Skip to main content
Use Palo Alto Networks Telemetry Pipeline to ingest logs from sources such as Fluent Bit, Open Telemetry, and HTTP. Apply parsers and processing rules, then send the output to Palo Alto Networks Cortex XCOR. You create and define a pipeline in Palo Alto Networks Telemetry Pipeline and set Cortex XCOR as a destination. After deploying your pipeline, processed log data streams to Cortex XCOR and is available for exploring and querying in Logs Explorer.

Prerequisites

Before creating a pipeline, you must install Palo Alto Networks Telemetry Pipeline, which includes installing a Core Operator and Core Instance.

Create a pipeline

Specify a source and destination, and apply parsers and processing rules. To route logs through Palo Alto Networks Telemetry Pipeline to Cortex XCOR:
  1. Create a pipeline. Follow the steps outlined in the Palo Alto Networks Telemetry Pipeline documentation.
  2. Add a source, such as Fluent Bit, Elasticsearch, or OpenTelemetry.
  3. Add the Cortex XCOR Logs destination.
  4. Click the Cortex XCOR Logs destination to edit its configuration:
    1. In the General section, in the Host field, enter:
    2. Expand the Advanced section, and in the URI field, enter:
  5. Complete the remaining steps to deploy your pipeline.
After deploying your pipeline, verify that Cortex XCOR is receiving your logs as anticipated.