> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cribl/ingest-data-from-cribl/data-souce-uuids.md).

# Data souce UUIDs

This table lists the Cribl catalog for the the specific collectors supported. If a dedicated collector does not exist, use the generic UUID collector.

Any data source can be ingested using the generic UUID collector with the correct vendor and product fields. Yet, while parsing and modeling rules can be applied to any source, out-of-the-box (OOTB) analytics are only available for data sources using dedicated UUIDs.

### Indicate specific vendor name as not listed below (Generic)

| Product                                                      | UUID                                                                                                                      | Datasets                   | Collection Method |
| ------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------- | -------------------------- | ----------------- |
| Indicate specific product name as not listed below (Generic) | <p>af01292940d7426594d3d3e55ae17ee0</p><p>Do not use this generic UUID when your data source is listed in this table.</p> | \<Vendor>\_\<Product>\_raw |                   |

### Amazon

| Product           | UUID                                                                                                           | Datasets                                                                                                                    | Collection Method                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ----------------- | -------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| AWS audit logs    | c19f87b6262f48259b3d5d2a2c691802                                                                               | `amazon_aws_raw`                                                                                                            | These AWS logs are collected via Amazon S3. To ensure compatibility, see [Ingest audit logs from AWS Cloud Trail](/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-s3/ingest-audit-logs-from-aws-cloudtrail.md).                                                                                                                                                     |
| AWS EKS           | fb8a9d4922cb4095b76d71e921d2d999                                                                               | `amazon_eks_raw`                                                                                                            | These AWS logs are collected via Amazon CloudWatch. To ensure collector compatibility, see [Ingest logs from Amazon CloudWatch](/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-cloud-watch/ingest-logs-from-amazon-cloudwatch.md).                                                                                                                                 |
| AWS flow logs     | 667083aa68544eee8b67cdd2d4cc327b                                                                               | `amazon_aws_raw`                                                                                                            | These logs are collected via Amazon S3. To ensure collector compatibility, see [Ingest network flow logs from Amazon S3](/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-s3/ingest-network-flow-logs-from-amazon-s3.md).                                                                                                                                            |
| AWS generic logs  | 0498f8a24de04b3e85102e742f6783f8                                                                               | `amazon_aws_raw`                                                                                                            | These logs are collected via Amazon S3. To ensure collector compatibility, see [Ingest generic logs from Amazon S3](/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-s3/ingest-generic-logs-from-amazon-s3.md).                                                                                                                                                      |
| AWS prompt logs   | a53edad7ef0c46ffb5037fb2e21520cb                                                                               | `amazon_aws_raw`                                                                                                            | For setup details, see [Prompt log collection in AWS](/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/prompt-log-collection-in-aws.md).                                                                                                                                                                            |
| AWS Route 53 logs | <p></p><ul><li>d57ae82c1e2a4d138fc34084d159b09e (old)</li><li>0a7544038b444998a20e698669817e3d (new)</li></ul> | <ul><li><code>amazon\_route53\_raw</code> (via old UUID)</li><li><code>amazon\_route53\_raw</code> (via new UUID)</li></ul> | These logs are collected via Amazon S3. Using the old UUID routes data to the generic AWS dataset. For native routing to the Route 53 dataset, use the new dedicated UUID. To ensure collector compatibility, see [Ingest network Route 53 logs from Amazon S3](/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-s3/ingest-network-route-53-logs-from-amazon-s3.md). |

### Box

| Product | UUID                             | Datasets                                                                                                                                                                                                                              | Collection Method                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| ------- | -------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Box     | 3ef05d14ae9349f8bbd48c8a4797334a | <ul><li>Events (admin\_logs): <code>box\_admin\_logs\_raw</code></li><li>Box Shield Alerts: <code>box\_shield\_alerts\_raw</code></li><li>Users: <code>box\_users\_raw</code></li><li>Groups: <code>box\_groups\_raw</code></li></ul> | <p>The <code>BOX\_DIRECTORIES</code> connector queries the following Box API endpoints:</p><ul><li><p><strong>Users</strong></p><ul><li>Endpoint: <code><https://api.box.com/2.0/users></code></li><li>Purpose: To fetch the list of users in Box enterprise.</li></ul></li><li><p><strong>Groups</strong></p><ul><li>Endpoint: <code><https://api.box.com/2.0/groups></code></li><li>Purpose: To fetch the list of groups in Box enterprise.</li></ul></li></ul><p>For setup details, see <a href="/pages/9W4NXadJIgGVPDvt43Kz">Ingest logs and data from Box</a>.</p> |

