To extend visibility, Cortex XDR can receive Syslog from
additional vendors that use CEF or LEEF formatted over Syslog (TLS
not supported).
Ingesting
logs and data requires a Cortex XDR Pro per TB license.
Cortex
XDR can receive Syslog from a variety of supported vendors (see External Data Ingestion Vendor Support). In addition, Cortex
XDR can receive Syslog from additional vendors that use CEF or LEEF
formatted over Syslog (TLS not supported).
After Cortex XDR
begins receiving logs from the third-party source, Cortex XDR automatically
parses the logs in LEEF format and creates a dataset with the name
<vendor>
_
<product>
_raw
.
You can then use XQL Search queries to view logs and create new
IOC or BIOC rules.