAM using the Custom - HTTP data source.Link to standard data source instructions│Set up an HTTP log collector to receive logsLink to standard data source instructions│Set up an HTTP log collector to receive logsShow markdown source
@@ -1,9 +1,9 @@ # HTTP log collector You can configure collecting any vendor logs over HTTP with a Custom - HTTP based Collector in a Raw, JSON, CEF, or LEEF format. -| HTTP log collector | Description | +| Collection Method | Description | | ------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | | Custom - HTTP based Collector (standard data source) overview | Forward any vendor logs over HTTP in a Raw, JSON, CEF, or LEEF format to Cortex XSIAM using the Custom - HTTP data source. | | Link to standard data source instructions | [Set up an HTTP log collector to receive logs](http-log-collector/set-up-an-http-log-collector-to-receive-logs) |
-
▸ ▾ Kubernetes modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/kubernetesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,8 @@# Kubernetes# KubernetesYou can configure collecting Kubernetes data using a standard data source with the Onboard Kubernetes wizard:You can configure collecting Kubernetes data using a standard data source with the Onboard Kubernetes wizard:Kubernetes vendor│DescriptionCollection Method│Description| ----------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ----------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Standard data source overview│The Kubernetes onboarding wizard is designed to facilitate the seamless setup of Kubernetes data into Cortex XSIAM and deploys your Kubernetes Connector.Standard data source overview│The Kubernetes onboarding wizard is designed to facilitate the seamless setup of Kubernetes data into Cortex XSIAM and deploys your Kubernetes Connector.Show markdown source
@@ -1,8 +1,8 @@ # Kubernetes You can configure collecting Kubernetes data using a standard data source with the Onboard Kubernetes wizard: -| Kubernetes vendor | Description | +| Collection Method | Description | | ----------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Standard data source overview | The Kubernetes onboarding wizard is designed to facilitate the seamless setup of Kubernetes data into Cortex XSIAM and deploys your Kubernetes Connector. | | Link to standard data source instructions | <p><a href="kubernetes/onboard-the-kubernetes-connector">Onboard the Kubernetes Connector </a></p><p>Other relevant topic:</p><ul><li><a href="kubernetes/whats-new-in-kubernetes-connector">What's new in Kubernetes Connector?</a></li><li><a href="kubernetes/supported-kubernetes-distributions">Supported Kubernetes distributions</a></li></ul> |
-
▸ ▾ Azure Event Hub modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-event-hubRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,9 +1,9 @@# Azure Event Hub# Azure Event HubYou can configure collecting Azure Event Hub logs using a standard data source or content pack (onboarded prior to July 26, 2026):You can configure collecting Azure Event Hub logs using a standard data source or content pack (onboarded prior to July 26, 2026):Azure Event Hub vendor│DescriptionCollection Method│Description| --------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ || --------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |Standard data source overview│Forward different types of logs to Cortex XSIAM from Azure Event Hub using the Microsoft Azure Event Hub data source.Standard data source overview│Forward different types of logs to Cortex XSIAM from Azure Event Hub using the Microsoft Azure Event Hub data source.Link to standard data source instructions│The following types of logs can be ingested from Azure Event Hub:- Activity logs
- Microsoft Entra ID Activity logs and Microsoft Entra ID Sign-in logs
- Resource logs, including AKS audit logs
For more information, see Ingest logs from Microsoft Azure Event Hub.
Link to standard data source instructions│The following types of logs can be ingested from Azure Event Hub:- Activity logs
- Microsoft Entra ID Activity logs and Microsoft Entra ID Sign-in logs
- Resource logs, including AKS audit logs
For more information, see Ingest logs from Microsoft Azure Event Hub.
Link to content pack details (onboarded prior to July 26, 2026)│Azure Logs: Use this content pack to ingest and normalize various Azure logs to the Cortex Data Model (XDM) schema, including Azure Entra ID events ingested via the Office 365 data source, and Azure Logs ingested via the Microsoft Azure Event Hub data source. It includes modeling and parsing rules for log normalization.Link to content pack details (onboarded prior to July 26, 2026)│Azure Logs: Use this content pack to ingest and normalize various Azure logs to the Cortex Data Model (XDM) schema, including Azure Entra ID events ingested via the Office 365 data source, and Azure Logs ingested via the Microsoft Azure Event Hub data source. It includes modeling and parsing rules for log normalization.Show markdown source
@@ -1,9 +1,9 @@ # Azure Event Hub You can configure collecting Azure Event Hub logs using a standard data source or content pack (onboarded prior to July 26, 2026): -| Azure Event Hub vendor | Description | +| Collection Method | Description | | --------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | Standard data source overview | Forward different types of logs to Cortex XSIAM from Azure Event Hub using the Microsoft Azure Event Hub data source. | | Link to standard data source instructions | <p>The following types of logs can be ingested from Azure Event Hub:</p><ul><li>Activity logs</li><li>Microsoft Entra ID Activity logs and Microsoft Entra ID Sign-in logs</li><li>Resource logs, including AKS audit logs</li></ul><p>For more information, see <a href="azure-event-hub/ingest-logs-from-microsoft-azure-event-hub">Ingest logs from Microsoft Azure Event Hub</a>.</p> | | Link to content pack details (onboarded prior to July 26, 2026) | [Azure Logs](https://cortex.marketplace.pan.dev/marketplace/details/MicrosoftEntraID): Use this content pack to ingest and normalize various Azure logs to the Cortex Data Model (XDM) schema, including Azure Entra ID events ingested via the Office 365 data source, and Azure Logs ingested via the Microsoft Azure Event Hub data source. It includes modeling and parsing rules for log normalization. |
-
▸ ▾ Azure Network Watcher modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-network-watcherRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,8 @@# Azure Network Watcher# Azure Network WatcherYou can configure collecting Azure Network Watcher logs using a standard data source:You can configure collecting Azure Network Watcher logs using a standard data source:Azure Network Watcher vendor│DescriptionCollection Method│Description| ----------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ----------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Standard data source overview│Forward different types of flow logs to Cortex XSIAM from Azure Network Watcher using the Azure Network Watcher data source.Standard data source overview│Forward different types of flow logs to Cortex XSIAM from Azure Network Watcher using the Azure Network Watcher data source.Link to standard data source instructions│The following types of flow logs can be ingested from Azure Network Watcher:- Network security group (NSG) flow logs
- Virtual network (VNet) flow logs
For more information, see Ingest network flow logs from Microsoft Azure Network Watcher.
Link to standard data source instructions│The following types of flow logs can be ingested from Azure Network Watcher:- Network security group (NSG) flow logs
- Virtual network (VNet) flow logs
For more information, see Ingest network flow logs from Microsoft Azure Network Watcher.
Show markdown source
@@ -1,8 +1,8 @@ # Azure Network Watcher You can configure collecting Azure Network Watcher logs using a standard data source: -| Azure Network Watcher vendor | Description | +| Collection Method | Description | | ----------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Standard data source overview | Forward different types of flow logs to Cortex XSIAM from Azure Network Watcher using the Azure Network Watcher data source. | | Link to standard data source instructions | <p>The following types of flow logs can be ingested from Azure Network Watcher:</p><ul><li>Network security group (NSG) flow logs</li><li>Virtual network (VNet) flow logs</li></ul><p>For more information, see <a href="azure-network-watcher/ingest-network-flow-logs-from-microsoft-azure-network-watcher">Ingest network flow logs from Microsoft Azure Network Watcher</a>.</p> |
-
▸ ▾ Microsoft 365 (Posture) modified +5 −5
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-365-postureRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,9 +1,9 @@# Microsoft 365 (Posture)# Microsoft 365 (Posture)You can configure collecting Microsoft 365 (Posture) logs using a Cloud Posture and Runtime Security data source or connector:You can configure collecting Microsoft 365 (Posture) logs using a Cloud Posture and Runtime Security data source or connector:Microsoft 365 (Posture) vendor│DescriptionCollection Method│Description| ------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- || ------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Cloud Posture and Runtime Security data source overview│Forward Microsoft 365 (Postrure) logs to Cortex XSIAM using the Microsoft 365 data source.Cloud Posture and Runtime Security data source overview│Forward Microsoft 365 (Postrure) logs to Cortex XSIAM using the Microsoft 365 data source.Link to Cloud Posture and Runtime Security data source instructions│How to onboard Microsoft 365Link to Cloud Posture and Runtime Security data source instructions│How to onboard Microsoft 365Show markdown source
@@ -1,9 +1,9 @@ # Microsoft 365 (Posture) You can configure collecting Microsoft 365 (Posture) logs using a Cloud Posture and Runtime Security data source or connector: -| Microsoft 365 (Posture) vendor | Description | -| ------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Cloud Posture and Runtime Security data source overview | Forward Microsoft 365 (Postrure) logs to Cortex XSIAM using the Microsoft 365 data source. | -| Link to Cloud Posture and Runtime Security data source instructions | [How to onboard Microsoft 365](../../cloud-posture-and-runtime-security-data-sources/how-to-onboard-microsoft-365) | -| Link to connector details | <p>• <a href="broken-reference">Microsoft 365</a><br>• <a href="microsoft365">Microsoft365</a><br>• <a href="microsoft-entra-id">Microsoft Entra ID</a></p> | +| Collection Method | Description | +| ------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| Cloud Posture and Runtime Security data source overview | Forward Microsoft 365 (Postrure) logs to Cortex XSIAM using the Microsoft 365 data source. | +| Link to Cloud Posture and Runtime Security data source instructions | [How to onboard Microsoft 365](../../cloud-posture-and-runtime-security-data-sources/how-to-onboard-microsoft-365) | +| Link to connector details | <p>• <a href="broken-reference">Microsoft 365</a><br>• <a href="microsoft-office-365/microsoft365">Microsoft365</a><br>• <a href="microsoft-entra-id">Microsoft Entra ID</a></p> |
-
▸ ▾ Microsoft Azure modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-azureRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,8 @@# Microsoft Azure# Microsoft AzureFollow a wizard to onboard your Microsoft Azure environment. The Azure onboarding wizard is designed to facilitate the seamless setup of Azure data into Cortex XSIAM.Follow a wizard to onboard your Microsoft Azure environment. The Azure onboarding wizard is designed to facilitate the seamless setup of Azure data into Cortex XSIAM.Microsoft Azure vendor│DescriptionCollection Method│Description| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------- || ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------- |Link to full configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XSIAM Premium license.│Onboard Microsoft AzureLink to full configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XSIAM Premium license.│Onboard Microsoft AzureLink to basic configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XSIAM NG SIEM, Cortex XSIAM Enterprise license, and Cortex XSIAM Enterprise+ licenses.│How to onboard Microsoft AzureLink to basic configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XSIAM NG SIEM, Cortex XSIAM Enterprise license, and Cortex XSIAM Enterprise+ licenses.│How to onboard Microsoft AzureShow markdown source
@@ -1,8 +1,8 @@ # Microsoft Azure Follow a wizard to onboard your Microsoft Azure environment. The Azure onboarding wizard is designed to facilitate the seamless setup of Azure data into Cortex XSIAM. -| Microsoft Azure vendor | Description | +| Collection Method | Description | | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------- | | Link to full configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XSIAM Premium license. | [Onboard Microsoft Azure](../../cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/onboard-microsoft-azure) | | Link to basic configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XSIAM NG SIEM, Cortex XSIAM Enterprise license, and Cortex XSIAM Enterprise+ licenses. | [How to onboard Microsoft Azure](../../cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/how-to-onboard-microsoft-azure) |
-
▸ ▾ Microsoft Defender for Endpoint Events modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-defender-for-endpoint-eventsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,9 +1,9 @@# Microsoft Defender for Endpoint Events# Microsoft Defender for Endpoint EventsYou can configure collecting Microsoft Defender for Endpoints raw EDR event data using a Standard Collector or with a content pack integration (onboarded prior to July 26, 2026):You can configure collecting Microsoft Defender for Endpoints raw EDR event data using a Standard Collector or with a content pack integration (onboarded prior to July 26, 2026):Microsoft Defender for Endpoints vendor│DescriptionCollection Method│Description| ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Standard Collector overview│Forward raw EDR event data from Microsoft Defender for Endpoint Events, streamed to Azure Event Hubs to Cortex XSIAM using the Microsoft Defender for Endpoint Events data source.Standard Collector overview│Forward raw EDR event data from Microsoft Defender for Endpoint Events, streamed to Azure Event Hubs to Cortex XSIAM using the Microsoft Defender for Endpoint Events data source.Link to Standard Collector instructions│Ingest raw EDR events from Microsoft Defender for EndpointLink to Standard Collector instructions│Ingest raw EDR events from Microsoft Defender for EndpointLinks to content pack/ integration details (onboarded prior to July 26, 2026)│The Microsoft Defender for Endpoint content pack provides a unified platform within Cortex XSIAM to deliver preventative protection, post-breach detection, automated investigation, and response for endpoints across Windows, macOS, Linux, Android, iOS, and network devices. It contains the following integrations:
- Microsoft Defender for Endpoint: Use this integration to connect to the MDE platform and import events as Cortex XSIAM issues to facilitate investigation and remediation actions. It includes playbooks, an automation script, and commands that perform endpoint investigation and response, collect indicator and file statistics, and retrieve authentication and permission details. You can run the commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.
