WE recently migrated from a A/V provider to now Cortex XDR. I am not seeing any way for these logs to be shipped to IDR. Is there a way to do this ?
Unfortunately, we do not support Cortex XDR yet, but happy to say that it is on our roadmap for this year.
When we have a better estimation delivery date, I will let you know.
Thanks much for the reply, I will noted that
we are using Cortex XDR as well and I was able to ship data from Cortex XDR to InsightIDR.
In Cortex XDR you can forward the logs to a Collector and on InsightIDR you can use the legacy Palo Alto Networks Traps TSM Event Source. It works, but of course it’s not well implemented. However, you can trigger your own alerts form the logs received if thats what you need.
Right now, Iam not forwarding Cortex XDR logs to InsightIDR anymore because it adds no real value for me, but this might change when Cortex XDR will be officially supported by InsightIDR.
FWIW, Cortex XDR is supported by InsightConnect for multiple types of response actions.