> ## Documentation Index
> Fetch the complete documentation index at: https://docs-xcor.paloaltonetworks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Route logs over HTTP

> Use the Cortex XCOR logging HTTP endpoint to send logs to your Cortex XCOR tenant over HTTP.

export const MyTenantList = () => <>
    <em><code>TENANT</code></em>: The name of your Cortex XCOR tenant.
  </>;

Use the Palo Alto Networks Cortex XCOR logging HTTP endpoint to send your logs to Cortex
XCOR over HTTP.
The endpoint uses the following format:

```text theme={null}
https://TENANT.chronosphere.io/api/v1/data/logs/ingest
```

* <MyTenantList />

In addition to formatted log data, such as JSON, the logging HTTP endpoint accepts
logs in plain text format. To minimize egress costs, this endpoint supports `gzip`,
`snappy`, and `zstd` compression methods.

Because the Cortex XCOR API requires authentication, include an API token with your
`curl` request, as shown in the following example. For more details, see
[Create an API token](/tooling/api-info#create-an-api-token).

```shell /"TOKEN"/ /INSTANCE/ /METHOD/ /ENDPOINT_PATH/ theme={null}
export CHRONOSPHERE_API_TOKEN="TOKEN"
export CHRONOSPHERE_DOMAIN="INSTANCE.chronosphere.io"

curl -H "API-Token: ${CHRONOSPHERE_API_TOKEN}" \
     -X METHOD "https://${CHRONOSPHERE_DOMAIN}/ENDPOINT_PATH"
```

Replace the following:

* *`TOKEN`*: Your API token.
* *`INSTANCE`*: The subdomain name for your organization's Cortex XCOR instance.
* *`METHOD`*: The HTTP method to use with the request, such as `GET` or `POST`.
* *`ENDPOINT_PATH`*: The specific endpoint you want to access.

<Note>
  The service account must have read access to route log data to Cortex XCOR.
</Note>

The following example shows a formatted `curl` request that includes the logging HTTP endpoint:

```shell wrap theme={null}
export CHRONOSPHERE_API_TOKEN="TOKEN"
export CHRONOSPHERE_DOMAIN="INSTANCE.chronosphere.io"

curl -H "API-Token: ${CHRONOSPHERE_API_TOKEN}" \
     -X METHOD "https://${CHRONOSPHERE_DOMAIN}.chronosphere.io/api/v1/data/logs/ingest"
```

## Limits

The logging HTTP endpoint has the following limits:

* Logs with timestamps exceeding 24 hours into the future or past are rejected.
* Requests (compressed) exceeding 50 MB are rejected.

## Status codes

The logging HTTP endpoint returns the following status codes:

* `200`: Accepted. The request was accepted for processing.
* `413`: Large request. The maximum content size per payload (compressed) is
  50 MB.


## Related topics

- [Route logs from Logstash](/ingest/logs/logstash-logs.md)
- [Route logs from Fluent Bit](/ingest/logs/fluentbit-logs.md)
- [Ingest log data](/ingest/logs.md)
- [Integrate with Cortex XCOR](/integrate.md)
- [Route logs through Palo Alto Networks Telemetry Pipeline](/ingest/logs/pipeline-logs.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.