- Microsoft Defender for Endpoint Alerts (deprecated): Use the Office 365 data source instead (Standard Collector).
Links to content pack/ integration details (onboarded prior to July 26, 2026)│The Microsoft Defender for Endpoint content pack provides a unified platform within Cortex XSIAM to deliver preventative protection, post-breach detection, automated investigation, and response for endpoints across Windows, macOS, Linux, Android, iOS, and network devices. It contains the following integrations:
- Microsoft Defender for Endpoint: Use this integration to connect to the MDE platform and import events as Cortex XSIAM issues to facilitate investigation and remediation actions. It includes playbooks, an automation script, and commands that perform endpoint investigation and response, collect indicator and file statistics, and retrieve authentication and permission details. You can run the commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.
- Microsoft Defender for Endpoint Alerts (deprecated): Use the Office 365 data source instead (Standard Collector).
Show markdown source
@@ -1,9 +1,9 @@ # Microsoft Defender for Endpoint Events You can configure collecting Microsoft Defender for Endpoints raw EDR event data using a Standard Collector or with a content pack integration (onboarded prior to July 26, 2026): -| Microsoft Defender for Endpoints vendor | Description | +| Collection Method | Description | | ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Standard Collector overview | Forward raw EDR event data from Microsoft Defender for Endpoint Events, streamed to Azure Event Hubs to Cortex XSIAM using the Microsoft Defender for Endpoint Events data source. | | Link to Standard Collector instructions | [Ingest raw EDR events from Microsoft Defender for Endpoint](microsoft-defender-for-endpoint-events/ingest-raw-edr-events-from-microsoft-defender-for-endpoint) | | Links to content pack/ integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/MicrosoftDefenderAdvancedThreatProtection">Microsoft Defender for Endpoint</a> content pack provides a unified platform within Cortex XSIAM to deliver preventative protection, post-breach detection, automated investigation, and response for endpoints across Windows, macOS, Linux, Android, iOS, and network devices. It contains the following integrations:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/microsoft-defender-advanced-threat-protection">Microsoft Defender for Endpoint</a>: Use this integration to connect to the MDE platform and import events as Cortex XSIAM issues to facilitate investigation and remediation actions. It includes playbooks, an automation script, and commands that perform endpoint investigation and response, collect indicator and file statistics, and retrieve authentication and permission details. You can run the commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.</li><li>Microsoft Defender for Endpoint Alerts (deprecated): Use the Office 365 data source instead (Standard Collector).</li></ul> |
-
▸ ▾ Microsoft Office 365 (email) modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-office-365-emailRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,8 @@# Microsoft Office 365 (email)# Microsoft Office 365 (email)You can configure collecting Microsoft Office 365 email metadata using a Standard Collector:You can configure collecting Microsoft Office 365 email metadata using a Standard Collector:Microsoft Office 365 vendor│DescriptionCollection Method│Description| --------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- || --------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |Standard Collector overview│Forward email metadata through Microsoft Graph API to Cortex XSIAM from Microsoft Office 365 using the Microsoft 365 data source.Standard Collector overview│Forward email metadata through Microsoft Graph API to Cortex XSIAM from Microsoft Office 365 using the Microsoft 365 data source.Link to Standard Collector instructions│Ingest logs and data from Microsoft 365Link to Standard Collector instructions│Ingest logs and data from Microsoft 365Show markdown source
@@ -1,8 +1,8 @@ # Microsoft Office 365 (email) You can configure collecting Microsoft Office 365 email metadata using a Standard Collector: -| Microsoft Office 365 vendor | Description | +| Collection Method | Description | | --------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- | | Standard Collector overview | Forward email metadata through Microsoft Graph API to Cortex XSIAM from Microsoft Office 365 using the Microsoft 365 data source. | | Link to Standard Collector instructions | [Ingest logs and data from Microsoft 365](microsoft-office-365-email/ingest-logs-and-data-from-microsoft-365) |
-
▸ ▾ Microsoft Office 365 modified +2 −2
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-office-365Read it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@# Microsoft Office 365# Microsoft Office 365You can configure collecting Microsoft Office 365 logs and data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connectors:You can configure collecting Microsoft Office 365 logs and data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connectors:Google Workspace vendor│DescriptionCollection Method│Description| ---------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ---------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Standard Collector overview│Forward logs and data to Cortex XSIAM from Microsoft Office 365 Management Activity API and Microsoft Graph API using the Office 365 data source.Standard Collector overview│Forward logs and data to Cortex XSIAM from Microsoft Office 365 Management Activity API and Microsoft Graph API using the Office 365 data source.Link to Standard Collector instructions│The following types of logs and data can be ingested from Microsoft Office 365 Management Activity API and Microsoft Graph API:Microsoft Office 365 audit events from Management Activity API
- Microsoft Entra ID (Azure AD)
- Exchange Online
- SharePoint Online
- DLP
- General
- Microsoft Entra ID (Azure AD) authentication and audit events from Microsoft Graph API
Microsoft 365 alerts from Microsoft Graph Security API are available for different products:
- Microsoft Graph Security API v1
- Microsoft Graph Security API v2
For more information, see Ingest logs from Microsoft Office 365.
Link to Standard Collector instructions│The following types of logs and data can be ingested from Microsoft Office 365 Management Activity API and Microsoft Graph API:Microsoft Office 365 audit events from Management Activity API
- Microsoft Entra ID (Azure AD)
- Exchange Online
- SharePoint Online
- DLP
- General
- Microsoft Entra ID (Azure AD) authentication and audit events from Microsoft Graph API
Microsoft 365 alerts from Microsoft Graph Security API are available for different products:
- Microsoft Graph Security API v1
- Microsoft Graph Security API v2
For more information, see Ingest logs from Microsoft Office 365.
Links to content pack/integration details (onboarded prior to July 26, 2026)│The Microsoft Exchange Online content pack integrates with Exchange Online and Office 365 mail services to enable monitoring, searching, content retrieval, deletion of emails, and management of tenant allow/block lists. The content items in this pack include several playbooks focused on searching and deleting content, automations like GetEWSFolder and CreateCertificate, and the following integrations:
- EWS O365: Use this integration to retrieve information on emails and activities in a target mailbox and perform operations such as deleting emails and attachments, moving email items, handling mail sending and replying including inline images, and retrieving out-of-office status information.
- O365 - Security And Compliance - Content Search v2: Use this integration to manage security and compliance content search across organizational assets including emails, SharePoint sites, and OneDrives, and to perform actions like previewing and deleting emails. It includes the capability to delete an email for all recipients using the
o365-sc-email-security-search-and-delete-email-office-365-quick-actioncommand. - EWS Extension Online Powershell v3: Use this integration to retrieve information about mailboxes and users in your organization, and to retrieve and modify tenant allow/block lists. It includes commands that retrieve information about mailboxes and users, display client access settings, retrieve permissions, list recipient objects, and manage tenant allow/block list entries (add, remove, list, count). It also includes commands to enable or disable mail flow rules and mail forwarding, and to list message trace details.
The Microsoft Graph API content pack provides the capability to interact with Microsoft APIs that do not have dedicated integrations in Cortex XSIAM, such as Mail Single-User. It includes the following integration:
- Microsoft Graph API: Use this integration to interact with various Microsoft APIs, such as Mail Single-User, that currently lack dedicated integrations in Cortex XSIAM. It includes commands that facilitate making specific API requests (
msgraph-api-requestwhich supports headers), managing the authentication process by generating login URLs (msgraph-api-generate-login-url) to support the OAuth consent dialog, and resetting the authentication context if needed (msgraph-api-auth-reset)
- Microsoft Graph API: Use this integration to interact with various Microsoft APIs, such as Mail Single-User, that currently lack dedicated integrations in Cortex XSIAM. It includes commands that facilitate making specific API requests (
Links to content pack/integration details (onboarded prior to July 26, 2026)│The Microsoft Exchange Online content pack integrates with Exchange Online and Office 365 mail services to enable monitoring, searching, content retrieval, deletion of emails, and management of tenant allow/block lists. The content items in this pack include several playbooks focused on searching and deleting content, automations like GetEWSFolder and CreateCertificate, and the following integrations:
- EWS O365: Use this integration to retrieve information on emails and activities in a target mailbox and perform operations such as deleting emails and attachments, moving email items, handling mail sending and replying including inline images, and retrieving out-of-office status information.
- O365 - Security And Compliance - Content Search v2: Use this integration to manage security and compliance content search across organizational assets including emails, SharePoint sites, and OneDrives, and to perform actions like previewing and deleting emails. It includes the capability to delete an email for all recipients using the
o365-sc-email-security-search-and-delete-email-office-365-quick-actioncommand. - EWS Extension Online Powershell v3: Use this integration to retrieve information about mailboxes and users in your organization, and to retrieve and modify tenant allow/block lists. It includes commands that retrieve information about mailboxes and users, display client access settings, retrieve permissions, list recipient objects, and manage tenant allow/block list entries (add, remove, list, count). It also includes commands to enable or disable mail flow rules and mail forwarding, and to list message trace details.
