Workday
Configure the Workday data source and connectors in Cortex XSIAM.
You can configure collecting Workday report data using a standard collector, content pack integration (onboarded prior to July 26, 2026), or connector:
Standard collector overview
Forward Workday report data to Cortex XSIAM using the Workday data source.
Link to standard collector instructions
Links to content pack/integration details (onboarded prior to July 26, 2026)
The Workday content pack provides solutions for financial management, human resources, and planning, specifically supporting the collection and modeling of user activity audit logs and sign-on events. It contains classifiers, modeling rules, and parsing rules, as well as the following integrations:
Workday Event Collector: Use this integration containing the
workday-get-activity-loggingcommand to get activity logs from Workday. It requires theWorkday Parsing RuleandWorkday Modeling Rulefor parsing and modeling ingested data.Workday: Use this integration containing the
workday-list-workerscommand to return information for specific workers.Workday IAM: Use this integration containing the
workday-iam-get-full-reportcommand to return report entries from Workday. It is part of the part of the IAM premium pack.Workday Sign On Event Collector: Use this integration containing the
workday-get-sign-on-eventscommand to get sign-on logs from Workday. This command is used for developing/debugging and is to be used with caution, as it can create events, leading to events duplication and exceeding the API request limitation.
Link to connector
Workday Automation and Collection (onboarded after July 26, 2026)
Last updated
Was this helpful?
