For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex Cloud Runtime

Box

Configure the Box data source for Cortex Cloud.

You can configure collecting Box logs and data using a standard data source or content pack integration (onboarded prior to July 26, 2026):

Box vendor
Description

Standard data source overview

Forward different types of data from Box enterprise accounts to Cortex Cloud using the Box data source.

Link to standard data source instructions

The following types of data can be ingested from Dropbox:

  • Events and security alerts

    • Events (admin_logs)

    • Box Shield Alerts

  • Directory and metadata

    • Users

    • Groups

For more information, see Ingest logs and data from Box.

Links to content pack integration details (onboarded prior to July 26, 2026)

The Box content pack contains classifiers, issue fields and types, and parsing and modeling rules to normalize Box data in Cortex XSIAM. It also includes the following integrations:

  • Box Event Collector: Use this integration to collect events from Box's logs. It includes a command to get Box events.

  • Box V2: Use this integration to manage Box users. It includes commands to search Box content and manage file folders and share links.

Last updated

Was this helpful?