-
Notifications
You must be signed in to change notification settings - Fork 550
Labels
CrestContributions from Crest developement team.Contributions from Crest developement team.Integration:panw_cortex_xdrPalo Alto Cortex XDRPalo Alto Cortex XDR
Description
Description
Add support for Cortex XDR Event Forwarding to the existing panw_cortex_xdr integration package. The integration currently supports Alerts and Incidents data streams but lacks support for raw endpoint telemetry data available via the Event Forwarding feature.
The integration should handle multiple event types exported for endpoints, including:
- Network events
- Process events
- File events
- Registry events
- Injection events
- Load Image events
- User Status Change events
- Host Status Change events
- Agent Status Change events
- Host Metadata Discovery/Change events
The integration should also include dashboards for alerts, incidents and telemetry data streams.
Documentation Links
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
CrestContributions from Crest developement team.Contributions from Crest developement team.Integration:panw_cortex_xdrPalo Alto Cortex XDRPalo Alto Cortex XDR