Notifications
Clear all
Palo Alto Cortex XDR Reviews
1
Posts
1
Users
0
Reactions
0
Views
Topic starter
18/07/2026 1:41 am
Hi everyone! I'm setting up our new Cortex XDR and need to get the logs into our existing Splunk instance. I've seen mentions of the Splunk Forwarder and something called "XDR API," but I'm a bit lost on the exact steps.
Could someone walk me through a beginner-friendly way to do this? I think we'll be using the forwarder, but I'm not sure what to configure on the Cortex side. A simple example config or a basic pipeline would be super helpful!
Thanks in advance for any guidance 😊