What functionality of the Broker VM would you use to ingest third-party firewall logs to the Cortex Data Lake?
The Broker VM is a virtual machine that acts as a data broker between third-party data sources and the Cortex Data Lake. It can ingest different types of data, such as syslog, netflow, database, and pathfinder. The Syslog Collector functionality of the Broker VM allows it to receive syslog messages from third-party devices, such as firewalls, routers, switches, and servers, and forward them to the Cortex Data Lake. The Syslog Collector can be configured to filter, parse, and enrich the syslog messages before sending them to the Cortex Data Lake. The Syslog Collector can also be used to ingest logs from third-party firewall vendors, such as Cisco, Fortinet, and Check Point, to the Cortex Data Lake. This enables Cortex XDR to analyze the firewall logs and provide visibility and threat detection across the network perimeter.Reference:
Supported Third-Party Firewall Vendors
Idella
2 months agoElden
2 months agoKimbery
3 months agoShayne
3 months agoStephania
3 months agoAnisha
3 months agoGlenna
4 months agoGail
4 months agoIsaac
4 months agoAnika
4 months agoThersa
4 months agoCory
5 months agoAlishia
5 months agoTanja
6 months agoMadelyn
5 months agoFreeman
6 months agoJanine
6 months agoNicolette
5 months agoKris
5 months agoQuentin
7 months agoMireya
7 months agoGlory
7 months agoVirgie
7 months agoTy
7 months agoBenedict
7 months agoLanie
7 months agoGarry
7 months agoCiara
6 months agoLemuel
7 months agoVivan
7 months ago