The Microsoft Graph API content pack provides the capability to interact with Microsoft APIs that do not have dedicated integrations in Cortex XSIAM, such as Mail Single-User. It includes the following integration:
- Microsoft Graph API: Use this integration to interact with various Microsoft APIs, such as Mail Single-User, that currently lack dedicated integrations in Cortex XSIAM. It includes commands that facilitate making specific API requests (
msgraph-api-requestwhich supports headers), managing the authentication process by generating login URLs (msgraph-api-generate-login-url) to support the OAuth consent dialog, and resetting the authentication context if needed (msgraph-api-auth-reset)
- Microsoft Graph API: Use this integration to interact with various Microsoft APIs, such as Mail Single-User, that currently lack dedicated integrations in Cortex XSIAM. It includes commands that facilitate making specific API requests (
Link to connector details│- Microsoft 365
- Microsoft Graph (onboarded after July 26, 2026)
Link to connector details│- Microsoft 365
- Microsoft365
- Microsoft 365 Copilot
- Microsoft Graph (onboarded after July 26, 2026)
Show markdown source
@@ -1,10 +1,10 @@ # Microsoft Office 365 You can configure collecting Microsoft Office 365 logs and data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connectors: -| Google Workspace vendor | Description | +| Collection Method | Description | | ---------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Standard Collector overview | Forward logs and data to Cortex XSIAM from Microsoft Office 365 Management Activity API and Microsoft Graph API using the Office 365 data source. | | Link to Standard Collector instructions | <p>The following types of logs and data can be ingested from Microsoft Office 365 Management Activity API and Microsoft Graph API:</p><ul><li><p>Microsoft Office 365 audit events from Management Activity API</p><ul><li>Microsoft Entra ID (Azure AD)</li><li>Exchange Online</li><li>SharePoint Online</li><li>DLP</li><li>General</li></ul></li><li>Microsoft Entra ID (Azure AD) authentication and audit events from Microsoft Graph API</li><li><p>Microsoft 365 alerts from Microsoft Graph Security API are available for different products:</p><ul><li>Microsoft Graph Security API v1</li><li>Microsoft Graph Security API v2</li></ul></li></ul><p>For more information, see <a href="microsoft-office-365/ingest-logs-from-microsoft-office-365">Ingest logs from Microsoft Office 365</a>.</p> | | Links to content pack/integration details (onboarded prior to July 26, 2026) | <ul><li><p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/MicrosoftExchangeOnline">Microsoft Exchange Online</a> content pack integrates with Exchange Online and Office 365 mail services to enable monitoring, searching, content retrieval, deletion of emails, and management of tenant allow/block lists. The content items in this pack include several playbooks focused on searching and deleting content, automations like GetEWSFolder and CreateCertificate, and the following integrations:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/ewso365">EWS O365</a>: Use this integration to retrieve information on emails and activities in a target mailbox and perform operations such as deleting emails and attachments, moving email items, handling mail sending and replying including inline images, and retrieving out-of-office status information.</li><li><a href="https://xsoar.pan.dev/docs/reference/integrations/security-and-compliance-v2">O365 - Security And Compliance - Content Search v2</a>: Use this integration to manage security and compliance content search across organizational assets including emails, SharePoint sites, and OneDrives, and to perform actions like previewing and deleting emails. It includes the capability to delete an email for all recipients using the <strong><code>o365-sc-email-security-search-and-delete-email-office-365-quick-action</code></strong> command.</li><li><a href="https://xsoar.pan.dev/docs/reference/integrations/ews-extension-online-powershell-v3">EWS Extension Online Powershell v3</a>: Use this integration to retrieve information about mailboxes and users in your organization, and to retrieve and modify tenant allow/block lists. It includes commands that retrieve information about mailboxes and users, display client access settings, retrieve permissions, list recipient objects, and manage tenant allow/block list entries (add, remove, list, count). It also includes commands to enable or disable mail flow rules and mail forwarding, and to list message trace details.</li></ul></li><li><p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/MicrosoftGraphAPI">Microsoft Graph API</a> content pack provides the capability to interact with Microsoft APIs that do not have dedicated integrations in Cortex XSIAM, such as Mail Single-User. It includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/microsoft-graph-api">Microsoft Graph API</a>: Use this integration to interact with various Microsoft APIs, such as Mail Single-User, that currently lack dedicated integrations in Cortex XSIAM. It includes commands that facilitate making specific API requests (<strong><code>msgraph-api-request</code></strong> which supports headers), managing the authentication process by generating login URLs (<strong><code>msgraph-api-generate-login-url</code></strong>) to support the OAuth consent dialog, and resetting the authentication context if needed (<strong><code>msgraph-api-auth-reset</code></strong>)</li></ul></li></ul> | -| Link to connector details | <ul><li><a href="broken-reference">Microsoft 365</a></li><li><a href="microsoft-graph">Microsoft Graph</a> (onboarded after July 26, 2026)</li></ul> | +| Link to connector details | <ul><li><a href="broken-reference">Microsoft 365</a></li><li><a href="microsoft-office-365/microsoft365">Microsoft365</a></li><li><a href="microsoft-office-365/microsoft-365-copilot">Microsoft 365 Copilot</a></li><li><a href="microsoft-office-365/microsoft-graph">Microsoft Graph</a> (onboarded after July 26, 2026)</li></ul> |
-
▸ ▾ Microsoft 365 Copilot renamed +0 −0
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-office-365/microsoft-365-copilotRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗ moved from
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-365-copilot.md -
▸ ▾ Microsoft 365 renamed +0 −0
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-office-365/microsoft-365Read it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗ moved from
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-365.md -
▸ ▾ Microsoft Graph renamed +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-office-365/microsoft-graphRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗ moved from
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-graph.mdBefore After@@ -1,14 +1,14 @@# Microsoft Graph# Microsoft Graphhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintIntegrate with Microsoft products through the Microsoft Graph API and Microsoft Endpoint Manager (Intune). Use the Microsoft Graph API to interact with Microsoft APIs that do not have dedicated connectors, and use Microsoft Endpoint Manager (Intune) for cloud-based mobile device and operating system management.Integrate with Microsoft products through the Microsoft Graph API and Microsoft Endpoint Manager (Intune). Use the Microsoft Graph API to interact with Microsoft APIs that do not have dedicated connectors, and use Microsoft Endpoint Manager (Intune) for cloud-based mobile device and operating system management.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Microsoft Graph API: Use the Microsoft Graph API integration to interact with Microsoft APIs that do not have dedicated integrations in Cortex XSIAM, for example, Mail Single-User, etc. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• Microsoft Graph API: Use the Microsoft Graph API integration to interact with Microsoft APIs that do not have dedicated integrations in Cortex XSIAM, for example, Mail Single-User, etc. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• Microsoft Graph Device Management: Microsoft Intune is a Microsoft cloud-based management solution that provides for mobile device and operating system management. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.• Microsoft Graph Device Management: Microsoft Intune is a Microsoft cloud-based management solution that provides for mobile device and operating system management. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # Microsoft Graph {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../../marketplace). {% endhint %} Integrate with Microsoft products through the Microsoft Graph API and Microsoft Endpoint Manager (Intune). Use the Microsoft Graph API to interact with Microsoft APIs that do not have dedicated connectors, and use Microsoft Endpoint Manager (Intune) for cloud-based mobile device and operating system management. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Microsoft Graph API](https://xsoar.pan.dev/docs/reference/integrations/microsoft-graph-api): Use the Microsoft Graph API integration to interact with Microsoft APIs that do not have dedicated integrations in Cortex XSIAM, for example, Mail Single-User, etc. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. * [Microsoft Graph Device Management](https://xsoar.pan.dev/docs/reference/integrations/microsoft-graph-device-management): Microsoft Intune is a Microsoft cloud-based management solution that provides for mobile device and operating system management. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. -
▸ ▾ Microsoft365 renamed +0 −0
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-office-365/microsoft365Read it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗ moved from
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft365.md -
▸ ▾ Okta modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/oktaRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@# Okta# OktaYou can configure collecting Okta logs and data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connectors:You can configure collecting Okta logs and data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connectors:Okta vendor│DescriptionCollection Method│Description| --------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || --------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Standard Collector overview│Forward logs and data to Cortex XSIAM from Okta using the Okta data source.Standard Collector overview│Forward logs and data to Cortex XSIAM from Okta using the Okta data source.Link to Standard Collector instructions│The following types of logs can be ingested from Okta:- Activity logs
For more information, see Ingest logs and data from Okta.
Link to Standard Collector instructions│The following types of logs can be ingested from Okta:- Activity logs
For more information, see Ingest logs and data from Okta.
Link to content pack/integration details (onboarded prior to July 26, 2026)│The Okta content pack integrates with Okta's cloud-based identity management service to provide identity-centric visibility, enrichment, and automated response capabilities against threats. It contains automations, classifiers, modeling rules, parsing rules, playbooks, and scripts. It also includes the following integrations:
- Okta IAM: Use this integration to interact with Okta's Identity Access Management service for executing CRUD operations related to employee lifecycle processes. It supports commands for selected features, such as those related to the Preference Center.
- Okta v2: Use this integration to integrate with Okta's cloud-based identity management service. It includes commands such as
okta-expire-password, which can optionally revoke existing sessions and require a password change at next login, and supports updating network zones and getting user information by email. - Okta Event Collector: Use this integration to collect event logs for authentication and Audit provided by the Okta admin API. It supports fetching events and includes commands related to date parsing.
Link to content pack/integration details (onboarded prior to July 26, 2026)│The Okta content pack integrates with Okta's cloud-based identity management service to provide identity-centric visibility, enrichment, and automated response capabilities against threats. It contains automations, classifiers, modeling rules, parsing rules, playbooks, and scripts. It also includes the following integrations:
- Okta IAM: Use this integration to interact with Okta's Identity Access Management service for executing CRUD operations related to employee lifecycle processes. It supports commands for selected features, such as those related to the Preference Center.
- Okta v2: Use this integration to integrate with Okta's cloud-based identity management service. It includes commands such as
okta-expire-password, which can optionally revoke existing sessions and require a password change at next login, and supports updating network zones and getting user information by email. - Okta Event Collector: Use this integration to collect event logs for authentication and Audit provided by the Okta admin API. It supports fetching events and includes commands related to date parsing.
