<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to configure Cortex XDR Alerts into Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Cortex-XDR-Alerts-into-Splunk/m-p/555596#M92009</link>
    <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;
&lt;P&gt;We are receiving PaloAlto Cortex XDR logs to splunk via syslog in CEF format as given in the below link:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.logrhythm.com/docs/devices/syslog-log-sources/syslog-palo-alto-cortex-xdr/cortex-alert-messages" target="_blank" rel="noopener"&gt;https://docs.logrhythm.com/docs/devices/syslog-log-sources/syslog-palo-alto-cortex-xdr/cortex-alert-messages&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/logs/cortex-xdr-log-notification-formats/management-audit-log-notification-format.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/logs/cortex-xdr-log-notification-formats/management-audit-log-notification-format.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;With the PaloAlto Networks Add-on we were unable to find the proper sourcetype for extracting the fields.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/2757/#/overview" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/2757/#/overview&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Also the git project for this addon doesnot have any reference of this data:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/PaloAltoNetworks/Splunk-Apps/tree/develop/demo/samples" target="_blank" rel="noopener"&gt;https://github.com/PaloAltoNetworks/Splunk-Apps/tree/develop/demo/samples&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Does anyone managed to address this? If so, how? we need to write our own sourcetype configurations for this kind of data?&lt;/P&gt;
&lt;P&gt;Thanks a lot for the help in advance!&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;BK&lt;/P&gt;</description>
    <pubDate>Tue, 31 May 2022 18:07:51 GMT</pubDate>
    <dc:creator>bharathkumarnec</dc:creator>
    <dc:date>2022-05-31T18:07:51Z</dc:date>
    <item>
      <title>How to configure Cortex XDR Alerts into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Cortex-XDR-Alerts-into-Splunk/m-p/555596#M92009</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;
&lt;P&gt;We are receiving PaloAlto Cortex XDR logs to splunk via syslog in CEF format as given in the below link:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.logrhythm.com/docs/devices/syslog-log-sources/syslog-palo-alto-cortex-xdr/cortex-alert-messages" target="_blank" rel="noopener"&gt;https://docs.logrhythm.com/docs/devices/syslog-log-sources/syslog-palo-alto-cortex-xdr/cortex-alert-messages&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/logs/cortex-xdr-log-notification-formats/management-audit-log-notification-format.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/logs/cortex-xdr-log-notification-formats/management-audit-log-notification-format.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;With the PaloAlto Networks Add-on we were unable to find the proper sourcetype for extracting the fields.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/2757/#/overview" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/2757/#/overview&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Also the git project for this addon doesnot have any reference of this data:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/PaloAltoNetworks/Splunk-Apps/tree/develop/demo/samples" target="_blank" rel="noopener"&gt;https://github.com/PaloAltoNetworks/Splunk-Apps/tree/develop/demo/samples&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Does anyone managed to address this? If so, how? we need to write our own sourcetype configurations for this kind of data?&lt;/P&gt;
&lt;P&gt;Thanks a lot for the help in advance!&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;BK&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 18:07:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Cortex-XDR-Alerts-into-Splunk/m-p/555596#M92009</guid>
      <dc:creator>bharathkumarnec</dc:creator>
      <dc:date>2022-05-31T18:07:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Alerts into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Cortex-XDR-Alerts-into-Splunk/m-p/562347#M100177</link>
      <description>&lt;P&gt;Hey,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had the same issues. I am using TRAPS4 for the sourcetype. And had to manually map the datasets. This worked well for us since we get reports on configuration changes and agent logs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The New PAN Addon/App 7.0.X Supports the Cortex API. Please refence the following:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunk.paloaltonetworks.com/cortex-xdr.html" target="_blank"&gt;Cortex XDR · GitBook (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 03:12:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Cortex-XDR-Alerts-into-Splunk/m-p/562347#M100177</guid>
      <dc:creator>Nomadic_Splunk</dc:creator>
      <dc:date>2021-08-06T03:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Alerts into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Cortex-XDR-Alerts-into-Splunk/m-p/599631#M104554</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/217978"&gt;@bharathkumarnec&lt;/a&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I have the need to ingest Cortex XDR logs into Splunk - are you using Splunk Connect for Syslog to ingest this data?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2022 20:46:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Cortex-XDR-Alerts-into-Splunk/m-p/599631#M104554</guid>
      <dc:creator>splunk_w_ro</dc:creator>
      <dc:date>2022-05-27T20:46:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Alerts into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Cortex-XDR-Alerts-into-Splunk/m-p/599632#M104555</link>