### CrowdStrike

| Product         | UUID                             | Datasets                          | Collection Method                                                                                                                                                                                                                                                                                                                                                                                        |
| --------------- | -------------------------------- | --------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Falcon incident | 230b2b0233bf4327806af72e6e5769f3 | `crowdstrike_falcon_incident_raw` | <p>Currently not supported by Cribl</p><p>CrowdStrike Streaming API</p><p>Base URL: <code><https://api.crowdstrike.com></code> (or <code>api.us-2.crowdstrike.com</code>, <code>api.eu-1.crowdstrike.com</code>, etc.)</p><p><code>GET /sensors/entities/datafeed/v2</code></p><p>For setup details, see <a href="/pages/NUvo15w9TyX30ZjJWV1L">Ingest alerts and metadata from CrowdStrike APIs</a>.</p> |
| Hosts           | 8b673ac8e2f34b4a8dc14c22f0e6063b | `crowdstrike_hosts_raw`           | <p>CrowdStrike Devices API</p><p><code>GET /devices/queries/devices-scroll/v1</code></p><p><code>POST /devices/entities/devices/v2</code></p><p>For setup details, see <a href="/pages/NUvo15w9TyX30ZjJWV1L">Ingest alerts and metadata from CrowdStrike APIs</a>.</p>                                                                                                                                   |

### Dropbox

| Product   | UUID                             | Datasets                                                                                                                                         | Collection Method                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| --------- | -------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Directory | e8d2c52bc9594621924fab0507264586 | <ul><li><code>dropbox\_members\_devices\_raw</code></li><li><code>dropbox\_users\_raw</code></li><li><code>dropbox\_groups\_raw</code></li></ul> | <p>Base URL: <code><https://api.dropboxapi.com></code></p><ul><li><p>Users (dropbox\_users\_raw)</p><ul><li>Endpoint: <code>/2/team/members/list\_v2</code></li></ul></li><li><p>Groups (dropbox\_groups\_raw)</p><ul><li>Endpoint: <code>/2/team/groups/list</code></li></ul></li><li><p>Devices (dropbox\_member\_devices\_raw)</p><ul><li>Endpoint: <code>/2/team/devices/list\_members\_devices</code></li></ul></li></ul><p>For setup details, see <a href="/pages/CCQhRBosDlCWnXaBZ1Zk">Ingest logs and data from Dropbox</a>.</p> |
| Events    | a6322b2fd9e545e0a4223ba754c48fb9 | `dropbox_events_raw`                                                                                                                             | <p>Base URL: <code><https://api.dropboxapi.com></code></p><p>Endpoint: <code>/2/team\_log/get\_events</code></p><p>For setup details, see <a href="/pages/CCQhRBosDlCWnXaBZ1Zk">Ingest logs and data from Dropbox</a>.</p>                                                                                                                                                                                                                                                                                                               |