Link to connectors│- Okta Automation and Collection (onboarded after July 26, 2026)
- Okta connector
Link to connectors│- Okta Automation and Collection (onboarded after July 26, 2026)
- Okta connector
Show markdown source
@@ -1,10 +1,10 @@ # Okta You can configure collecting Okta logs and data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connectors: -| Okta vendor | Description | +| Collection Method | Description | | --------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Standard Collector overview | Forward logs and data to Cortex XSIAM from Okta using the Okta data source. | | Link to Standard Collector instructions | <p>The following types of logs can be ingested from Okta:</p><ul><li>Activity logs</li></ul><p>For more information, see <a href="okta/ingest-logs-and-data-from-okta">Ingest logs and data from Okta</a>.</p> | | Link to content pack/integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/Okta/">Okta</a> content pack integrates with Okta's cloud-based identity management service to provide identity-centric visibility, enrichment, and automated response capabilities against threats. It contains automations, classifiers, modeling rules, parsing rules, playbooks, and scripts. It also includes the following integrations:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/okta-iam">Okta IAM</a>: Use this integration to interact with Okta's Identity Access Management service for executing CRUD operations related to employee lifecycle processes. It supports commands for selected features, such as those related to the Preference Center.</li><li><a href="https://xsoar.pan.dev/docs/reference/integrations/okta-v2">Okta v2</a>: Use this integration to integrate with Okta's cloud-based identity management service. It includes commands such as <strong><code>okta-expire-password</code></strong>, which can optionally revoke existing sessions and require a password change at next login, and supports updating network zones and getting user information by email.</li><li><a href="https://xsoar.pan.dev/docs/reference/integrations/okta-event-collector">Okta Event Collector</a>: Use this integration to collect event logs for authentication and Audit provided by the Okta admin API. It supports fetching events and includes commands related to date parsing.</li></ul> | | Link to connectors | <ul><li><a href="okta/okta-automation-and-collection">Okta Automation and Collection</a> (onboarded after July 26, 2026)</li><li><a href="okta/okta-connector">Okta connector</a></li></ul> |
-
▸ ▾ OneLogin modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/oneloginRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@# OneLogin# OneLoginYou can configure collecting OneLogin logs and data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):You can configure collecting OneLogin logs and data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):OneLogin vendor│DescriptionCollection Method│Description| --------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || --------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Standard Collector overview│Forward logs and data to Cortex XSIAM from OneLogin via the OneLogin REST APIs using the OneLogin data source.Standard Collector overview│Forward logs and data to Cortex XSIAM from OneLogin via the OneLogin REST APIs using the OneLogin data source.Link to Standard Collector instructions│The following types of data can be ingested from OneLogin:Log collection
- Events: User logins, administrative operations, provisioning, and a list of all OneLogin event types
Directory
- Users: Lists of users.
- Groups: Lists of groups.
- Apps: Lists of apps.
For more information, see Ingest logs and data from OneLogin.
Link to Standard Collector instructions│The following types of data can be ingested from OneLogin:Log collection
- Events: User logins, administrative operations, provisioning, and a list of all OneLogin event types
Directory
- Users: Lists of users.
- Groups: Lists of groups.
- Apps: Lists of apps.
For more information, see Ingest logs and data from OneLogin.
Link to content pack/integration details (onboarded prior to July 26, 2026)│The OneLogin content pack provides capabilities for simple customer authentication and streamlined workforce identity operations utilizing APIs. It includes one modeling rule for data normalization and the following integration:
- OneLogin Event Collector: Use this integration to gather simple customer authentication and streamlined workforce identity operations with the
onelogin-get-eventscommand.
Link to content pack/integration details (onboarded prior to July 26, 2026)│The OneLogin content pack provides capabilities for simple customer authentication and streamlined workforce identity operations utilizing APIs. It includes one modeling rule for data normalization and the following integration:
- OneLogin Event Collector: Use this integration to gather simple customer authentication and streamlined workforce identity operations with the
onelogin-get-eventscommand.
Link to connector (onboarded after July 26, 2026)│OneLoginLink to connector (onboarded after July 26, 2026)│OneLoginShow markdown source
@@ -1,10 +1,10 @@ # OneLogin You can configure collecting OneLogin logs and data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026): -| OneLogin vendor | Description | +| Collection Method | Description | | --------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Standard Collector overview | Forward logs and data to Cortex XSIAM from OneLogin via the OneLogin REST APIs using the OneLogin data source. | | Link to Standard Collector instructions | <p>The following types of data can be ingested from OneLogin:</p><ul><li><p>Log collection</p><ul><li>Events: User logins, administrative operations, provisioning, and a list of all OneLogin event types</li></ul></li><li><p>Directory</p><ul><li>Users: Lists of users.</li><li>Groups: Lists of groups.</li><li>Apps: Lists of apps.</li></ul></li></ul><p>For more information, see <a href="onelogin/ingest-logs-and-data-from-onelogin">Ingest logs and data from OneLogin</a>.</p> | | Link to content pack/integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/OneLogin">OneLogin</a> content pack provides capabilities for simple customer authentication and streamlined workforce identity operations utilizing APIs. It includes one modeling rule for data normalization and the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/one-login-event-collector">OneLogin Event Collector</a>: Use this integration to gather simple customer authentication and streamlined workforce identity operations with the <strong><code>onelogin-get-events</code></strong> command.</li></ul> | | Link to connector (onboarded after July 26, 2026) | [OneLogin](onelogin/onelogin) |
-
▸ ▾ Oracle Cloud Infrastructure modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/oracle/oracle-cloud-infrastructureRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,8 @@# Oracle Cloud Infrastructure# Oracle Cloud InfrastructureFollow a wizard to onboard your Oracle Cloud Infrastructure (OCI) environment. The OCI onboarding wizard is designed to facilitate the seamless setup of OCI data into Cortex XSIAM.Follow a wizard to onboard your Oracle Cloud Infrastructure (OCI) environment. The OCI onboarding wizard is designed to facilitate the seamless setup of OCI data into Cortex XSIAM.Oracle Cloud Infrastructure vendor│DescriptionCollection Method│Description| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Link to full configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XSIAM Premium license.│Onboard Oracle Cloud InfrastructureLink to full configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XSIAM Premium license.│Onboard Oracle Cloud InfrastructureLink to basic configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XSIAM NG SIEM, Cortex XSIAM Enterprise license, and Cortex XSIAM Enterprise+ licenses.│How to onboard Oracle Cloud Infrastructure with foundational configurationLink to basic configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XSIAM NG SIEM, Cortex XSIAM Enterprise license, and Cortex XSIAM Enterprise+ licenses.│How to onboard Oracle Cloud Infrastructure with foundational configurationShow markdown source
@@ -1,8 +1,8 @@ # Oracle Cloud Infrastructure Follow a wizard to onboard your Oracle Cloud Infrastructure (OCI) environment. The OCI onboarding wizard is designed to facilitate the seamless setup of OCI data into Cortex XSIAM. -| Oracle Cloud Infrastructure vendor | Description | +| Collection Method | Description | | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Link to full configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XSIAM Premium license. | [Onboard Oracle Cloud Infrastructure](../../cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/onboard-oracle-cloud-infrastructure) | | Link to basic configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XSIAM NG SIEM, Cortex XSIAM Enterprise license, and Cortex XSIAM Enterprise+ licenses. | [How to onboard Oracle Cloud Infrastructure with foundational configuration](../../cloud-service-provider-csp-onboarding/oracle-cloud-infrastructure-cloud-onboarding/how-to-onboard-oracle-cloud-infrastructure-with-foundational-configuration) |
-
▸ ▾ SentinelOne DeepVisibility modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sentinelone/sentinelone-deepvisibilityRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@# SentinelOne DeepVisibility# SentinelOne DeepVisibilityYou can configure collecting SentinelOne DeepVisibility raw EDR event data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):You can configure collecting SentinelOne DeepVisibility raw EDR event data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):SentinelOne DeepVisibility vendor│DescriptionCollection Method│Description| --------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || --------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Standard Collector overview│Forward raw EDR event data from SentinelOne DeepVisibility to Cortex XSIAM, streamed via Cloud Funnel to Amazon S3 using the SentinelOne - Deep Visibility data source.Standard Collector overview│Forward raw EDR event data from SentinelOne DeepVisibility to Cortex XSIAM, streamed via Cloud Funnel to Amazon S3 using the SentinelOne - Deep Visibility data source.Link to Standard Collector instructions│Ingest raw EDR events from SentinelOne DeepVisibilityLink to Standard Collector instructions│Ingest raw EDR events from SentinelOne DeepVisibilityLinks to content pack/integration instructions (onboarded prior to July 26, 2026)│The SentinelOne content pack provides capabilities for endpoint protection, allowing users to receive alerts, manage protection policies, search processes, and execute remediation actions on endpoints. The SentinelOne pack contains classifiers, issue fields, issue types, layouts, modeling rules, and playbooks. It also includes the following integrations:
- SentinelOne Activity and Alerts: Use this integration to fetch activities, threats, and issues from SentinelOne using the
sentinelone-get-eventscommand. - SentinelOne v2 (Partner Contribution): Use this integration to send requests to your management server and get responses with data pulled from agents or from the management database. It includes commands to connect, disconnect, shut down, and uninstall agents as well as get agent, threat, and site information.
Links to content pack/integration instructions (onboarded prior to July 26, 2026)│The SentinelOne content pack provides capabilities for endpoint protection, allowing users to receive alerts, manage protection policies, search processes, and execute remediation actions on endpoints. The SentinelOne pack contains classifiers, issue fields, issue types, layouts, modeling rules, and playbooks. It also includes the following integrations:
- SentinelOne Activity and Alerts: Use this integration to fetch activities, threats, and issues from SentinelOne using the
sentinelone-get-eventscommand. - SentinelOne v2 (Partner Contribution): Use this integration to send requests to your management server and get responses with data pulled from agents or from the management database. It includes commands to connect, disconnect, shut down, and uninstall agents as well as get agent, threat, and site information.
