Skip to content

Commit

Permalink
Update cortex-xdr.md (#547)
Browse files Browse the repository at this point in the history
* Update cortex-xdr.md

Fix troubleshooting link and first paragraph

Signed-off-by: Paul Nguyen <[email protected]>

* Update cortex-xdr.md

Signed-off-by: Paul Nguyen <[email protected]>

---------

Signed-off-by: Paul Nguyen <[email protected]>
  • Loading branch information
paulmnguyen authored Nov 30, 2023
1 parent a0f1c90 commit 58365ce
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions products/splunk/docs/cortex-xdr.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ title: Cortex XDR

Cortex XDR is supported starting with App/Add-on 7.0.0.

IoT Security is cloud-hosted so logs are retrieved by Splunk using the IoT Security logging API. Logs are pulled down in JSON format with sourcetype="pan:iot_alert", sourcetype="pan:iot_device" and eventtype="pan_iot_device", eventtype="pan_iot_alert".
Cortex XDR is cloud-hosted so logs are retrieved by Splunk using the Cortex XDR API's. Logs are pulled down in JSON format with sourcetype="pan:xdr_incident".

## Create API Key in Cortex XDR

Expand Down Expand Up @@ -54,4 +54,4 @@ After waiting the interval time, check that logs are coming into Splunk by click

sourcetype="pan:xdr_incident"

You should see some JSON formatted logs show up. If nothing shows up, wait a little longer, ensure there is activity in Cortex XDR to generate logs, and try the [Troubleshooting Guide](/splunk/docs/troubleshoot#troubleshooting-cortex-xdr).
You should see some JSON formatted logs show up. If nothing shows up, wait a little longer, ensure there is activity in Cortex XDR to generate logs, and try the [Troubleshooting Guide](/splunk/docs/troubleshooting/#troubleshooting-cortex-xdr).

0 comments on commit 58365ce

Please sign in to comment.