Cortex XDR provides visibility into your external logs. The availability of logs and alerts varies by the data source.
The following table describes the visibility of each vendor and device type, and where you can view information ingested from external sources, depending on the data source.
A indicates support and a dash (—) indicates the feature is not supported.
Vendor and Device Type | Raw Data Visibility | Normalized Log Visibility | Cortex XDR Alert Visibility | Vendor Alert Visibility |
---|---|---|---|---|
Raw data is searchable in XQL Search. | Option to ingest network flow logs as Cortex XDR network connection stories that are searchable in the Query Builder and in XQL Search. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | — | |
Raw data is searchable in XQL Search. | Option to ingest network Route 53 DNS logs as Cortex XDR network connection stories that are searchable in the Query Builder and in XQL Search. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | — | |
Raw data is searchable in XQL Search. | — | Cortex XDR can raise Cortex XDR alerts (Correlation Rules only) when relevant from flow logs. | — | |
Raw data is searchable in XQL Search. | Option to ingest network flow logs as Cortex XDR network connection stories that are searchable in the Query Builder and in XQL Search. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from flow logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | — | |
Raw data is searchable in XQL Search. NoteLogs with | Network stories that include Check Point network connection logs are searchable in the Query Builder and in XQL Search. NoteLogs with | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | Alerts from Check Point firewalls are raised throughout Cortex XDR when relevant. | |
Raw data is searchable in XQL Search. | Network stories that include Corelight Zeek network connection logs are searchable in the Query Builder and in XQL Search. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | — | |
Raw data is searchable in XQL Search. | Network stories that include Cisco network connection logs are searchable in the Query Builder and in XQL Search. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | — | |
Raw data is searchable in XQL Search. | Network stories that include Fortinet network connection logs are searchable in the Query Builder and in XQL Search. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | Alerts from Fortinet firewalls are raised throughout Cortex XDR when relevant. | |
Raw data is searchable in XQL Search. | Option to ingest network flow logs as Cortex XDR network connection stories and Google Cloud DNS logs that are searchable in the Query Builder and in XQL Search. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | — | |
Raw data is searchable in XQL Search. | — | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. Note
| — | |
Raw data is searchable in XQL Search. | Cortex XDR uses Windows DHCP logs to enrich your network logs with hostnames and MAC addresses that are searchable in XQL Search. | — | — | |
Raw data is searchable in XQL Search. | Network stories that include ZIA network connection and firewall logs are searchable in the Query Builder and in XQL Search. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. Note
| — | |
Raw data is searchable in XQL Search. | Network stories that include ZPA network connection logs are searchable in the Query Builder and in XQL Search. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. Note
| — |
Vendor and Device Type | Raw Data Visibility | Normalized Log Visibility | Cortex XDR Alert Visibility | Vendor Alert Visibility |
---|---|---|---|---|
Logs and stories are searchable in XQL Search | Option to stitch audit logs with authentication stories that are searchable in the Query Builder and XQL Search. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | — | |
Logs and stories are searchable in XQL Search | Option to stitch audit logs with authentication stories that are searchable in the Query Builder and XQL Search. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | — | |
Raw data is searchable in XQL Search. | Option to stitch audit logs with authentication stories that are searchable in the Query Builder and XQL Search. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | — | |
Raw data is searchable in XQL Search. | Relevant Login, Token, Google drive, SAML, Admin Console, Enterprise Groups, and Rules audit logs normalized into authentication stories. All are searchable in the Query Builder. | For all logs, Cortex XDR can raise Cortex XDR alerts (Analytics and Correlation Rules) when relevant from logs. | — | |
Email logs are searchable in XQL Search | Microsoft 365 normalized email stories | For Microsoft 365 email logs, Cortex XDR can also raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from the email logs. | — | |
Microsoft Office 365Ingest Logs from Microsoft Office 365 | Logs and stories (Azure AD authentication and audit logs only) are searchable in XQL Search | Azure AD authentication logs and Azure AD Sign-in logs normalized into authentication stories. Azure AD audit logs normalized to cloud audit logs stories. Exchange Online, SharePoint Online, and General audit logs normalized into stories. All are searchable in the Query Builder. | For all Microsoft Office 365 logs, Cortex XDR can also raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from Office 365 logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | — |
Logs and stories are searchable in XQL Search | Logs stitched with authentication stories are searchable in the Query Builder. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules only) when relevant from logs. Note
| — | |
Raw data is searchable in XQL Search. | All log types are normalized into authentication stories, and are searchable in the Query Builder. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | — | |
Logs and stories are searchable in XQL Search | Logs stitched with authentication stories are searchable in the Query Builder. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | — | |
Raw data is searchable in XQL Search | Logs stitched with authentication stories are searchable in the Query Builder. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | — |
Vendor and Device Type | Raw Data Visibility | Normalized Log Visibility | Cortex XDR Alert Visibility | Vendor Alert Visibility |
---|---|---|---|---|
Raw data is searchable in XQL Search. | — | Cortex XDR can raise Cortex XDR alerts (Correlation Rules only) when relevant from logs. | — | |
Raw data is searchable in XQL Search. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | — | ||
