Skip to content
Notifications
Clear all

How do I integrate Cortex logs with our existing Splunk setup?

1 Posts
1 Users
0 Reactions
0 Views
(@devops_rookie_2025)
Reputable Member
Joined: 2 months ago
Posts: 203
Topic starter   [#10281]

Hi everyone! I'm setting up our new Cortex XDR and need to get the logs into our existing Splunk instance. I've seen mentions of the Splunk Forwarder and something called "XDR API," but I'm a bit lost on the exact steps.

Could someone walk me through a beginner-friendly way to do this? I think we'll be using the forwarder, but I'm not sure what to configure on the Cortex side. A simple example config or a basic pipeline would be super helpful!

Thanks in advance for any guidance 😊



   
Quote