Link to connector (onboarded after July 26, 2026)│SentinelOneLink to connector (onboarded after July 26, 2026)│SentinelOneShow markdown source
@@ -1,10 +1,10 @@ # SentinelOne DeepVisibility You can configure collecting SentinelOne DeepVisibility raw EDR event data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026): -| SentinelOne DeepVisibility vendor | Description | +| Collection Method | Description | | --------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Standard Collector overview | Forward raw EDR event data from SentinelOne DeepVisibility to Cortex XSIAM, streamed via Cloud Funnel to Amazon S3 using the SentinelOne - Deep Visibility data source. | | Link to Standard Collector instructions | [Ingest raw EDR events from SentinelOne DeepVisibility](sentinelone-deepvisibility/ingest-raw-edr-events-from-sentinelone-deepvisibility) | | Links to content pack/integration instructions (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/SentinelOne">SentinelOne</a> content pack provides capabilities for endpoint protection, allowing users to receive alerts, manage protection policies, search processes, and execute remediation actions on endpoints. The SentinelOne pack contains classifiers, issue fields, issue types, layouts, modeling rules, and playbooks. It also includes the following integrations:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/sentinel-one-event-collector">SentinelOne Activity and Alerts</a>: Use this integration to fetch activities, threats, and issues from SentinelOne using the <strong><code>sentinelone-get-events</code></strong> command.</li><li><a href="https://xsoar.pan.dev/docs/reference/integrations/sentinel-one-v2">SentinelOne v2 (Partner Contribution)</a>: Use this integration to send requests to your management server and get responses with data pulled from agents or from the management database. It includes commands to connect, disconnect, shut down, and uninstall agents as well as get agent, threat, and site information.</li></ul> | | Link to connector (onboarded after July 26, 2026) | [SentinelOne](sentinelone) |
- SentinelOne Activity and Alerts: Use this integration to fetch activities, threats, and issues from SentinelOne using the
-
▸ ▾ ServiceNow CDMB modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/servicenow/servicenow-cdmbRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,9 +1,9 @@# ServiceNow CDMB# ServiceNow CDMBYou can configure collecting data from the ServiceNow CMDB database using a Standard Collector or connector (onboarded after July 26, 2026):You can configure collecting data from the ServiceNow CMDB database using a Standard Collector or connector (onboarded after July 26, 2026):ServiceNow CMDB vendor│DescriptionCollection Method│Description| ------------------------------------------------- | ----------------------------------------------------------------------------------------------------- || ------------------------------------------------- | ----------------------------------------------------------------------------------------------------- |Standard Collector overview│Forward logs from the ServiceNow CMDB database to Cortex XSIAM using the ServiceNow CMDB data source.Standard Collector overview│Forward logs from the ServiceNow CMDB database to Cortex XSIAM using the ServiceNow CMDB data source.Link to Standard Collector instructions│Ingest data from ServiceNow CMDBLink to Standard Collector instructions│Ingest data from ServiceNow CMDBLink to connector (onboarded after July 26, 2026)│ServiceNow Automation and CollectionLink to connector (onboarded after July 26, 2026)│ServiceNow Automation and CollectionShow markdown source
@@ -1,9 +1,9 @@ # ServiceNow CDMB You can configure collecting data from the ServiceNow CMDB database using a Standard Collector or connector (onboarded after July 26, 2026): -| ServiceNow CMDB vendor | Description | +| Collection Method | Description | | ------------------------------------------------- | ----------------------------------------------------------------------------------------------------- | | Standard Collector overview | Forward logs from the ServiceNow CMDB database to Cortex XSIAM using the ServiceNow CMDB data source. | | Link to Standard Collector instructions | [Ingest data from ServiceNow CMDB](servicenow-cdmb/ingest-data-from-servicenow-cmdb) | | Link to connector (onboarded after July 26, 2026) | [ServiceNow Automation and Collection](servicenow-automation-and-collection) |
-
▸ ▾ Workday modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/workdayRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,11 +1,11 @@# Workday# WorkdayYou can configure collecting Workday report data using a standard collector, content pack integration (onboarded prior to July 26, 2026), or connector:You can configure collecting Workday report data using a standard collector, content pack integration (onboarded prior to July 26, 2026), or connector:Workday vendor│DescriptionCollection Method│Description| ---------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ---------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Standard collector overview│Forward Workday report data to Cortex XSIAM using the Workday data source.Standard collector overview│Forward Workday report data to Cortex XSIAM using the Workday data source.Link to standard collector instructions│Ingest report data from WorkdayLink to standard collector instructions│Ingest report data from WorkdayLinks to content pack/integration details (onboarded prior to July 26, 2026)│The Workday content pack provides solutions for financial management, human resources, and planning, specifically supporting the collection and modeling of user activity audit logs and sign-on events. It contains classifiers, modeling rules, and parsing rules, as well as the following integrations:
- Workday Event Collector: Use this integration containing the
workday-get-activity-loggingcommand to get activity logs from Workday. It requires theWorkday Parsing RuleandWorkday Modeling Rulefor parsing and modeling ingested data. - Workday: Use this integration containing the
workday-list-workerscommand to return information for specific workers. - Workday IAM: Use this integration containing the
workday-iam-get-full-reportcommand to return report entries from Workday. It is part of the part of the IAM premium pack. - Workday Sign On Event Collector: Use this integration containing the
workday-get-sign-on-eventscommand to get sign-on logs from Workday. This command is used for developing/debugging and is to be used with caution, as it can create events, leading to events duplication and exceeding the API request limitation.
Links to content pack/integration details (onboarded prior to July 26, 2026)│The Workday content pack provides solutions for financial management, human resources, and planning, specifically supporting the collection and modeling of user activity audit logs and sign-on events. It contains classifiers, modeling rules, and parsing rules, as well as the following integrations:
- Workday Event Collector: Use this integration containing the
workday-get-activity-loggingcommand to get activity logs from Workday. It requires theWorkday Parsing RuleandWorkday Modeling Rulefor parsing and modeling ingested data. - Workday: Use this integration containing the
workday-list-workerscommand to return information for specific workers. - Workday IAM: Use this integration containing the
workday-iam-get-full-reportcommand to return report entries from Workday. It is part of the part of the IAM premium pack. - Workday Sign On Event Collector: Use this integration containing the
workday-get-sign-on-eventscommand to get sign-on logs from Workday. This command is used for developing/debugging and is to be used with caution, as it can create events, leading to events duplication and exceeding the API request limitation.
Link to connector│- Workday Automation and Collection (onboarded after July 26, 2026)
- Workday
Link to connector│- Workday Automation and Collection (onboarded after July 26, 2026)
- Workday
Show markdown source
@@ -1,11 +1,11 @@ # Workday You can configure collecting Workday report data using a standard collector, content pack integration (onboarded prior to July 26, 2026), or connector: -| Workday vendor | Description | +| Collection Method | Description | | ---------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Standard collector overview | Forward Workday report data to Cortex XSIAM using the Workday data source. | | Link to standard collector instructions | [Ingest report data from Workday](workday/ingest-report-data-from-workday) | | Links to content pack/integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/Workday">Workday</a> content pack provides solutions for financial management, human resources, and planning, specifically supporting the collection and modeling of user activity audit logs and sign-on events. It contains classifiers, modeling rules, and parsing rules, as well as the following integrations:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/workday-event-collector">Workday Event Collector</a>: Use this integration containing the <strong><code>workday-get-activity-logging</code></strong> command to get activity logs from Workday. It requires the <strong><code>Workday Parsing Rule</code></strong> and <strong><code>Workday Modeling Rule</code></strong> for parsing and modeling ingested data.</li><li><a href="https://xsoar.pan.dev/docs/reference/integrations/workday">Workday</a>: Use this integration containing the <strong><code>workday-list-workers</code></strong> command to return information for specific workers.</li><li><a href="https://xsoar.pan.dev/docs/reference/integrations/workday-iam">Workday IAM</a>: Use this integration containing the <strong><code>workday-iam-get-full-report</code></strong> command to return report entries from Workday. It is part of the part of the IAM premium pack.</li><li><a href="https://xsoar.pan.dev/docs/reference/integrations/workday-sign-on-event-collector">Workday Sign On Event Collector</a>: Use this integration containing the <strong><code>workday-get-sign-on-events</code></strong> command to get sign-on logs from Workday. This command is used for developing/debugging and is to be used with caution, as it can create events, leading to events duplication and exceeding the API request limitation.</li></ul> | | Link to connector | <ul><li><a href="workday/workday-automation-and-collection">Workday Automation and Collection</a> (onboarded after July 26, 2026)</li><li><a href="workday/workday">Workday</a></li></ul> |
- Workday Event Collector: Use this integration containing the
-
▸ ▾ Zscaler Internet Access modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/zscaler/zscaler-internet-accessRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,11 +1,11 @@# Zscaler Internet Access# Zscaler Internet AccessYou can configure collecting Zscaler Internet Access logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):You can configure collecting Zscaler Internet Access logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):Zscaler Internet Access vendor│DescriptionCollection Method│Description| ---------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ---------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Syslog Collector applet overview│Forward firewall and network logs to Cortex XSIAM from Zscaler Internet Access using the Broker VM Syslog Collector applet in a CEF format.Syslog Collector applet overview│Forward firewall and network logs to Cortex XSIAM from Zscaler Internet Access using the Broker VM Syslog Collector applet in a CEF format.Link to Syslog Collector applet instructions│Ingest logs from Zscaler Internet AccessLink to Syslog Collector applet instructions│Ingest logs from Zscaler Internet AccessLinks to content pack/integration details (onboarded prior to July 26, 2026)│The Zscaler Internet Access content pack provides Cloud security features, including managing URL and IP address policies, managing categories, sandbox reporting, and ingestion and normalization of Zscaler Internet Access (ZIA) logs into Cortex XSIAM via both VM-based NSS Feed and Cloud NSS Feed methods. It contains the
Zscaler Internet Access Modeling Rule, theZscaler ZIA Parsing Rule, and the Block Domain - Zscaler playbook. It also includes the following integration:- Zscaler Internet Access: Use this integration to manage URL and IP address allow lists and block lists, manage and update categories, retrieve Sandbox reports, and manage IP destination groups within a Zscaler session. It includes commands for blacklisting and unblacklisting URLs and IPs, managing categories (adding/removing URLs and IPs), retrieving categories, listing, creating, editing, and deleting IP destination groups, manually logging in and logging out, and activating configuration changes in Zscaler.
Links to content pack/integration details (onboarded prior to July 26, 2026)│The Zscaler Internet Access content pack provides Cloud security features, including managing URL and IP address policies, managing categories, sandbox reporting, and ingestion and normalization of Zscaler Internet Access (ZIA) logs into Cortex XSIAM via both VM-based NSS Feed and Cloud NSS Feed methods. It contains the
Zscaler Internet Access Modeling Rule, theZscaler ZIA Parsing Rule, and the Block Domain - Zscaler playbook. It also includes the following integration:- Zscaler Internet Access: Use this integration to manage URL and IP address allow lists and block lists, manage and update categories, retrieve Sandbox reports, and manage IP destination groups within a Zscaler session. It includes commands for blacklisting and unblacklisting URLs and IPs, managing categories (adding/removing URLs and IPs), retrieving categories, listing, creating, editing, and deleting IP destination groups, manually logging in and logging out, and activating configuration changes in Zscaler.
