Learn how to create a forwarding configuration that specifies the log type you want to forward.
After you integrate with an external service such as Slack, a syslog server, Amazon S3, Amazon SQS, Webhook, or Splunk, create a forwarding configuration that specifies the data or log type you want to forward. You can configure notifications for issues, cases, and logs. To send reports to email or Slack, see Run or schedule reports.
Prerequisite
Before you can select an external service for notification forwarding, you must integrate the external service with Cortex XDR. For more information, see Configure external applications for forwarding. No prior configuration is required to send data to an email distribution list.
Select → → → → .
Enter a name for the configuration.
Select the data or log type you want to forward:
Issues: Send notifications for specific issue types.
Note
Forwarding destinations: Only issues and cases can be forwarded to Slack, Splunk, Amazon SQS, Amazon S3, or Webhook.
Notification forwarding by domain: To configure notification forwarding for issues by domain, select Issues and filter the Issues table by Issue Domain.
Alert vs. issue format:By default, new configurations use the issue format, but you can select the alert format if needed, when forwarding to email, Slack, or a syslog server. You cannot forward issues in the alert format to Splunk, Amazon SQS, Amazon S3, or Webhook.
Existing legacy configurations are not automatically updated and continue to send notifications in the alert format. To use the issue format, edit the existing configuration.
Agent Audit Logs: Send notifications for audit logs reported by your Cortex XDR agents.
Management Audit Logs: Send notifications for audit logs about events related to your Cortex XDR tenant.
Cases—Send notifications for specific cases.
Note
Not all data and log types can be sent to all external services. For more information, see Forward logs and data from Cortex XDR to external services.
(Optional) Enter a description of the forwarding configuration.
Click Next, and under Scope, filter which issues, cases, or logs you want included in a notification.
For example, for a filter set to
Severity = Medium, Category = Configuration, Cortex XDR sends the issues or events matching this filter as a notification.Click Next.
Select email or the external service you want to forward to.
Click Next.
Review the forwarding configuration and click Create.