Integrate a syslog receiver
Define syslog settings and then configure notification forwarding to receive notifications about alerts and reports.
A syslog receiver can be a physical or virtual server, a SaaS solution, or any service that accepts syslog messages.
To send Cortex XDR notifications to your syslog receiver, you first need to define the settings for the syslog receiver. Once this is complete, you can configure notification forwarding.
How to send logs to a syslog receiver
Before you begin, enable access to the following Cortex XDR IP addresses for your region in your firewall.
United States - Americas (US)
35.232.87.9
35.224.66.220
Germany (DE)
35.234.95.96
35.246.192.146
Netherlands - Europe (EU)
34.90.202.186
34.90.105.250
Canada (CA)
35.203.54.204
35.203.52.255
United Kingdom (UK)
34.105.227.105
34.105.149.197
Singapore (SG)
35.240.192.37
34.87.125.227
Japan (JP)
34.84.88.183
35.243.76.189
Australia (AU)
35.189.38.167
34.87.219.39
United States - Government
104.198.222.185
35.239.59.210
India (IN)
34.93.247.41
34.93.183.131
Switzerland (CH)
34.65.228.95
34.65.74.83
Warsaw (PL)
34.118.45.145
34.118.126.170
Taiwan (TW)
35.234.2.208
35.185.171.91
Qatar (QT)
34.18.48.182
34.18.43.40
France (FA)
34.163.100.253
34.155.72.149
Israel (IL)
34.165.194.4
34.165.101.105
Saudi Arabia (SA)
34.166.50.215
34.166.55.72
Indonesia (ID)
34.101.248.99
34.101.176.232
Spain (ES)
34.175.83.90
34.175.230.150
Italy (IT)
34.154.0.173
34.154.71.94
South Korea (KR)
34.64.198.58
34.47.86.20
South Africa (ZA)
34.35.70.253
34.35.10.167
Select Settings → Configurations → Integrations → External Applications.
In Syslog Servers, click + New Server.
Define the following parameters:
ParameterDescriptionName
Unique name for the server profile.
Destination
IP address or fully qualified domain name (FQDN) of the syslog receiver.
Port
Port number on which to send syslog messages.
Facility
Select one of the syslog standard values. The value maps to how your syslog server uses the facility field to manage messages. For details on the facility field, see RFC 5424.
Protocol
Method of communication with the syslog receiver:
TCP: No validation is made on the connection with the syslog receiver. However, if an error occurred with the domain used to make the connection, the Test connection will fail.
UDP: No error checking, error correction, or acknowledgment. No validation is done for the connection or when sending data.
TCP + SSL: Cortex XDR validates the syslog receiver certificate and uses the certificate signature and public key to encrypt the data sent over the connection.
Certificate
The communication between Cortex XDR and the syslog destination can use TLS. In this case, upon connection, Cortex XDR validates that the syslog receiver has a certificate signed by either a trusted root CA or a self-signed certificate. You may need to merge the Root and Intermediate certificate if you receive a certificate error when using a public certificate.
If your syslog receiver uses a self-signed CA, upload your self-signed syslog receiver CA. If you only use a trusted root CA leave the certificate field empty.
You can ignore certificate errors. For security reasons, this is not recommended. If you choose this option, logs will be forwarded even if the certificate contains errors.
Test the parameters to ensure a valid connection, and click Create when ready.
You can define up to five syslog receivers. Upon success, the table displays the syslog servers and their status.
What to do next
After you integrate with your syslog receiver, configure your forwarding settings. For more information see, Configure notification forwarding.
Last updated
Was this helpful?
