Configure external applications for forwarding - Configure external applications so you can forward data to services such as syslog servers, Slack, Splunk, Amazon SQS, Amazon S3, and Webhook. - Administrator Guide - Cortex CLOUD

Cortex Cloud Posture Management Documentation

Product
Cortex Cloud Application Security > Cortex CLOUD
License
Cloud Posture Management
Creation date
2025-01-22
Last date published
2026-06-10
Category
Administrator Guide
Abstract

Configure external applications so you can forward data to services such as syslog servers, Slack, Splunk, Amazon SQS, Amazon S3, and Webhook.

Cases, issues, and logs can be forwarded to third-party external services. The external service must be configured in Cortex Cloud before you set up notification forwarding.

Only cases and issues can be forwarded to Slack, Amazon S3, Amazon SQS, Splunk, and Webhook. Before forwarding cases or issues to Splunk, Amazon S3, Amazon SQS, or Webhook, you need to configure egress in the Cortex Gateway.

You do not need to configure egress for email, Slack, or syslog forwarding. No prior configuration is required to send data or logs to an email distribution list.

Note

There are two options for configuring external applications. To configure relevant external applications before you begin creating forwarding notifications, follow the steps in the following topics using the menu path SettingsConfigurationsIntegrationsExternal Applications. You can also configure an external application as part of the workflow for configuring notification forwarding found at SettingsConfigurationsGeneralNotificationsAdd Forwarding Notifications. After defining the configuration and setting the scope of the notifications, you can select an existing external application or Add Application. After you choose Add Application, the steps are identical to those described in the following topics.