Link to connector (onboarded after July 26, 2026)│ZscalerLink to connector (onboarded after July 26, 2026)│ZscalerShow markdown source
@@ -1,11 +1,11 @@ # Zscaler Internet Access You can configure collecting Zscaler Internet Access logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026): -| Zscaler Internet Access vendor | Description | +| Collection Method | Description | | ---------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Syslog Collector applet overview | Forward firewall and network logs to Cortex XSIAM from Zscaler Internet Access using the Broker VM Syslog Collector applet in a CEF format. | | Link to Syslog Collector applet instructions | [Ingest logs from Zscaler Internet Access](../../generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/zscaler-internet-access/ingest-logs-from-zscaler-internet-access) | | Links to content pack/integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/Zscaler">Zscaler Internet Access</a> content pack provides Cloud security features, including managing URL and IP address policies, managing categories, sandbox reporting, and ingestion and normalization of Zscaler Internet Access (ZIA) logs into Cortex XSIAM via both VM-based NSS Feed and Cloud NSS Feed methods. It contains the <strong><code>Zscaler Internet Access Modeling Rule</code></strong>, the <strong><code>Zscaler ZIA Parsing Rule</code></strong>, and the Block Domain - Zscaler playbook. It also includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/zscaler">Zscaler Internet Access</a>: Use this integration to manage URL and IP address allow lists and block lists, manage and update categories, retrieve Sandbox reports, and manage IP destination groups within a Zscaler session. It includes commands for blacklisting and unblacklisting URLs and IPs, managing categories (adding/removing URLs and IPs), retrieving categories, listing, creating, editing, and deleting IP destination groups, manually logging in and logging out, and activating configuration changes in Zscaler.</li></ul> | | Link to connector (onboarded after July 26, 2026) | [Zscaler](zscaler) |
-
▸ ▾ Zscaler Private Access modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/zscaler/zscaler-private-accessRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,12 +1,12 @@# Zscaler Private Access# Zscaler Private AccessYou can configure collecting Zscaler Private Access logs using a Broker VM Syslog Collector applet or with a content pack integration (onboarded after July 26, 2026):You can configure collecting Zscaler Private Access logs using a Broker VM Syslog Collector applet or with a content pack integration (onboarded after July 26, 2026):Zscaler Private Access vendor│DescriptionCollection Method│Description| ----------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ----------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Syslog Collector applet overview│If you use Zscaler Private Access (ZPA) in your network as an alternative to VPNs, you can forward your network logs to Cortex XSIAM from Zscaler Private Access using the Broker VM Syslog Collector applet in a LEEF format.Syslog Collector applet overview│If you use Zscaler Private Access (ZPA) in your network as an alternative to VPNs, you can forward your network logs to Cortex XSIAM from Zscaler Private Access using the Broker VM Syslog Collector applet in a LEEF format.Link to Syslog Collector applet instructions│Ingest logs from Zscaler Private AccessLink to Syslog Collector applet instructions│Ingest logs from Zscaler Private AccessLink to content pack/integration instructions (onboarded after July 26, 2026)│The ZscalerZPA content pack provides data modeling capabilities for event logs ingested from the Zscaler Private Access (ZPA) service, which enables secure access to internal applications and services. It includes theZscaler Private Access Modeling Rule. Event collection relies on configuring the generic Syslog Collector on the Broker VM.Link to content pack/integration instructions (onboarded after July 26, 2026)│The ZscalerZPA content pack provides data modeling capabilities for event logs ingested from the Zscaler Private Access (ZPA) service, which enables secure access to internal applications and services. It includes theZscaler Private Access Modeling Rule. Event collection relies on configuring the generic Syslog Collector on the Broker VM.Show markdown source
@@ -1,12 +1,12 @@ # Zscaler Private Access You can configure collecting Zscaler Private Access logs using a Broker VM Syslog Collector applet or with a content pack integration (onboarded after July 26, 2026): -| Zscaler Private Access vendor | Description | +| Collection Method | Description | | ----------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Syslog Collector applet overview | If you use Zscaler Private Access (ZPA) in your network as an alternative to VPNs, you can forward your network logs to Cortex XSIAM from Zscaler Private Access using the Broker VM Syslog Collector applet in a LEEF format. | | Link to Syslog Collector applet instructions | [Ingest logs from Zscaler Private Access](../../generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/zscaler-private-access/ingest-logs-from-zscaler-private-access) | | Link to content pack/integration instructions (onboarded after July 26, 2026) | The [ZscalerZPA](https://cortex.marketplace.pan.dev/marketplace/details/ZscalerZPA) content pack provides data modeling capabilities for event logs ingested from the Zscaler Private Access (ZPA) service, which enables secure access to internal applications and services. It includes the **`Zscaler Private Access Modeling Rule`**. Event collection relies on configuring the generic Syslog Collector on the Broker VM. |
-
▸ ▾ parse_cef modified +10 −29
xsiam/configure-cortex-xsiam/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/ingest/parse_cefRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -6,44 +6,25 @@parse_cef()parse_cef()``````## Description## DescriptionThe `parse_cef()` function processes a CEF string and returns an object whose structure (key and \The `parse_cef()` function processes a CEF string and returns an object whose structure (key and \value pairs) is determined by the input parameters.value pairs) is determined by the input parameters.## Example## Example: Parsing CEF logs during ingestionThis example parses a CEF string to return a key and value pairs object based on the input parameters.The following example demonstrates how to use the `parse_cef` function within a parsing rule to process raw logs and store the resulting object in a specific dataset. This logic is configured in the `INGEST` section to execute as data is written to Cortex XSIAM.``````dataset = xdr_data[INGEST:vendor="test", product="parse_cef", target_dataset="test_parse_cef_raw", no_hit = keep]alter raw ="<14>Oct 2 10:06:18 PAN-PROD-APPSVC-EU-W4-FW01 CEF:0 Palo Alto Networks PAN-OS 8.1.15-h3 end TRAFFIC 1 rt=Oct 02 2022 17:06:18 GMT src=35.204.254.72 app=ssl proto=TCP in=8697 double=1.15 mac=B3-F5-10-ED-C4-EE ad.vd=root ad.subtype=forward pattern:test=test" alter raw ="<14>Oct 2 10:06:18 PAN-PROD-APPSVC-EU-W4-FW01 CEF:0 Palo Alto Networks PAN-OS 8.1.15-h3 end TRAFFIC 1 rt=Oct 02 2022 17:06:18 GMT src=35.204.254.72 app=ssl proto=TCP in=8697 double=1.15 mac=B3-F5-10-ED-C4-EE ad.vd=root ad.subtype=forward pattern:test=test" alter parsed = parse_cef(raw) alter parsed = parse_cef(raw) fields parsed fields parsed; ``````### Output results### Explanation of the rule components:The results displayed is an object with the following contents:* `INGEST` section: Defines the `vendor`, `product`, and the `target_dataset` where the parsed logs will be stored.* `alter raw`: In this rule context, this defines the source string to be parsed (simulating the `_raw_log` input).```* `parse_cef(raw)`: Processes the CEF string into a structured object containing key-value pairs."parsed": {* Semicolon (`;`): Required at the end of the rule to ensure proper compilation."ad.subtype": "forward","ad.vd": "root","app": "ssl","cefDeviceEventClassId": "end","cefDeviceProduct": "PAN-OS","cefDeviceVendor": "Palo Alto Networks","cefDeviceVersion": "8.1.15-h3","cefName": "TRAFFIC","cefSeverity": "1","cefVersion": "CEF:0","double": "1.15","in": "8697","mac": "B3-F5-10-ED-C4-EE","pattern:test": "test","proto": "6","rt": 1664730378000,"src": "35.204.254.72"}```Show markdown source
@@ -6,44 +6,25 @@ parse_cef() ``` ## Description The `parse_cef()` function processes a CEF string and returns an object whose structure (key and \ value pairs) is determined by the input parameters. -## Example +## Example: Parsing CEF logs during ingestion -This example parses a CEF string to return a key and value pairs object based on the input parameters. +The following example demonstrates how to use the `parse_cef` function within a parsing rule to process raw logs and store the resulting object in a specific dataset. This logic is configured in the `INGEST` section to execute as data is written to Cortex XSIAM. ``` -dataset = xdr_data -| alter raw ="<14>Oct 2 10:06:18 PAN-PROD-APPSVC-EU-W4-FW01 CEF:0|Palo Alto Networks|PAN-OS|8.1.15-h3|end|TRAFFIC|1|rt=Oct 02 2022 17:06:18 GMT src=35.204.254.72 app=ssl proto=TCP in=8697 double=1.15 mac=B3-F5-10-ED-C4-EE ad.vd=root ad.subtype=forward pattern:test=test" +[INGEST:vendor="test", product="parse_cef", target_dataset="test_parse_cef_raw", no_hit = keep] +alter raw ="<14>Oct 2 10:06:18 PAN-PROD-APPSVC-EU-W4-FW01 CEF:0|Palo Alto Networks|PAN-OS|8.1.15-h3|end|TRAFFIC|1|rt=Oct 02 2022 17:06:18 GMT src=35.204.254.72 app=ssl proto=TCP in=8697 double=1.15 mac=B3-F5-10-ED-C4-EE ad.vd=root ad.subtype=forward pattern:test=test" | alter parsed = parse_cef(raw) -| fields parsed +| fields parsed; ``` -### Output results +### Explanation of the rule components: -The results displayed is an object with the following contents: - -``` -"parsed": { - "ad.subtype": "forward", - "ad.vd": "root", - "app": "ssl", - "cefDeviceEventClassId": "end", - "cefDeviceProduct": "PAN-OS", - "cefDeviceVendor": "Palo Alto Networks", - "cefDeviceVersion": "8.1.15-h3", - "cefName": "TRAFFIC", - "cefSeverity": "1", - "cefVersion": "CEF:0", - "double": "1.15", - "in": "8697", - "mac": "B3-F5-10-ED-C4-EE", - "pattern:test": "test", - "proto": "6", - "rt": 1664730378000, - "src": "35.204.254.72" -} -``` +* `INGEST` section: Defines the `vendor`, `product`, and the `target_dataset` where the parsed logs will be stored. +* `alter raw`: In this rule context, this defines the source string to be parsed (simulating the `_raw_log` input). +* `parse_cef(raw)`: Processes the CEF string into a structured object containing key-value pairs. +* Semicolon (`;`): Required at the end of the rule to ensure proper compilation. -
▸ ▾ parse_json modified +0 −15
xsiam/configure-cortex-xsiam/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/ingest/parse_jsonRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -5,23 +5,8 @@``````parse_json()parse_json()``````## Description## DescriptionTheparse_json()function processes a JSON string and returns an object whose structure (key and
\Theparse_json()function processes a JSON string and returns an object whose structure (key and
\value pairs) is determined by the input parameters.value pairs) is determined by the input parameters.## ExampleThis example parses a JSON string to return a key and value pairs object based on the input parameters.```dataset = xdr_data| alter json_string = "{'a':'b'}"| alter result = parse_json(json_string)| fields result```### Output resultsThe results return an object with key 'a' having value 'b'.Show markdown source
@@ -5,23 +5,8 @@ ``` parse_json() ``` ## Description The `parse_json()` function processes a JSON string and returns an object whose structure (key and \ value pairs) is determined by the input parameters. - -## Example - -This example parses a JSON string to return a key and value pairs object based on the input parameters. - -``` -dataset = xdr_data -| alter json_string = "{'a':'b'}" -| alter result = parse_json(json_string) -| fields result -``` - -### Output results - -The results return an object with key 'a' having value 'b'. -
▸ ▾ Processes protected by exploit security policy modified +10 −10
xsiam/protect-your-endpoints/endpoint-security/endpoint-protection/processes-protected-by-exploit-security-policyRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,22 +1,22 @@# Processes protected by exploit security policy# Processes protected by exploit security policyBy default, your exploit security profile protects endpoints from attack techniques that target specific processes. Each exploit protection capability protects a different set of processes that Palo Alto Networks researchers determine are susceptible to attack. The following tables display the processes that are protected by each exploit protection capability for each operating system.By default, your exploit security profile protects endpoints from attack techniques that target specific processes. Each exploit protection capability protects a different set of processes that Palo Alto Networks researchers determine are susceptible to attack. The following tables display the processes that are protected by each exploit protection capability for each operating system.Windows processes protected by exploit security policy││Windows processes protected by exploit security policy││| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ || ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Browser exploits protection││Browser exploits protection││- [updated version of Adobe Flash Player for Firefox installed on endpoint]
- browser_broker.exe
- chrome.exe
- firefox.exe
- flashutil_activex.exe
- iexplore.exe
- microsoftedge.exe
- microsoftedgecp.exe
- opera_plugin_wrapper.exe
- opera.exe
- plugin-container.exe
- safari.exe
- webkit2webprocess.exe
- [updated version of Adobe Flash Player for Firefox installed on endpoint]
- browser_broker.exe
- chrome.exe
- firefox.exe
- flashutil_activex.exe
- iexplore.exe
- microsoftedge.exe
- microsoftedgecp.exe
- opera_plugin_wrapper.exe
- opera.exe
- plugin-container.exe
- safari.exe
- webkit2webprocess.exe
Logical exploits protection││Logical exploits protection││- cliconfg.exe
- dism.exe
- dllhost.exe
- excel.exe
- migwiz.exe
- mmc.exe
- powerpnt.exe
- sysprep.exe
- winword.exe
- cliconfg.exe
- dism.exe
- dllhost.exe
- excel.exe
- migwiz.exe
- mmc.exe
- powerpnt.exe
- sysprep.exe
- winword.exe
Known vulnerable processes protection││Known vulnerable processes protection││- 7z.exe
- 7zfm.exe
- 7zg.exe
- acrobat.exe
- acrord32.exe
- acrord32info.exe
- allplayer.exe
- applemobiledeviceservice.exe
- apwebgrb.exe
- armsvc.exe
- blazehdtv.exe
- bsplayer.exe
- cmd.exe
- eqnedt32.exe
- excel.exe
- flashfxp.exe
- fltldr.exe
- fontdrvhost.exe
- foxit reader.exe
- foxitreader.exe
- groovemonitor.exe
- hxmail.exe
- i_view32.exe
- infopath.exe
- ipodservice.exe
- itunes.exe
- ituneshelper.exe
- journal.exe
- jqs.exe
- microsoft.photos.exe
- msaccess.exe
- mspub.exe
- mstsc.exe
- nginx.exe
- notepad++.exe
- nslookup.exe
- outlook.exe
- powerpnt.exe
- pptview.exe
- qttask.exe
- quicktimeplayer.exe
- rar.exe
- reader_sl.exe
- realconverter.exe
- realplay.exe
- realsched.exe
- skype.exe
- skypeapp.exe
- skypehost.exe
- SLMail.exe
- soffice.exe
- telnet.exe
- unrar.exe
- vboxservice.exe
- vboxsvc.exe
- vboxtray.exe
- video.ui.exe
- visio.exe
- vlc.exe
- vmware-authd.exe
- vmware-hostd.exe
- vmware-vmx.exe
- vpreview.exe
- vprintproxy.exe
- wab.exe
- w3wp.exe
- winrar.exe
- winword.exe
- wireshark.exe
- wmplayer.exe
- wmpnetwk.exe
- xpsrchvw.exe
- 7z.exe
- 7zfm.exe
- 7zg.exe
- acrobat.exe
- acrord32.exe
- acrord32info.exe
- allplayer.exe
- applemobiledeviceservice.exe
- apwebgrb.exe
- armsvc.exe
- blazehdtv.exe
- bsplayer.exe
- cmd.exe
- eqnedt32.exe
- excel.exe
- flashfxp.exe
- fltldr.exe
- fontdrvhost.exe
- foxit reader.exe
- foxitreader.exe
- groovemonitor.exe
- hxmail.exe
- i_view32.exe
- infopath.exe
- ipodservice.exe
- itunes.exe
- ituneshelper.exe
- journal.exe
- jqs.exe
- microsoft.photos.exe
- msaccess.exe
- mspub.exe
- mstsc.exe
- nginx.exe
- notepad++.exe
- nslookup.exe
- outlook.exe
- powerpnt.exe
- pptview.exe
- qttask.exe
- quicktimeplayer.exe
- rar.exe
- reader_sl.exe
- realconverter.exe
- realplay.exe
- realsched.exe
- skype.exe
- skypeapp.exe
- skypehost.exe
- SLMail.exe
- soffice.exe
- sqlservr.exe
- telnet.exe
- unrar.exe
- vboxservice.exe
- vboxsvc.exe
- vboxtray.exe
- video.ui.exe
- visio.exe
- vlc.exe
- vmware-authd.exe
- vmware-hostd.exe
- vmware-vmx.exe
- vpreview.exe
- vprintproxy.exe
- wab.exe
- w3wp.exe
- winrar.exe
- winword.exe
- wireshark.exe
- wmplayer.exe
- wmpnetwk.exe
- xpsrchvw.exe
Operating system exploit protection││Operating system exploit protection││- ctfmon.exe
- dllhost.exe
- dns.exe
- lsass.exe
- msmpeng.exe
- runtimebroker.exe
- spoolsv.exe
- svchost.exe
- taskeng.exe
- taskhost.exe
- wmiprvse.exe
- wmiprvse.exe
- wwahost.exe
- ctfmon.exe
- dllhost.exe
- dns.exe
- lsass.exe
- msmpeng.exe
- runtimebroker.exe
- spoolsv.exe
- svchost.exe
- taskeng.exe
- taskhost.exe
- wmiprvse.exe
- wmiprvse.exe
- wwahost.exe
Mac processes protected by exploit security policy││Mac processes protected by exploit security policy││| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Browser exploits protection││Browser exploits protection││- com.apple.safariservices
- com.apple.webkit.plugin
- com.apple.webkit.plugin.64
- com.apple.webkit.webcontent
- firefox
- firefox-bin
- google chrome helper
- google chrome
- plugin-container
- safari
- seamonkey
- com.apple.safariservices
- com.apple.webkit.plugin
- com.apple.webkit.plugin.64
- com.apple.webkit.webcontent
- firefox
- firefox-bin
- google chrome helper
- google chrome
- plugin-container
- safari
- seamonkey
Logical exploits protection││Logical exploits protection││- adobereader
- app drive for google drive
- app drop for dropbox
- app for dropbox
- app for facebook
- app for google drive
- app for googledocs
- app for instagram
- app for linkedin
- app for youtube
- com.apple.safariservices
- com.apple.webkit.plugin
- com.apple.webkit.plugin.64
- com.apple.webkit.webcontent
- document writer
- firefox
- firefox-bin
- google chrome helper
- google chrome
- itunes helper
- itunes
- mail+ for yahoo
- microsoft excel
- microsoft outlook
- microsoft powerpoint
- microsoft remote desktop
- microsoft word
- miniwriterfree
- parallels client
- pdf reader pro free
- pdf reader x
- plugin-container
- quicktime player
- safari
- seamonkey
- slack
- sonicwall mobile connect
- textwrangler
- vlc
- vmware fusion services
- vmware fusion
- vpn shield
- winmail.dat file viewer
- adobereader
- app drive for google drive
- app drop for dropbox
- app for dropbox
- app for facebook
- app for google drive
- app for googledocs
- app for instagram
- app for linkedin
- app for youtube
- com.apple.safariservices
- com.apple.webkit.plugin
- com.apple.webkit.plugin.64
- com.apple.webkit.webcontent
- document writer
- firefox
- firefox-bin
- google chrome helper
- google chrome
- itunes helper
- itunes
- mail+ for yahoo
- microsoft excel
- microsoft outlook
- microsoft powerpoint
- microsoft remote desktop
- microsoft word
- miniwriterfree
- parallels client
- pdf reader pro free
- pdf reader x
- plugin-container
- quicktime player
- safari
- seamonkey
- slack
- sonicwall mobile connect
- textwrangler
- vlc
- vmware fusion services
- vmware fusion
- vpn shield
- winmail.dat file viewer
Known vulnerable processes protection││Known vulnerable processes protection││Show markdown source
@@ -1,22 +1,22 @@ # Processes protected by exploit security policy By default, your exploit security profile protects endpoints from attack techniques that target specific processes. Each exploit protection capability protects a different set of processes that Palo Alto Networks researchers determine are susceptible to attack. The following tables display the processes that are protected by each exploit protection capability for each operating system. -| Windows processes protected by exploit security policy | | | -| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -| **Browser exploits protection** | | | -| <ul><li>[updated version of Adobe Flash Player for Firefox installed on endpoint]</li><li>browser_broker.exe</li><li>chrome.exe</li><li>firefox.exe</li></ul> | <ul><li>flashutil_activex.exe</li><li>iexplore.exe</li><li>microsoftedge.exe</li><li>microsoftedgecp.exe</li><li>opera_plugin_wrapper.exe</li></ul> | <ul><li>opera.exe</li><li>plugin-container.exe</li><li>safari.exe</li><li>webkit2webprocess.exe</li></ul> | -| **Logical exploits protection** | | | -| <ul><li>cliconfg.exe</li><li>dism.exe</li><li>dllhost.exe</li></ul> | <ul><li>excel.exe</li><li>migwiz.exe</li><li>mmc.exe</li></ul> | <ul><li>powerpnt.exe</li><li>sysprep.exe</li><li>winword.exe</li></ul> | -| **Known vulnerable processes protection** | | | -| <ul><li>7z.exe</li><li>7zfm.exe</li><li>7zg.exe</li><li>acrobat.exe</li><li>acrord32.exe</li><li>acrord32info.exe</li><li>allplayer.exe</li><li>applemobiledeviceservice.exe</li><li>apwebgrb.exe</li><li>armsvc.exe</li><li>blazehdtv.exe</li><li>bsplayer.exe</li><li>cmd.exe</li><li>eqnedt32.exe</li><li>excel.exe</li><li>flashfxp.exe</li><li>fltldr.exe</li><li>fontdrvhost.exe</li><li>foxit reader.exe</li><li>foxitreader.exe</li><li>groovemonitor.exe</li><li>hxmail.exe</li><li>i_view32.exe</li><li>infopath.exe</li></ul> | <ul><li>ipodservice.exe</li><li>itunes.exe</li><li>ituneshelper.exe</li><li>journal.exe</li><li>jqs.exe</li><li>microsoft.photos.exe</li><li>msaccess.exe</li><li>mspub.exe</li><li>mstsc.exe</li><li>nginx.exe</li><li>notepad++.exe</li><li>nslookup.exe</li><li>outlook.exe</li><li>powerpnt.exe</li><li>pptview.exe</li><li>qttask.exe</li><li>quicktimeplayer.exe</li><li>rar.exe</li><li>reader_sl.exe</li><li>realconverter.exe</li><li>realplay.exe</li><li>realsched.exe</li><li>skype.exe</li><li>skypeapp.exe</li><li>skypehost.exe</li></ul> | <ul><li>SLMail.exe</li><li>soffice.exe</li><li>telnet.exe</li><li>unrar.exe</li><li>vboxservice.exe</li><li>vboxsvc.exe</li><li>vboxtray.exe</li><li>video.ui.exe</li><li>visio.exe</li><li>vlc.exe</li><li>vmware-authd.exe</li><li>vmware-hostd.exe</li><li>vmware-vmx.exe</li><li>vpreview.exe</li><li>vprintproxy.exe</li><li>wab.exe</li><li>w3wp.exe</li><li>winrar.exe</li><li>winword.exe</li><li>wireshark.exe</li><li>wmplayer.exe</li><li>wmpnetwk.exe</li><li>xpsrchvw.exe</li></ul> | -| **Operating system exploit protection** | | | -| <ul><li>ctfmon.exe</li><li>dllhost.exe</li><li>dns.exe</li><li>lsass.exe</li><li>msmpeng.exe</li></ul> | <ul><li>runtimebroker.exe</li><li>spoolsv.exe</li><li>svchost.exe</li><li>taskeng.exe</li></ul> | <ul><li>taskhost.exe</li><li>wmiprvse.exe</li><li>wmiprvse.exe</li><li>wwahost.exe</li></ul> | +| Windows processes protected by exploit security policy | | | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| **Browser exploits protection** | | | +| <ul><li>[updated version of Adobe Flash Player for Firefox installed on endpoint]</li><li>browser_broker.exe</li><li>chrome.exe</li><li>firefox.exe</li></ul> | <ul><li>flashutil_activex.exe</li><li>iexplore.exe</li><li>microsoftedge.exe</li><li>microsoftedgecp.exe</li><li>opera_plugin_wrapper.exe</li></ul> | <ul><li>opera.exe</li><li>plugin-container.exe</li><li>safari.exe</li><li>webkit2webprocess.exe</li></ul> | +| **Logical exploits protection** | | | +| <ul><li>cliconfg.exe</li><li>dism.exe</li><li>dllhost.exe</li></ul> | <ul><li>excel.exe</li><li>migwiz.exe</li><li>mmc.exe</li></ul> | <ul><li>powerpnt.exe</li><li>sysprep.exe</li><li>winword.exe</li></ul> | +| **Known