### Google

| Product                              | UUID                             | Datasets                                 | Collection Method                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| ------------------------------------ | -------------------------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Cloud Logging (audit logs/flow logs) | 00a8322c85e14beabfa7ad5f3d62db73 | `google_cloud_logging_raw`               | For setup details, see [Ingest logs and data from a GCP Pub/Sub](/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google/google-cloud-platform/ingest-logs-and-data-from-a-gcp-pub-sub.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Gmail                                | 8607490288d1407ba82b5c5ad9dc64a0 | `google_gmail_raw`                       | <p><code>GET <https://gmail.googleapis.com/gmail/v1/users/{userId}/messages></code></p><p>For setup details, see <a href="/pages/k42XTN7awfOTeP6iYlsB">Ingest logs and data from Google Workspace</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Workspace alerts                     | 4f263650cd29475c81f2ff953cf19827 | `google_workspace_alerts_raw`            | <p>Description: Ingests security and system alerts from the Google Workspace Alert Center.</p><ul><li><p>API Details</p><ul><li>API Name: Google Alert Center API</li><li>Version: <code>v1beta1</code></li><li>Base URL: <code><https://alertcenter.googleapis.com></code></li><li>Endpoint: <code>/v1beta1/alerts</code></li><li>Method: <code>GET (List)</code></li><li>OAuth Scope: <code><https://www.googleapis.com/auth/apps.alerts></code></li></ul></li><li><p>Request Parameters</p><ul><li>filter: Used for incremental ingestion based on <code>createTime</code>.</li><li>Format: <code>createTime >= "\[TIMESTAMP\_START]" AND createTime \&#x3C; "\[TIMESTAMP\_END]"</code></li><li>orderBy: <code>createTime asc</code></li><li>pageToken: Used for pagination.</li></ul></li><li><p>Data Mapping</p><ul><li>Source: The full JSON response object from the <code>alerts</code> list.</li><li>Destination: Each alert object is ingested as a single record.</li></ul></li></ul><p>For setup details, see <a href="/pages/k42XTN7awfOTeP6iYlsB">Ingest logs and data from Google Workspace</a>.</p> |
| Workspace ChromeOS devices           | e82ae276e6b9442fa80920a03d2a38d6 | `google_workspace_chrome_raw`            | <p><code>GET <https://admin.googleapis.com/admin/directory/v1/customer/{customer}/devices/chromeos></code></p><p>For setup details, see <a href="/pages/k42XTN7awfOTeP6iYlsB">Ingest logs and data from Google Workspace</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Workspace groups                     | 689ae8ef14e848e3855b81e91d8af9bc | `google_workspace_enterprise_groups_raw` | <p><code>GET <https://admin.googleapis.com/admin/directory/v1/groups></code></p><p>For setup details, see <a href="/pages/k42XTN7awfOTeP6iYlsB">Ingest logs and data from Google Workspace</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Workspace rules                      | 2621aaf3334a4147ae727afe84db31a9 | `google_workspace_rules_raw`             | <p><code>GET <https://gmail.googleapis.com/gmail/v1/users/{userId}/settings/filters></code></p><p>For setup details, see <a href="/pages/k42XTN7awfOTeP6iYlsB">Ingest logs and data from Google Workspace</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Workspace users                      | 359ecd845fa54caab6ddb4b7c7a2764d | `google_workspace_user_acounts_raw`      | <p><code>GET <https://admin.googleapis.com/admin/directory/v1/users/{userKey}></code></p><p>For setup details, see <a href="/pages/k42XTN7awfOTeP6iYlsB">Ingest logs and data from Google Workspace</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |

