Ingest Database Data as Datasets - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM Administrator Guide

Product
Cortex XSIAM
Creation date
2024-07-16
Last date published
2024-12-01
Category
Administrator Guide
Abstract

Cortex XSIAM can receive data from a client relational database directly to your log repository.

Cortex XSIAM can receive data from a client relational database directly to your log repository for query and visualization purposes. After you activate the Database Collector applet on a Broker VM in your network, which includes defining the database connection details and settings related to the query details for collecting the data from the database to monitor and upload to Cortex XSIAM, you can collect data as datasets.

After Cortex XSIAM begins receiving data from a client relational database, Cortex XSIAM automatically parses the logs and creates a dataset with the specific name you set as the target dataset when you configured the Database Collector using the format <Vendor>_<Product>_raw. The Database Collector checks for any changes in the configured database based on the SQL Query defined in the database connection according to the execution frequency of collection that you configured and appends the data to the dataset. You can then use XQL Search queries to view data and create new Correlation Rules.

Configure Cortex XSIAM to receive data as datasets data from a client relational database.

  1. Activate the Database Collector applet on a Broker VM within your network.

  2. Use the XQL Search to query and review logs.