Raw data is searchable in XQL Search. | — | Cortex XDR can raise Cortex XDR alerts (Correlation Rules only) when relevant from logs. | — | |
Raw data is searchable in XQL Search. | — | Cortex XDR can raise Cortex XDR alerts (Correlation Rules only) when relevant from logs. | — | |
Raw data is searchable in XQL Search. | — | Cortex XDR can raise Cortex XDR alerts (Correlation Rules only) when relevant from logs. | — | |
Raw data is searchable in XQL Search. | — | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | — | |
Raw data is searchable in XQL Search. | Prisma Cloud alerts are stitched with Cloud Provider logs when relevant. | Cortex XDR can raise Cortex XDR alerts (Correlation Rules only) when relevant from logs. | Alerts from Prisma Cloud are raised throughout Cortex XDR when relevant. | |
Raw data is searchable in XQL Search. | — | Cortex XDR can raise Cortex XDR alerts (Correlation Rules only) when relevant from logs. | Alerts from Prisma Cloud Compute are raised throughout Cortex XDR when relevant. |
Vendor and Device Type | Raw Data Visibility | Normalized Log Visibility | Cortex XDR Alert Visibility | Vendor Alert Visibility |
---|---|---|---|---|
Windows Event CollectorActivate Windows Event Collector | Windows event logs are available with agent EDR data and are searchable in XQL Search. The normalized Windows event log data is also available in | Windows event logs are stitched with agent EDR data and are searchable in the Query Builder. The Windows event logs are also normalized into the common Cortex Windows event format in | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | — |
Vendor and Device Type | Raw Data Visibility | Normalized Log Visibility | Cortex XDR Alert Visibility | Vendor Alert Visibility |
---|---|---|---|---|
— | N/A | N/A | N/A | |
— | N/A | N/A | N/A | |
— | N/A | N/A | N/A |
Vendor and Device Type | Raw Data Visibility | Normalized Log Visibility | Cortex XDR Alert Visibility | Vendor Alert Visibility |
---|---|---|---|---|
Any Vendor Sending CEF, LEEF, CISCO, CORELIGHT, or RAW formatted Syslog | Raw data is searchable in XQL Search. | — | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | To enable Cortex XDR to display alerts from other vendors, you must map your alert fields to the Cortex XDR field format (see Ingest External Alerts). |
Raw data is searchable in XQL Search. | — | Cortex XDR can raise Cortex XDR alerts (Correlation Rules only) when relevant from logs. | — | |
Raw data is searchable in XQL Search. | — | Cortex XDR can raise Cortex XDR alerts (Correlation Rules only) when relevant from logs. | — | |
Raw data is searchable in XQL Search. | — | Cortex XDR can raise Cortex XDR alerts (Correlation Rules only) when relevant from logs. | — | |
Any vendor logs from a third party source over FTP, FTPS, or SFTP | Raw data is searchable in XQL Search. | — | Cortex XDR can raise Cortex XDR alerts (Correlation Rules only) when relevant from logs. | — |
Raw data is searchable in XQL Search. | NetFlow events are stitched with the Agent’s EDR data and other Network products to a Session Story, and are searchable in the Query Builder and in XQL. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | — | |
Raw data is searchable in XQL Search. | — | Cortex XDR can raise Cortex XDR alerts (Correlation Rules only) when relevant from logs. | To enable Cortex XDR to display alerts from other vendors, you must map your alert fields to the Cortex XDR field format (see Ingest External Alerts). | |
Raw data is searchable in XQL Search. | — | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | — | |
Raw data is searchable in XQL Search. | — | Cortex XDR can raise Cortex XDR alerts (Correlation Rules only) when relevant from logs. | — | |
Raw data is searchable in XQL Search. | Selected Box audit event logs are normalized into stories and are searchable in the Query Builder and in XQL. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | — | |
Raw data is searchable in XQL Search. | Selected Box audit event logs are normalized into stories and are searchable in the Query Builder and in XQL. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | — | |
Raw data is searchable in XQL Search. | — | Cortex XDR can raise Cortex XDR alerts (Correlation Rules only) when relevant from logs. | — | |
Raw data is searchable in XQL Search. | — | Cortex XDR can raise Cortex XDR alerts (Correlation Rules only) when relevant from logs. | — | |
Raw data is searchable in XQL Search. | Cortex XDR uses IoT Security information to improve analytics detection and assets management information. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | — | |
Raw data is searchable in XQL Search. | — | Cortex XDRCortex XDR alerts (Correlation Rules only) when relevant from logs. | — | |
Raw data is searchable in XQL Search. | — | Cortex XDR can raise Cortex XDR alerts (Correlation Rules only) when relevant from logs. | — | |
Raw data is searchable in XQL Search. | — | Cortex XDRCortex XDR alerts (Correlation Rules only) when relevant from logs. | — | |
Raw data is searchable in XQL Search. | Detection events are stitched with other Palo Alto Networks product logs to stories, and are searchable in the Query Builder and in XQL. | Cortex XDR can raise Cortex XDR alerts (Analytics, IOC, BIOC, and Correlation Rules) when relevant from logs. NoteWhile Correlation Rules alerts are raised on non-normalized and normalized logs, Analytics, IOC and BIOC alerts are only raised on normalized logs. | Alerts from NGFW are raised throughout Cortex XDR when relevant. | |
Raw data is searchable in XQL Search. | — | Cortex XDRCortex XDR alerts (Correlation Rules only) when relevant from logs. | — | |
Any vendor sending alerts | — | — | — | Alerts are surfaced throughout Cortex XDR when relevant. To enable Cortex XDR to display your alerts, you must map your alert fields to the Cortex XDR field format (see Ingest External Alerts). |
Datasets created from ingesting data
When ingesting data from an external source, Cortex XDR creates a dataset that you can query using Cortex Query Language (XQL). Datasets created in this way use the following naming convention.
<vendor_name>_<product_name>_raw
For example: cisco_asa_raw
The datatypes used for the fields in an imported dataset are automatically assigned based on the input content. Fields can have a datatype of string
, int
, float
, array
, time
, or boolean
. All other fields are ingested as a JSON object.
For CEF type files, when extension values are quoted, the CEF parser automatically removes the quotes from the values. In addition, files containing invalid UTF-8 are parsed under XQL mapping field _invalid_utf8
.