      <description>&lt;P&gt;No, Palo Alto does not support syslog logging for Cortex XDR. Only the API method is supported and it doesn't tell you much. There is zero CIM mapping for compliance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunk.paloaltonetworks.com/cortex-xdr.html" target="_blank" rel="noopener"&gt;Cortex XDR · GitBook (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Example Data:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;alert_categories&lt;/SPAN&gt;:&amp;nbsp;[&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;Impact&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;]&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;alert_count&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;alerts_grouping_status&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;Disabled&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;assigned_user_mail&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;assigned_user_pretty_name&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;creation_time&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;1653682350413&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;critical_severity_alert_count&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;description&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;'Sensitive account password reset attempt' generated by XDR Analytics BIOC detected on host &amp;lt;HOST&amp;gt; involving user &amp;lt;USER&amp;gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;detection_time&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;high_severity_alert_count&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;host_count&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;hosts&lt;/SPAN&gt;:&amp;nbsp;[&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&amp;lt;HOST&amp;gt;:&amp;lt;GUID&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;]&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;incident_id&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;XXXX&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;incident_name&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;incident_sources&lt;/SPAN&gt;:&amp;nbsp;[&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;XDR Analytics BIOC&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;]&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;low_severity_alert_count&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;manual_description&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;manual_score&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;manual_severity&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;med_severity_alert_count&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;mitre_tactics_ids_and_names&lt;/SPAN&gt;:&amp;nbsp;[&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;TA0040 - Impact&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;]&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;mitre_techniques_ids_and_names&lt;/SPAN&gt;:&amp;nbsp;[&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;T1531 - Account Access Removal&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;]&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;modification_time&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;1653683107818&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;notes&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;rule_based_score&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;severity&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;low&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;starred&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;false&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;status&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;new&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;user_count&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;users&lt;/SPAN&gt;:&amp;nbsp;[&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&amp;lt;USER&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;]&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;wildfire_hits&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;xdr_url&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;https://&amp;lt;COMPNAY&amp;gt;.xdr.&amp;lt;REGION&amp;gt;.paloaltonetworks.com/incident-view?caseId=xxxxx&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2022 20:59:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Cortex-XDR-Alerts-into-Splunk/m-p/599632#M104555</guid>
      <dc:creator>Nomadic_Splunk</dc:creator>
      <dc:date>2022-05-27T20:59:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Alerts into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Cortex-XDR-Alerts-into-Splunk/m-p/599916#M104605</link>
      <description>&lt;P&gt;Thanks for getting back to me - per the PAN documentation (&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/logs" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/logs&lt;/A&gt;), it looks like alerts can be sent to a syslog receiver. It's disappointing that you can't get those using an input within the PAN TA.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 14:15:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Cortex-XDR-Alerts-into-Splunk/m-p/599916#M104605</guid>
      <dc:creator>splunk_w_ro</dc:creator>
      <dc:date>2022-05-31T14:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Alerts into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Cortex-XDR-Alerts-into-Splunk/m-p/599969#M104613</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/246267"&gt;@splunk_w_ro&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Don't get me wrong, you can send them to a syslog receiver, you'll just need to write your own parsing from the pan::log SourceType which is owned by the PAN_TA which creates a really nasty problem of needing to do the changes everytime the PAN_TA is updated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 18:02:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Cortex-XDR-Alerts-into-Splunk/m-p/599969#M104613</guid>
      <dc:creator>Nomadic_Splunk</dc:creator>
      <dc:date>2022-05-31T18:02:22Z</dc:date>
    </item>
  </channel>
</rss>