### Microsoft

| Product                      | UUID                             | Datasets                          | Collection Method                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ---------------------------- | -------------------------------- | --------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Azure                        | fce13a1d51294f84bae4a37851503060 | `msft_azure_raw`                  | Azure Event Hubs SDK (AMQP): For setup details, see [Ingest logs from Microsoft Azure Event Hub](/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-event-hub/ingest-logs-from-microsoft-azure-event-hub.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Azure AD                     | c00d6d52e5b141a8baa8db9d9345423d | `msft_azure_ad_raw`               | For set up details, see [Ingest logs from Microsoft Office 365](/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-office-365/ingest-logs-from-microsoft-office-365.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Azure AD audit               | 0e076d5abe864bf78e8145ea9e0d749e | `msft_azure_ad_audit_raw`         | <p>Microsoft Graph API: <code>GET /v1.0/auditLogs/directoryaudits</code></p><p>For set up details, see <a href="/pages/QOGdoAK0N5DbsEAotzRY">Ingest logs from Microsoft Office 365</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Azure AD sign-ins            | f56dcfdf6bca43e793a4b6e9290e7b12 | `msft_azure_ad_raw`               | <p>Microsoft Graph API: <code>GET /v1.0/auditLogs/signIns</code></p><p>For set up details, see <a href="/pages/QOGdoAK0N5DbsEAotzRY">Ingest logs from Microsoft Office 365</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Defender                     | ce9e8cf36e0742c38aa89787a256855f | `msft_defender_raw`               | <p>Azure Event Hubs SDK (AMQP): For setup details, see <a href="/pages/x9mEFw2SlO5111d9WdUM">Ingest raw EDR events from Microsoft Defender for Endpoint</a>.</p><p>To enable analytics, contact <a href="https://support.paloaltonetworks.com/Support/Index">Customer Support</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| DHCP                         | b55819e8959c49728d5d98a6d87eafb6 | `msft_dhcp_raw`                   | <p><code>File Collection: C:\Windows\System32\dhcp\DhcpSrvLog-\*.log</code></p><p>For set up details, see <a href="/pages/tr1F2J42PtgiO2WrMQrQ">Ingest logs from Windows DHCP using Elasticsearch Filebeat</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Graph security alerts        | 5619f2f691fc46c4b202587fdaa031c3 | `msft_graph_security_alerts_raw`  | <p>Microsoft Graph API: <code>/v1.0/security/alerts\_v2</code></p><p>For set up details, see <a href="/pages/QOGdoAK0N5DbsEAotzRY">Ingest logs from Microsoft Office 365</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Office 365 Azure AD          | e1f109f886ea42fbb96be6ec0cc597a9 | `msft_o365_azure_ad_raw`          | <p>The Base URLs for the APIs are (depending on the environment):</p><p>Worldwide: <code><https://manage.office.com></code></p><p>GCC: <code><https://manage-gcc.office.com></code></p><p>GCC High: <code><https://manage.office365.us></code></p><p>DoD: <code><https://manage.protection.apps.mil></code></p><p>Endpoints:</p><p>Start Subscription: <code>/api/v1.0/{tenantID}/activity/feed/subscriptions/start?contentType={type}</code></p><p>List Available Content: <code>/api/v1.0/{tenantID}/activity/feed/subscriptions/content?contentType={type}</code></p><p>Fetch Content Blob: Dynamic URI returned from the “List Available Content” call.</p><p>Content Types: <code>audit.exchange</code>, <code>audit.sharepoint</code>, <code>audit.general</code>, <code>audit.azureactivedirectory</code>, <code>dlp.all</code>.</p><p>For set up details, see <a href="/pages/QOGdoAK0N5DbsEAotzRY">Ingest logs from Microsoft Office 365</a>.</p> |
| Office 365 DLP               | 8f052782739d4b8389644cca23b994ac | `msft_o365_dlp_raw`               | <p>See Office 365 Azure AD.</p><p>For set up details, see <a href="/pages/QOGdoAK0N5DbsEAotzRY">Ingest logs from Microsoft Office 365</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Office 365 domains           | cae29fd87b554bd9a5694afb225e8dc9 | `msft_o365_domains_raw`           | Microsoft Graph API: `GET /v1.0/domains`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Office 365 Exchange Online   | dee8e85ce7db4573a8bc21b807e1d73a | `msft_o365_exchange_online_raw`   | <p>See Office 365 Azure AD.</p><p>For set up details, see <a href="/pages/QOGdoAK0N5DbsEAotzRY">Ingest logs from Microsoft Office 365</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Office 365 General           | c7655e83805b4a058e66043a6715156c | `msft_o365_general_raw`           | <p>See Office 365 Azure AD.</p><p>For set up details, see <a href="/pages/QOGdoAK0N5DbsEAotzRY">Ingest logs from Microsoft Office 365</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Office 365 Sharepoint Online | 3a37f519e9094a3f8c4185fa572cd111 | `msft_o365_sharepoint_online_raw` | <p>See Office 365 Azure AD.</p><p>For set up details, see <a href="/pages/QOGdoAK0N5DbsEAotzRY">Ingest logs from Microsoft Office 365</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Office 365 contacts (email)  | de1b694a6c8341958bc08c4b7c140874 | `msft_o365_contacts_raw`          | <p>Microsoft Graph API: <code>GET /v1.0/users/{id}/mailFolders/inbox/messageRules</code></p><p>For set up details, see <a href="/pages/5HiEaajpzHTtlIbjgaET">Ingest logs and data from Microsoft 365</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Office 365 devices (email)   | de229685f708413fad46289657ea09de | `msft_o365_devices_raw`           | <p>Microsoft Graph API: <code>GET /v1.0/users/{id}/registeredDevices</code></p><p>For set up details, see <a href="/pages/5HiEaajpzHTtlIbjgaET">Ingest logs and data from Microsoft 365</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Office 365 groups (email)    | 0b0499ac0d984145b201c6d674771dbf | `msft_o365_groups_raw`            | <p>Microsoft Graph API: <code>GET /v1.0/groups</code></p><p>For set up details, see <a href="/pages/5HiEaajpzHTtlIbjgaET">Ingest logs and data from Microsoft 365</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Office 365 mailboxes (email) | 9855a03559ce4263b568671e695d1fa8 | `msft_o365_mailboxes_raw`         | <p>The Base URLs for the APIs are (depending on the environment): <code>[https://graph.microsoft.com\&#x3C;/code>](https://graph.microsoft.com\&#x3C;/code>) (or \<code><https://graph.microsoft.us`></code> for FedRAMP)</p><p>Incoming Messages: <code>GET /v1.0/users/{id}/messages</code></p><p>Outgoing Messages: <code>GET /v1.0/users/{id}/mailFolders/sentitems/messages/delta</code></p><p>For set up details, see <a href="/pages/5HiEaajpzHTtlIbjgaET">Ingest logs and data from Microsoft 365</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Office 365 rules (email)     | 6b925df8923d4038bf78998d1ffde77c | `msft_o365_rules_raw`             | <p>Microsoft Graph API: <code>/users/{id}/mailFolders/inbox/messageRules</code></p><p>For set up details, see <a href="/pages/5HiEaajpzHTtlIbjgaET">Ingest logs and data from Microsoft 365</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Office 365 users (email)     | dcfb7a412e654efd868de0b8cf81766a | `msft_o365_users_raw`             | <p>Microsoft Graph API: <code>GET /v1.0/users</code></p><p>For set up details, see <a href="/pages/5HiEaajpzHTtlIbjgaET">Ingest logs and data from Microsoft 365</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Windows Event Logs           | 63b0fbeb501e4650896e7064d3412e14 | `microsoft_windows_raw`           | For more information, see [Collect Windows Event Logs for Cortex XSIAM via Cribl](/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cribl/ingest-data-from-cribl/collect-windows-event-logs-for-cortex-xsiam-via-cribl.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |

