Forcepoint DLP
Use Forcepoint DLP data with Cortex Cloud.
You can configure collecting Corelight Zeek logs using a Broker VM Syslog Collector applet or content pack integration (onboarded prior to July 26, 2026):
Syslog Collector applet overview
If you use Forcepoint DLP to prevent data loss over endpoint channels, you can forward logs to Cortex Cloud using the Broker VM Syslog Collector applet in a CEF or LEEF format.
Link to Syslog Collector applet instructions
Link to content pack/integration details (onboarded prior to July 26, 2026)
The Forcepoint DLP content pack fetches security incidents from Forcepoint DLP and ingests them as events into Cortex XSIAM for processing and analysis. contains the Forcepoint DLP Modeling Rule, and the Forcepoint DLP Parsing Rule. It also includes the following integration:
Forcepoint DLP Event Collector (Beta): Use this integration to fetch security incidents from Forcepoint DLP as Cortex XSIAM events. This integration is an event collector and utilizes parsing and modeling rules within the content pack for data normalization.
Last updated
Was this helpful?
