Skip to main content
Before you can use Palo Alto Networks Cortex XCOR to view and manage your telemetry data (of whatever type), you need to get that data into Cortex XCOR.

Supported ingestion methods

Cortex XCOR supports multiple methods to ingest telemetry data, which depend on which type of data you want to ingest: After ingesting telemetry data, you can use the control mechanisms that Cortex XCOR provides to control costs and ensure you’re ingesting only the data you care about.

OpenTelemetry support

For more information about using OpenTelemetry to ingest logs, metrics, and traces, see OpenTelemetry support in Cortex XCOR.

Ingestion models

Cortex XCOR utilizes push and pull models of ingestion, depending on the data collected and the method of ingestion. Pull models, like the Chronosphere Collector, scrape telemetry data from external sources and pull it in. These metrics have consistent reporting intervals. Push models, like tracing, send telemetry data to Cortex XCOR, which is then processed. These metrics can have a broad spectrum of reporting frequency, from large bursts of data to long periods with no data reporting. The ingestion model depends on the telemetry data source. Metrics pushed to Cortex XCOR can have latency delays or sparse time series, which can result in unexpected query results.