### Okta

| Product | UUID                             | Datasets       | Collection Method                                                                                                                                                                                                                        |
| ------- | -------------------------------- | -------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| SSO     | 5faf4c1fdb8443d9920d6a54815432c1 | `okta_sso_raw` | <p>Okta System Log API</p><p>Base URL: <code>https\://{your-okta-domain}.okta.com</code></p><p><code>GET /api/v1/logs</code></p><p>For set up details, see <a href="/pages/YrAuueNjX5qcysm90YVL">Ingest logs and data from Okta</a>.</p> |

### OneLogin

| Product  | UUID                             | Datasets                                                                                                                                | Collection Method                                                                                                                                                                                                                               |
| -------- | -------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Events   | 22b23a3f9f1e49998645b683d5dc3a6f | `onelogin_events_raw`                                                                                                                   | <p>Base URL: <code>https\://\<subdomain>.onelogin.com</code></p><p>Endpoint: <code>/api/1/events\`</code></p><p>For set up details, see <a href="/pages/OrztTF17lXjdJYk2IX6W">Ingest logs and data from OneLogin</a>.</p>                       |
| OneLogin | 88cfbd3e7b974d999b10edac83995b8a | <ul><li><code>onelogin\_users\_raw</code></li><li><code>onelogin\_groups\_raw</code></li><li><code>onelogin\_apps\_raw</code></li></ul> | <p>Base URL: <code>https\://\<subdomain>.onelogin.com</code></p><p>Endpoints: <code>/api/1/users/api/1/groups/api/2/apps</code></p><p>For set up details, see <a href="/pages/OrztTF17lXjdJYk2IX6W">Ingest logs and data from OneLogin</a>.</p> |

### PingID

| Product | UUID                             | Datasets             | Collection Method                                                                                                                                                                                                                                                                                              |
| ------- | -------------------------------- | -------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| PingONE | 924951a8394b4605b1725f943292ab4f | `pingid_pingone_raw` | <p>PingOne API:</p><p>Base URL: <code><https://admin-api.pingone.com></code></p><p>Endpoint: <code>/v3/reports/{account\_id}/poll-subscriptions/{subscription\_id}/events</code></p><p>For set up details, see <a href="/pages/NHtfTkMzqmoZviaq8RkV">Ingest authentication logs and data from PingOne</a>.</p> |

### Proofpoint

| Product | UUID                             | Datasets             | Collection Method                                                                                                                                                                                                                                    |
| ------- | -------------------------------- | -------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| TAP     | 3eefce0f791e4391a3643b8cf860a361 | `proofpoint_tap_raw` | <p>API Base URL: <code><https://tap-api-v2.proofpoint.com></code></p><p>Resource Path: <code>/v2/siem/all</code></p><p>For set up details, see <a href="/pages/ZWbhV9C9AIpgscId2fJa">Ingest logs from Proofpoint Targeted Attack Protection</a>.</p> |

