Collect Windows Event Logs for Cortex XSIAM via Cribl - Learn more about how to collect Windows Event Logs for Cortex XSIAM using Cribl. - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM Documentation

Product
Cortex XSIAM
Creation date
2024-03-06
Last date published
2026-05-31
Category
Administrator Guide
Abstract

Learn more about how to collect Windows Event Logs for Cortex XSIAM using Cribl.

There are two primary methods for streaming Windows Event Logs to Cortex XSIAM using Cribl. The choice depends on whether you prefer a centralized, agentless architecture or a distributed, agent-based approach.

Important

Avoid data duplication: Do not enable both WEF and Cribl Edge on the same endpoint for the same log channels.

Note

For the general Cribl-to-XSIAM integration workflow (credentials, destination, XSIAM pack, and verification), see Cribl integration documentation.