Skip to content

Palo Alto Cortex XDR Event Forwarding #13268

@cpascale43

Description

@cpascale43

Description

Add support for Cortex XDR Event Forwarding to the existing panw_cortex_xdr integration package. The integration currently supports Alerts and Incidents data streams but lacks support for raw endpoint telemetry data available via the Event Forwarding feature.

The integration should handle multiple event types exported for endpoints, including:

  • Network events
  • Process events
  • File events
  • Registry events
  • Injection events
  • Load Image events
  • User Status Change events
  • Host Status Change events
  • Agent Status Change events
  • Host Metadata Discovery/Change events

The integration should also include dashboards for alerts, incidents and telemetry data streams.

Documentation Links

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions