Ingesting Authentication Logs and Data requires a Cortex XDR Pro per TB license.
To receive authentication logs and data from PingOne for Enterprise, you must first set up a Poll subscription in PingOne and then configure the Collection Integrations settings in Cortex XDR. After you set up collection integration, Cortex XDR immediately begins receiving new authentication logs and data from the source. These logs and data are then searchable in Cortex XDR.
Set up PingOne for Enterprise to send logs and data.
To set up the integration, you must have an account for the PingOne management dashboard and access to create a subscription for SSO logs.
From the PingOne Dashboard:
Select→ → .
Enter a NAME for the subscription.
Select Poll as the subscription type.
Leave the remaining defaults and select Done.
Identify your account ID and subscription ID.
Select the subscription you just set up and note the part of the poll URL between /reports/ and /poll-subscriptions. This is your PingOne account ID.
In this URL, the account ID is
Next, note the part of the poll URL between /poll-subscriptions/ and /events. This is your subscription ID.
In the example above, the subscription ID is
Select→ → → .
Connect Cortex XDR to your PingOne for Enterprise authentication service.
Enter your PingOne ACCOUNT ID.
Enter your PingOne SUBSCRIPTION ID.
Enter your PingOne USER NAME.
Enter your PingOne PASSWORD.
Test the connection settings.
If successful, Enable PingOne authentication log collection.
After configuration is complete, Cortex XDR begins receiving information from the authentication service. From the Integrations page, you can view the log collection summary.
To search for specific authentication logs or data, you can Create an Authentication Query or Create an XQL Query.