For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex XDR 3.x

Ingest logs from a Syslog receiver

To extend visibility, Cortex XDR can receive Syslog from additional vendors that use CEF or LEEF formatted over Syslog (TLS not supported).

Notice

Ingestion of logs and data requires a Cortex XDR Pro per GB license.

Note

New Cortex XDR licenses that are purchased from October 1st, 2025 and onwards, will no longer support Syslog ingestion from external sources. The Syslog log collector can still be used, but all unsupported data sources ingested using this collector will be ignored, and will not be ingested into Cortex XDR.

Cortex XDR can receive Syslog from a variety of supported vendors (see External data ingestion vendor support). In addition, Cortex XDR can receive Syslog from additional vendors that use CEF, LEEF, CISCO, CORELIGHT, or RAW formatted over Syslog.

After Cortex XDR begins receiving logs from the third-party source, Cortex XDR automatically parses the logs in CEF, LEEF, CISCO, CORELIGHT, or RAW format and creates a dataset with the name <vendor>_<product>_raw. You can then use XQL Search queries to view logs and create new IOC, BIOC, and Correlation Rules.

To receive Syslog from an external source:

  1. Set up your Syslog receiver to forward logs.

  2. Activate the Syslog Collector applet on a Broker VM within your network.

  3. Use the XQL Search to search your logs.

Last updated

Was this helpful?