> ## Documentation Index
> Fetch the complete documentation index at: https://docs-xcor.paloaltonetworks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Route logs through Palo Alto Networks Telemetry Pipeline

> Learn how to route log data through Palo Alto Networks Telemetry Pipeline to Palo Alto Networks Cortex XCOR.

export const MyTenant = () => <>
    Replace <em><code>TENANT</code></em> with the name of your Cortex XCOR tenant.
  </>;

Use Palo Alto Networks Telemetry Pipeline to ingest logs from sources
such as Fluent Bit, Open Telemetry, and HTTP. Apply parsers and processing rules,
then send the output to Palo Alto Networks Cortex XCOR. You create and define a
pipeline in Palo Alto Networks Telemetry Pipeline and set Cortex XCOR as a destination.

After deploying your pipeline, processed log data streams to Cortex XCOR
and is available for [exploring and querying](/investigate/querying/query-logs) in Logs
Explorer.

## Prerequisites

Before creating a pipeline, you must [install Palo Alto Networks Telemetry Pipeline](/ingest/pipeline/v2/install),
which includes installing a Core Operator and Core Instance.

## Create a pipeline

Specify a source and destination, and apply parsers and processing rules.

To route logs through Palo Alto Networks Telemetry Pipeline to Cortex XCOR:

1. [Create a pipeline](/ingest/pipeline/v2/build/create-modify#create-a-pipeline). Follow the
   steps outlined in the Palo Alto Networks Telemetry Pipeline documentation.

2. Add a source, such as Fluent Bit, Elasticsearch, or OpenTelemetry.

3. Add the [Cortex XCOR Logs](/ingest/pipeline/plugins/destination-plugins/chronosphere)
   destination.

4. Click the **Cortex XCOR Logs** destination to edit its configuration:
   1. In the **General** section, in the **Host** field, enter:

      ```text /TENANT/ theme={null}
      TENANT.chronosphere.io
      ```

      <MyTenant />

   2. Expand the **Advanced** section, and in the **URI** field, enter:

      ```text theme={null}
      /api/v1/data/logs/ingest
      ```

5. Complete the remaining steps to deploy your pipeline.

After deploying your pipeline,
[verify that Cortex XCOR is receiving your logs](/ingest/logs/verify-logs)
as anticipated.


## Related topics

- [Palo Alto Networks Telemetry Pipeline v3](/ingest/pipeline/v3.md)
- [Palo Alto Networks Telemetry Pipeline plugins](/ingest/pipeline/plugins.md)
- [Navigate the Palo Alto Networks Telemetry Pipeline web interface](/ingest/pipeline/navigate.md)
- [Palo Alto Networks Telemetry Pipeline concepts](/ingest/pipeline/v2/concepts.md)
- [Palo Alto Networks Telemetry Pipeline v2](/ingest/pipeline/v2.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.