Cortext¶
Key facts¶
- MSG Format based filter
- Cortex requires TLS and uses IETF Framed SYSLOG default port is 6587
| Ref | Link | 
|---|---|
| Splunk Add-on | https://splunkbase.splunk.com/app/2757/ | 
Sourcetypes¶
| sourcetype | notes | 
|---|---|
| pan:* | |
| pan:xsoar | none | 
Index Configuration¶
| key | index | notes | 
|---|---|---|
| Palo Alto Networks_Palo Alto Networks Cortex XSOAR | epintel | none |