Cortex XDR forwards the management audit
log to external data sources according to the following formats.
Management audit log notifications
are forward to email accounts.
Management Audit logs forwarded
to a Syslog server are sent in a
CEF format RF 5425 according
to the following mapping:
<9>: PRI (considered a prioirty field)1: version number2020-03-22T07:55:07.964311Z: timestamp of when alert/log was sentcortexxdr: host name
HEADER/Vendor="Palo Alto Networks" (as a constant string)HEADER/Device Product="Cortex XDR" (as a constant string)HEADER/Device Version= Cortex XDR version (2.0/2.1....)HEADER/Severity=informationalHEADER/Device Event Class ID="Management Audit Logs" (as a constant string)HEADER/name = type
end=timestampsuser=user namecat=categorymsg=descriptiondeviceHostName = host nameexternalId = idcs1=emailcs1Label="email" (as a constant string)cs2=subtypecs2Label="subtype" (as a constant string)cs3=resultcs3Label="result" (as a constant string)cs4=reasoncs4Label="reason" (as a constant string)