Skip to main content
You can route log data from Logstash to Palo Alto Networks Cortex XCOR. To route logs, configure an HTTP output plugin in your Logstash pipeline configuration file that specifies your Cortex XCOR tenant as a destination.
  1. In your Logstash pipeline configuration file, add an output section that defines the http plugin:
    • The service account must have read access to route log data to Cortex XCOR.
    • Optional: The format=>"json_batch" option collects each batch of events received by the output and places them into a single JSON array that’s sent in one request.
  2. After defining the output, contact Cortex XCOR Support and indicate which field in your data contains log timestamps.