For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex Cloud Runtime

Corelight Zeek

Use Corelight Zeek data with Cortex Cloud.

You can configure collecting Corelight Zeek logs using a Broker VM Syslog Collector applet or content pack integration (onboarded prior to July 26, 2026):

Corelight Zeek vendor
Description

Syslog Collector applet overview

If you use Corelight Zeek sensors for network monitoring, you can forward network connection logs to Cortex Cloud using the Broker VM Syslog Collector applet with TCP as the transport Protocol and a Corelight format.

Link to Syslog Collector applet instructions

Link to content pack/integration details (onboarded prior to July 26, 2026)

The Corelight Zeek content pack provides data normalization capabilities through rules for parsing and modeling network protocol logs that are ingested via a Syslog collector on the Broker VM into Cortex XSIAM. It includes Corelight Zeek Modeling Rules and Corelight Zeek Parsing Rules.

Last updated

Was this helpful?