For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex Cloud Runtime

Forcepoint DLP

Use Forcepoint DLP data with Cortex Cloud.

You can configure collecting Corelight Zeek logs using a Broker VM Syslog Collector applet or content pack integration (onboarded prior to July 26, 2026):

Forcepoint DLP vendor
Description

Syslog Collector applet overview

If you use Forcepoint DLP to prevent data loss over endpoint channels, you can forward logs to Cortex Cloud using the Broker VM Syslog Collector applet in a CEF or LEEF format.

Link to Syslog Collector applet instructions

Link to content pack/integration details (onboarded prior to July 26, 2026)

The Forcepoint DLP content pack fetches security incidents from Forcepoint DLP and ingests them as events into Cortex XSIAM for processing and analysis. contains the Forcepoint DLP Modeling Rule, and the Forcepoint DLP Parsing Rule. It also includes the following integration:

  • Forcepoint DLP Event Collector (Beta): Use this integration to fetch security incidents from Forcepoint DLP as Cortex XSIAM events. This integration is an event collector and utilizes parsing and modeling rules within the content pack for data normalization.

Last updated

Was this helpful?