Can Cortex XDR logs be shipped to IDR

Good Day,
WE recently migrated from a A/V provider to now Cortex XDR. I am not seeing any way for these logs to be shipped to IDR. Is there a way to do this ?

Hey Kadeem,
good day!

Unfortunately, we do not support Cortex XDR yet, but happy to say that it is on our roadmap for this year.
When we have a better estimation delivery date, I will let you know.

Mirela

1 Like

Thanks much for the reply, I will noted that :smiley:

Hi Kadeem,

we are using Cortex XDR as well and I was able to ship data from Cortex XDR to InsightIDR.

In Cortex XDR you can forward the logs to a Collector and on InsightIDR you can use the legacy Palo Alto Networks Traps TSM Event Source. It works, but of course it’s not well implemented. However, you can trigger your own alerts form the logs received if thats what you need.

Right now, Iam not forwarding Cortex XDR logs to InsightIDR anymore because it adds no real value for me, but this might change when Cortex XDR will be officially supported by InsightIDR.

Best regards
Robert

2 Likes

FWIW, Cortex XDR is supported by InsightConnect for multiple types of response actions.

1 Like

Hi Mirela,

Are there any updates as for when the integration for Palo Alto Cortex XDR to Insight IDR will be ready?

Thanks in advance
/Richard

2 Likes

Yes, Iam also interested if there is an updated timeline for this.

Hi Mirela,

Is there a better estimation delivery date for this integration to ship Cortex XDR logs to IDR?

Hi all,

I’ve added a short update below on this topic. Let me know if you’ve any questions/thoughts.

Current Status:
We’ve kicked off engineering work to support Palo Alto data via syslog. We are aiming to support any Palo Alto products that flow into the data lake such as Cortex XDR, Prisma and Firewall Activity.

Timelines:
We are targeting to release syslog support for Palo Alto Data Lake within Q2 2022.

Further Integrations:
We are also hoping to introduce a native API integration with Palo Alto Data Lake in the future. However, this is not something engineering teams are actively working on right now.