Skip to content

Cortext

Key facts

  • MSG Format based filter
  • Cortex requires TLS and uses IETF Framed SYSLOG default port is 6587
Ref Link
Splunk Add-on https://splunkbase.splunk.com/app/2757/

Sourcetypes

sourcetype notes
pan:*
pan:xsoar none

Index Configuration

key index notes
Palo Alto Networks_Palo Alto Networks Cortex XSOAR epintel none