> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion-vendor-support.md).

# External data ingestion vendor support

{% hint style="info" %}

### Notice

Ingestion of logs and data requires a Cortex XDR Pro per GB license.
{% endhint %}

{% hint style="info" %}

### Note

New Cortex XDR licenses that are purchased from October 1st, 2025 and onwards will no longer support the data collectors marked with an asterisk (\*). For comprehensive data collector support, consider upgrading to an XSIAM license.
{% endhint %}

To provide you with a more complete and detailed picture of the activity involved in an incident, you can ingest data from a variety of external, third-party sources into Cortex XDR.

Cortex XDR can receive logs, or both logs and alerts, from the source. Depending on the data source, Cortex XDR can provide visibility into your external data in the form of:

* Log stitching with other logs in order to create network or authentication stories.
* Raw data in queries from XQL Search.
* Alerts reported by the vendor throughout Cortex XDR, such as in the alerts table, incidents, and views.
* Alerts raised by Cortex XDR on log data, such as analytics alerts.

To ingest data, you must set up the Syslog Collector applet on a Broker VM within your network.

The following table summarizes the vendor data that can be ingested, according to log or data type.

| Log/Data Type                                  | Vendor Support                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ---------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Network Connections                            | <ul><li><a href="/pages/YkPJVtOQ45rNkHQWMITd">Amazon S3 (flow logs)</a></li><li><a href="/pages/rPfYW0vit1DZxOEBvrLi">Amazon S3 (Route 53 logs)</a></li><li><a href="/pages/N4WQYDlrYem3VEQPKNAQ">Azure Event Hub</a></li><li><a href="/pages/AC4Bn9WBkUCPRipyxutP">Azure Network Watcher (flow logs)</a></li><li><a href="/pages/YUjUijTXxgqjaAZald0j">Check Point FW1/VPN1</a></li><li><a href="/pages/046Q8fW2fKwf623wJtQc">Cisco ASA and Cisco AnyConnect VPN</a></li><li><a href="/pages/L36E2Auad50WBRIKNcVk">Corelight Zeek</a></li><li><a href="/pages/Klr1dnWh70SvZ1XT2hrf">Fortinet Fortigate</a></li><li><a href="/pages/31Rhn0tMDXY1dOFFCgcH">Google Cloud Platform (flow logs, DNS logs)</a></li><li><a href="/pages/fnn8u8Vte9j6xs9VkWHC">Okta</a></li><li><a href="/pages/f8E3mLShUkhTNqu63FdT">Prisma Browser</a></li><li><a href="/pages/EDkIZfrXd6lBNotO4GNv">Windows DHCP via Elasticsearch Filebeat</a></li><li><a href="/pages/vrrM5ISZImNKn5ZsdMtm">Zscaler Internet Access (ZIA)</a></li><li><a href="/pages/NyuLyKPlUWA3yoZOHTIn">Zscaler Private Access (ZPA)</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Authentication Services/Audit Logs             | <ul><li><a href="/pages/m0NkdDNjpXvaNB02tfB9">Amazon S3 (audit logs)</a></li><li><a href="/pages/N4WQYDlrYem3VEQPKNAQ">Azure Event Hub (audit logs, AKS logs)</a></li><li><a href="/pages/31Rhn0tMDXY1dOFFCgcH">Google Cloud Platform (audit logs, GKE logs)</a></li><li><a href="/pages/DIt5vpLqBTelvpYmBEMg">Google Workspace</a></li><li><a href="/pages/Cb1Saht2SQyoDgSq8gEb">Microsoft 365 (email)</a></li><li><a href="/pages/XFc7qVGnxedPZxp5ugAa">Microsoft Office 365</a></li><li><a href="/pages/fnn8u8Vte9j6xs9VkWHC">Okta</a></li><li><a href="/pages/jt3BKjE8LMLuH3mHBMZA">OneLogin</a></li><li><a href="/pages/rZyFqLYt76zD5Noxlchy">PingFederate</a>\*</li><li><a href="/pages/SELhfBu2MARjm9aP4keC">PingOne for Enterprise</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Operation and System Logs from Cloud Providers | <ul><li><a href="/pages/N4WQYDlrYem3VEQPKNAQ">Azure Event Hub</a></li><li><a href="/pages/31Rhn0tMDXY1dOFFCgcH">Google Cloud Platform</a></li><li><a href="/pages/4hcoazoSsO4HmdeX7B4V">Google Kubernetes Engine</a></li><li><a href="/pages/fnn8u8Vte9j6xs9VkWHC">Okta</a></li><li><a href="/pages/vJ6E62yaLd2gCVgtGx8t">Prisma Cloud (alerts)</a></li><li><a href="/pages/wYIdh8hcXNRHH3kAbaHv">Prisma Cloud Compute (alerts)</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Endpoint Logs                                  | <ul><li><a href="/pages/Xt9UApzXJQ2jAGv2WXdQ">Windows Event Collector</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Cloud Assets                                   | <ul><li><a href="/pages/hB094iCuDkedQvwdAJz0">AWS</a></li><li><a href="/pages/Mf9i1GGPAi4FRwrlrLHQ">Google Cloud Platform</a></li><li><a href="/pages/jjbs3JMXUiesVTFk0dOs">Microsoft Azure</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Custom External Sources                        | <ul><li><a href="/pages/IssZOynJdSjsMx8ChhfW">Any Vendor Sending CEF, LEEF, CISCO, CORELIGHT, or RAW formatted Syslog</a>*</li><li><a href="/pages/JaNeuLV7L0lKDDZPPxdm"><em>Any vendor CSV files on a shared Windows directory</em></a><em>*</em></li><li><a href="/pages/sRU1mTqfLSFA8bCOArki">Any vendor logs stored in a database</a>*</li><li><a href="/pages/5aLTi5iKmedEB3jl8m8F"><em>Any vendor logs stored in files on a network share</em></a><em>*</em></li><li><a href="/pages/3FwEQufRrBO2wbZPxveg">Any vendor logs from a third party source over FTP, FTPS, or SFTP</a>*</li><li><a href="/pages/DmAApC8GXKagLMUGRWoa"><em>Any vendor sending NetFlow flow records</em></a><em>*</em></li><li><a href="/pages/reeEqnxkagjzgfAhfqDz">Any vendor sending logs over HTTP</a>*</li><li><a href="/pages/uS4cntSrbI7pPAeRmlKX"><em>Apache Kafka</em></a><em>*</em></li><li><a href="/pages/FXBN4zdy8QmcQSGAyWYd">BeyondTrust Privilege Management Cloud</a>*</li><li><a href="/pages/3UUZJy5lozZievlQ8Cad"><em>Box</em></a></li><li><a href="/pages/nPvfVK6ChikAEBviUTmG"><em>Dropbox</em></a></li><li><a href="/pages/DElHiEMz2XAlG1zra9dY"><em>Elasticsearch Filebeat</em></a></li><li><a href="/pages/n4ZhErMBMfebtjOyWglb"><em>Forcepoint DLP</em></a><em>*</em></li><li><a href="/pages/LF5067yJthqiQcMoOGNn">IoT Security</a></li><li><a href="/pages/WH1iRBvvwf1XFx7wuDRK">Strata Logging Service</a></li><li><a href="/pages/IecEm91O8VHTsiAPpbPH">Workday</a></li><li><a href="/pages/r8NWczREINCgG9meBUX1">Any vendor sending alerts</a>\*</li></ul> |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion-vendor-support.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