### Salesforce: Salesforce logs

| UUID                             | Datasets                                                                                                                                             | Collection Method                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| -------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| ab109687acd24978aabcb7ad8b5742e3 | <ul><li><code>salesforce\_login\_raw</code></li><li><code>salesforce\_audit\_raw</code></li><li><code>salesforce\_eventlogfile\_raw</code></li></ul> | <p>The data schema for <code>salesforce\_eventlogfile\_raw</code> is dynamic and not hardcoded in the data collector's source code.</p><p>Here's how it works:</p><p>Dynamic Field Discovery: The collector calls the Salesforce describe endpoint (<code>/services/data/v56.0/sobjects/EventLogFile/describe</code>) to retrieve the list of all available fields for the <code>EventLogFile</code> object.</p><p>Query Construction: It constructs a SOQL query selecting all these discovered fields, such as <code>SELECT Id</code>, <code>LogFile</code>, <code>LogDate</code>,.... <code>FROM EventLogFile</code>).</p><p>CSV to JSON: The downloaded log files are in CSV format. The collector converts each CSV row into a JSON object where the keys are the CSV headers (which correspond to the fields discovered in the Dynamic Field Discovery explained above).</p><p>For set up details, see Ingest logs and data from Salesforce.</p> |

### Salesforce: Salesforce snapshots

| UUID                             |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| -------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| addbf31a6372491e88d45934dff5b5b0 | <p>The data fetched by this data collector is written to datasets based on the Salesforce object being retrieved. The data collector dynamically sets the Product field in the response to the name of the Salesforce object. Assuming the standard naming convention <code>\<vendor>\_\<product>\_raw</code> (where Vendor is salesforce); the data will be written to the following datasets (corresponding to the objects defined in <code>consts.go</code>):</p><ul><li><code>salesforce\_ConnectedApplication\_raw</code></li><li><code>salesforce\_PermissionSet\_raw</code></li><li><code>salesforce\_Profile\_raw</code></li><li><code>salesforce\_GroupMember\_raw</code></li><li><code>salesforce\_Group\_raw</code></li><li><code>salesforce\_User\_raw</code></li><li><code>salesforce\_UserRole\_raw</code></li><li><code>salesforce\_TenantSecurityLogin\_raw</code></li><li><code>salesforce\_UserAccountTeamMember\_raw</code></li><li><code>salesforce\_TenantSecurityUserPerm\_raw</code></li></ul> | <p>Authentication:</p><p>Path: <code>/services/oauth2/token</code></p><p>Purpose: Used for obtaining and refreshing access tokens.</p><p>Data Query:</p><p>Path: <code>/services/data/v56.0/queryAll</code></p><p>Purpose: Used to execute SOQL queries to fetch records for the snapshot objects, such as User, Profile, and Group.</p><p>Object Description:</p><p>Path: <code>/services/data/v56.0/sobjects/{object}/describe</code></p><p>Purpose: Used to dynamically retrieve the list of fields for a specific object before querying it.</p><p>All endpoints are relative to the base URL: https\://{domain}.my.salesforce.com.</p><p>For set up details, see <a href="/pages/GHFgg2AjrdVD6id73OuD">Ingest logs and data from Salesforce</a>.</p> |

### Sentinel One: Deep Visibility

| UUID                             | Datasets                          | Collection Method                                                                                                                                                                                                                                     |
| -------------------------------- | --------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| b9fa55e6fa564c709358425ce0f61517 | `sentinelone_deep_visibility_raw` | <p>For set up details, see <a href="/pages/EuiG6jdx436G3FIHIB4o">Ingest raw EDR events from SentinelOne DeepVisibility</a>.</p><p>To enable analytics, contact <a href="https://support.paloaltonetworks.com/Support/Index">Customer Support</a>.</p> |

### Service Now: CDMB

| UUID                             | Datasets                                                    | Collection Method                                                                                                                                                                                                                                           |
| -------------------------------- | ----------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| 8b3e767247e44471a95e563378d0b9be | <p>servicenow\_cmdb\_</p><p><em>\<table name>\_raw</em></p> | <p>ServiceNow Table API</p><p>Base URL: <code>https\://{instance}.service-now\.com</code></p><p><code>GET /api/now/table/{table\_name}</code></p><p>For set up details, see <a href="/pages/1Z37kYwbFv08wUdfW0mA">Ingest data from ServiceNow CMDB</a>.</p> |

Workday

| UUID                             | Datasets              | Collection Method                                                                                                                                                                          |
| -------------------------------- | --------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| 00d4e740702d4eb2939a87c2318513dd | `workday_workday_raw` | <p>Workday Report-as-a-Service (RaaS)</p><p>Endpoint: Configurable Report URL</p><p>For set up details, see <a href="/pages/rhd37wbp9yzs3DlXO7ct">Ingest report data from Workday</a>.</p> |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cribl/ingest-data-from-cribl/data-souce-uuids.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