vulnerable processes protection** | | | +| <ul><li>7z.exe</li><li>7zfm.exe</li><li>7zg.exe</li><li>acrobat.exe</li><li>acrord32.exe</li><li>acrord32info.exe</li><li>allplayer.exe</li><li>applemobiledeviceservice.exe</li><li>apwebgrb.exe</li><li>armsvc.exe</li><li>blazehdtv.exe</li><li>bsplayer.exe</li><li>cmd.exe</li><li>eqnedt32.exe</li><li>excel.exe</li><li>flashfxp.exe</li><li>fltldr.exe</li><li>fontdrvhost.exe</li><li>foxit reader.exe</li><li>foxitreader.exe</li><li>groovemonitor.exe</li><li>hxmail.exe</li><li>i_view32.exe</li><li>infopath.exe</li></ul> | <ul><li>ipodservice.exe</li><li>itunes.exe</li><li>ituneshelper.exe</li><li>journal.exe</li><li>jqs.exe</li><li>microsoft.photos.exe</li><li>msaccess.exe</li><li>mspub.exe</li><li>mstsc.exe</li><li>nginx.exe</li><li>notepad++.exe</li><li>nslookup.exe</li><li>outlook.exe</li><li>powerpnt.exe</li><li>pptview.exe</li><li>qttask.exe</li><li>quicktimeplayer.exe</li><li>rar.exe</li><li>reader_sl.exe</li><li>realconverter.exe</li><li>realplay.exe</li><li>realsched.exe</li><li>skype.exe</li><li>skypeapp.exe</li><li>skypehost.exe</li></ul> | <ul><li>SLMail.exe</li><li>soffice.exe</li><li>sqlservr.exe</li><li>telnet.exe</li><li>unrar.exe</li><li>vboxservice.exe</li><li>vboxsvc.exe</li><li>vboxtray.exe</li><li>video.ui.exe</li><li>visio.exe</li><li>vlc.exe</li><li>vmware-authd.exe</li><li>vmware-hostd.exe</li><li>vmware-vmx.exe</li><li>vpreview.exe</li><li>vprintproxy.exe</li><li>wab.exe</li><li>w3wp.exe</li><li>winrar.exe</li><li>winword.exe</li><li>wireshark.exe</li><li>wmplayer.exe</li><li>wmpnetwk.exe</li><li>xpsrchvw.exe</li></ul> | +| **Operating system exploit protection** | | | +| <ul><li>ctfmon.exe</li><li>dllhost.exe</li><li>dns.exe</li><li>lsass.exe</li><li>msmpeng.exe</li></ul> | <ul><li>runtimebroker.exe</li><li>spoolsv.exe</li><li>svchost.exe</li><li>taskeng.exe</li></ul> | <ul><li>taskhost.exe</li><li>wmiprvse.exe</li><li>wmiprvse.exe</li><li>wwahost.exe</li></ul> | | Mac processes protected by exploit security policy | | | | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Browser exploits protection** | | | | <ul><li>com.apple.safariservices</li><li>com.apple.webkit.plugin</li><li>com.apple.webkit.plugin.64</li><li>com.apple.webkit.webcontent</li></ul> | <ul><li>firefox</li><li>firefox-bin</li><li>google chrome helper</li><li>google chrome</li></ul> | <ul><li>plugin-container</li><li>safari</li><li>seamonkey</li></ul> | | **Logical exploits protection** | | | | <ul><li>adobereader</li><li>app drive for google drive</li><li>app drop for dropbox</li><li>app for dropbox</li><li>app for facebook</li><li>app for google drive</li><li>app for googledocs</li><li>app for instagram</li><li>app for linkedin</li><li>app for youtube</li><li>com.apple.safariservices</li><li>com.apple.webkit.plugin</li><li>com.apple.webkit.plugin.64</li><li>com.apple.webkit.webcontent</li><li>document writer</li></ul> | <ul><li>firefox</li><li>firefox-bin</li><li>google chrome helper</li><li>google chrome</li><li>itunes helper</li><li>itunes</li><li>mail+ for yahoo</li><li>microsoft excel</li><li>microsoft outlook</li><li>microsoft powerpoint</li><li>microsoft remote desktop</li><li>microsoft word</li><li>miniwriterfree</li><li>parallels client</li><li>pdf reader pro free</li></ul> | <ul><li>pdf reader x</li><li>plugin-container</li><li>quicktime player</li><li>safari</li><li>seamonkey</li><li>slack</li><li>sonicwall mobile connect</li><li>textwrangler</li><li>vlc</li><li>vmware fusion services</li><li>vmware fusion</li><li>vpn shield</li><li>winmail.dat file viewer</li></ul> | | **Known vulnerable processes protection** | | |
-
▸ ▾ Host firewall for macOS modified +2 −2
xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/host-firewall/host-firewall-for-macosRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -11,17 +11,17 @@ If you want to apply location-based host firewall rules, you must first enable n### Add a new host firewall profile### Add a new host firewall profileConfigure host firewall profiles that contain one or more rules groups. The groups are enforced according to their order of appearance within the profile, from top to bottom (and within each group, the rules are also enforced from top to bottom). You can also configure profiles based on the device location within your internal network. When you edit, re-prioritize, disable, or delete a rules group from a profile, the change takes effect on the next heartbeat in all policies where this profile is included.Configure host firewall profiles that contain one or more rules groups. The groups are enforced according to their order of appearance within the profile, from top to bottom (and within each group, the rules are also enforced from top to bottom). You can also configure profiles based on the device location within your internal network. When you edit, re-prioritize, disable, or delete a rules group from a profile, the change takes effect on the next heartbeat in all policies where this profile is included.hint infohint infoRules that were created on macOS 10 and Cortex XDR agent 7.5 and prior are managed only in the Legacy Host Firewall Rules and do not appear in the Rule Groups tables.Rules that were created on macOS 10 and Cortex XDR agent 7.5 and prior are managed only in the Legacy Host Firewall Rules and do not appear in the Rule Groups tables.endhintendhint1. From Inventory → Endpoints → Policy Management → Extensions Profiles → Profiles, select + New Profile or Import from File. Select the Platform and click Host Firewall → Next.1. From Inventory → Endpoints → Policy Management → Extensions Profiles → Profiles, select +New Profile or Import from File. Select the Platform and click Host Firewall → Next.2. Fill-in the General Information for the new profile.2. Fill-in the General Information for the new profile.Assign a Profile Name and optional description to the profile.Assign a Profile Name and optional description to the profile.3. Define your Report Settings.3. Define your Report Settings.When the profile operates in report mode, Cortex XSIAM overrides all rules set to Block traffic. Instead, the traffic is allowed to go through, and the enforcement event is reported as Override Block. You can configure a profile in report mode if you need for example to test new block rules before you actually apply them.When the profile operates in report mode, Cortex XSIAM overrides all rules set to Block traffic. Instead, the traffic is allowed to go through, and the enforcement event is reported as Override Block. You can configure a profile in report mode if you need for example to test new block rules before you actually apply them.4. Configure Internal and External Rule Groups.4. Configure Internal and External Rule Groups.@@ -95,11 +95,11 @@ After you define the required host firewall profiles, configure the Protection P4. Save the policy hierarchy.4. Save the policy hierarchy.After the policy is saved and applied to the agents, Cortex XDR enforces the host firewall policies on your environment.After the policy is saved and applied to the agents, Cortex XDR enforces the host firewall policies on your environment.### Monitor the host firewall activity on your endpoint### Monitor the host firewall activity on your endpointTo view only the communication events on the endpoint to which the Cortex XDR host firewall rules were applied, you can run theCytool firewall showcommand.To view only the communication events on the endpoint to which the Cortex XDR host firewall rules were applied, you can run theCytool firewall showcommand.Additionally, to monitor the communication on your macOS endpoint, you can use the following operating system utilities: From the endpoint System Preferences → Security and Privacy → Firewall → Firewall options, you can view the list of blocked and allowed applications in the firewall. The Cortex XSIAM host firewall blocks only incoming communications on Mac endpoints, still allowing outbound communication initiated from the endpoint.Additionally, to monitor the communication on your macOS endpoint, you can use the following operating system utilities: From the endpoint System Preferences → Security and Privacy → Firewall → Firewall options, you can view the list of blocked and allowed applications in the firewall. The Cortex XSIAM host firewall can be defined to block incoming communications on Mac endpoints, while still allowing outbound communication initiated from the endpoint. To restrict outgoing traffic, you can create specific rules to block targeted outbound connections as needed.
Show markdown source
@@ -11,17 +11,17 @@ If you want to apply location-based host firewall rules, you must first enable n ### Add a new host firewall profile Configure host firewall profiles that contain one or more rules groups. The groups are enforced according to their order of appearance within the profile, from top to bottom (and within each group, the rules are also enforced from top to bottom). You can also configure profiles based on the device location within your internal network. When you edit, re-prioritize, disable, or delete a rules group from a profile, the change takes effect on the next heartbeat in all policies where this profile is included. {% hint style="info" %} Rules that were created on macOS 10 and Cortex XDR agent 7.5 and prior are managed only in the Legacy Host Firewall Rules and do not appear in the Rule Groups tables. {% endhint %} -1. From Inventory → Endpoints → Policy Management → Extensions Profiles → Profiles, select + New Profile or Import from File. Select the Platform and click Host Firewall → Next. +1. From Inventory → Endpoints → Policy Management → Extensions Profiles → Profiles, select +New Profile or Import from File. Select the Platform and click Host Firewall → Next. 2. Fill-in the General Information for the new profile. Assign a Profile Name and optional description to the profile. 3. Define your Report Settings. When the profile operates in report mode, Cortex XSIAM overrides all rules set to Block traffic. Instead, the traffic is allowed to go through, and the enforcement event is reported as Override Block. You can configure a profile in report mode if you need for example to test new block rules before you actually apply them. 4. Configure Internal and External Rule Groups. @@ -95,11 +95,11 @@ After you define the required host firewall profiles, configure the Protection P 4. Save the policy hierarchy. After the policy is saved and applied to the agents, Cortex XDR enforces the host firewall policies on your environment. ### Monitor the host firewall activity on your endpoint To view only the communication events on the endpoint to which the Cortex XDR host firewall rules were applied, you can run the `Cytool firewall show` command. -Additionally, to monitor the communication on your macOS endpoint, you can use the following operating system utilities: From the endpoint System Preferences → Security and Privacy → Firewall → Firewall options, you can view the list of blocked and allowed applications in the firewall. The Cortex XSIAM host firewall blocks only incoming communications on Mac endpoints, still allowing outbound communication initiated from the endpoint. +Additionally, to monitor the communication on your macOS endpoint, you can use the following operating system utilities: From the endpoint System Preferences → Security and Privacy → Firewall → Firewall options, you can view the list of blocked and allowed applications in the firewall. The Cortex XSIAM host firewall can be defined to block incoming communications on Mac endpoints, while still allowing outbound communication initiated from the endpoint. To restrict outgoing traffic, you can create specific rules to block targeted outbound connections as needed. <br>