The Cloud Logging and Collection Service (CLCS) Management APIs allow you to programmatically manage Next-Generation Firewalls (NGFWs) connected to your CLCS environment.
CLCS enables NGFWs to forward logs directly to Cortex XDR for analysis and threat detection. These APIs provide the ability to list all connected devices and disconnect one or more devices in bulk, replacing the slow, manual UI workflow that only supports one-at-a-time removal.
{% hint style="info" %} Required licenses: This feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM product that has the Cloud Runtime Security or Cloud Posture Security add-ons. {% endhint %}
RBAC permissions:
- List connected devices: Data Collection > Data Sources > View
- Disconnect devices: Data Collection > Data Sources > Edit