Ingest Report Data from Workday
Extend Cortex® XDR™ visibility into reports data from Workday.
Ingesting logs and data requires a Cortex XDR Pro per TB license.
To receive Workday report data, you must first configure data collection from Workday using a Workday custom report to ingest the appropriate data. This is configured by setting up a Workday Collector in Cortex® XDR™ and configuring report data collection via this Workday custom report that you set up.
As soon as Cortex XDR begins receiving data, the app automatically creates a Workday XQL dataset (
workday_workday_raw). You can then use XQL Search queries to view the data and create new Correlation Rules. In addition, Cortex XDR adds the workday fields next to each user in the Key Assets list in the Incident View, and in the User node in the Causality View of Identity Analytics alerts.
Any user with permissions to view alerts and incidents can view the Workday data.
You can only configure a single Workday Collector, which is automatically configured to run the report every 6 hours. You can always use the
Sync Nowoption to run the report whenever you want.
Complete the following tasks before you begin configuring Cortex XDR to receive report data from Workday.
- Create an Integration System User that is designated to access the custom report from Workday for data collection in Cortex XDR.
- Create an Integration System Security Group for the Integration System User created in Step 1 for accessing the report. When setting this group ensure to define the following.
- Type of Tenanted Security Group—Select eitherIntegration System Security Group (Constrained)orIntegration System Security Group (Unconstrained)depending on how your data is configured. For more information, see the Workday documentation.
- Integration System User—Select the user that you defined in step 1 for accessing the custom report.
- Create the Workday credentials for the Integration System User created in Step 1 so that the username and password can be used to access the report in Cortex XDR. Record these credentials as you will need them when configuring the Workday Collector in Cortex XDR.
For more information on completing any of these prerequisite steps, see the Workday documentation.
Configure Cortex XDR to receive report data from Workday.
- Configure a Workday custom report to use for data collection.
- Login to the Workday Resource Center.
- In search field, specifyCreate Custom Reportto open the wizard.
- Configure the followingCreate Custom Reportsettings.
- Report Name—Specify the name of the report.
- Report Detailssection.
- Report Type—SelectAdvanced. When you select this option, theEnable As Web Servicecheckbox is displayed.
- Enable As Web Service—Select this checkbox, so that you will be able to generate a URL of the report to configure in Cortex XDR.
- Data Sourcesection.
- Optimized for Performance—Select whether the data should be optimized for performance. The way this checkbox is configured determines theData Sourceoptions available to choose from.
- Date Source—Select the applicable data source containing the data that is used to configure data collection from Workday to Cortex XDR.
- ClickOK, and configure the followingAdditional Infosettings.TheAdditional Infotable in theColumnstab is where you can perform the following:
TheBusiness Objectchanges depending on theData Sourceselected.For the incident and card views in Cortex XDR, map the following fields in the table by selecting the applicableFieldthat contains the data representing the Cortex XDR field name as provided below that should be added to theColumn Heading Override XML Alias. For example, forfull_name, select the applicableFieldfrom theBusiness Objectdefined that contains the full name of the user and in theColumn Heading Override XML Aliasspecifyfull_nameto map the setFieldto the Cortex XDR field name.
- For the incident and card views in Cortex XDR, map the required fields from theData Sourceconfigured by selecting the applicableFieldthat you want to map to the Cortex XDR field name required for data collection in theColumn Heading Override XML Aliascolumn.
- (Optional) You can map any additional fields from theData Sourceconfigured that you want to be able to query in XQL Search using theworkday_workday_rawdataset. This is configured by selecting the applicableFieldand leaving the default field name that is displayed in theColumn Heading Override XML Aliascolumn. This default field name is what is used in XQL Search and the dataset to view and query the data.
- (Optional) Filter out any employees that you do not want included in theFiltertab.
- Share access to the report with the designated Integration System User that you created by setting the following settings in theSharetab.
- Report Definition Sharing Options—SelectShare with specific authorized groups and users.
- Ensure that the followingWeb Services Optionssettings in theAdvancedtab are configured.Here is an example of the configured settings, where theWeb Service API VersionandNamespaceare automatically populated and dependent on your report.
- (Optional)Testthe report to ensure all the fields are populated.
- Get the URL for the report.
- In the related actions menu, select.ActionsWeb ServiceView URLs
- Scroll down to theJSONsection.
- Hover over theJSONlink and click the icon, which open a new tab in your browser with the URL for the report. You need to use the designated user credentials to open the report.
- Copy the URL for the report and record them somewhere as this URL needs to be provided when setting up the Workday Collector in Cortex XDR.
- Complete the report by clickingDone.
- Configure the Workday collection in Cortex XDR.
- Select.Settings ( )ConfigurationsData CollectionCollection Integrations
- In the Workday Collector configuration, click theherelink to begin a new configuration.
- Set the following parameters.
- Name—Specify the name for the Workday Collector that is displayed in Cortex XDR.
- ClickTestto validate access, and then clickEnable.A notification appears confirming that the Workday Collector was saved successfully, and closes on its own after a few seconds.Once report data starts to come in, a green check mark appears underneath theWorkdayCollector configuration with the data and time that the data was last synced.
- (Optional) Manage your Workday Collector.After you enable the Workday Collector, you can make additional changes as needed. To modify a configuration, select any of the following options.
- Editthe Workday Collector settings.
- Disablethe Workday Collector.
- Deletethe Workday Collector.
- Sync Nowto run the report to get the latest report data. The report is run automatically every 6 hours, but you can always get the latest data as needed.
- After Cortex XDR begins receiving report data from Workday, you can use the XQL Search to search for logs in the new dataset (workday_workday_raw).
Recommended For You
Recommended videos not found.