Outputs
Palo Alto Cortex XSIAM
Ships pipeline data to a Palo Alto Networks Cortex XSIAM HTTP Log Collector. Events land in the raw dataset ({vendor}_{product}_raw) bound to your collector's API key and are queryable from the XSIAM Query Builder (XQL).
Requirements
- A Cortex XSIAM tenant with the Cortex - Analytics pack enabled.
- An HTTP Log Collector configured on the tenant, along with its generated API key.
Create an HTTP Log Collector on Cortex XSIAM
- In the Cortex XSIAM console, open Settings → Data Sources & Integrations.
- Click + Add New, then choose HTTP.
- Give the collector a Name, Vendor, and Product. Raw events will land in the auto-created dataset
{vendor}_{product}_raw. - Set Log Format to JSON.
- Choose a Compression setting (gzip or uncompressed). This must match the connector configuration in Monad — the connector sends uncompressed by default; enable Enable Gzip Compression in the Monad settings if the collector is configured for gzip.
- Click Generate to create the API key and copy it immediately. XSIAM only shows the key once; if you lose it you must regenerate it.
- Save the collector.
The tenant API FQDN is the hostname portion of your XSIAM API URL — e.g. api-example.xdr.us.paloaltonetworks.com.
Details
- Endpoint:
POST https://<tenant_fqdn>/logs/v1/event - Payload: newline-delimited JSON (NDJSON), one event per line.
- Compression: off by default. Turn on Enable Gzip Compression to send
Content-Encoding: gzip; the collector's UI Compression setting must match. - Auth: the API key is sent as the raw
Authorizationheader (not Bearer-prefixed). - Batching: up to 500 records or ~1 MiB per request (whichever comes first), flushed every 5 seconds. XSIAM enforces a hard 10 MB body limit and rate-limits at 400 requests/sec per customer.
- Vendor / product / dataset: these are bound to the API key on the XSIAM side, not sent in the request.
Verifying data in Cortex XSIAM
- Command Center (
Settings → Monitoring) — live ingestion rate and data-source status (~30 s refresh). - Query Builder (
Investigation → Query Builder) — rundataset = <vendor>_<product>_raw | limit 50to inspect the events Monad shipped. - Dataset Management (
Settings → Data Management) — verify the dataset exists and check retention/storage. - Health Issues — surfaces ingestion errors; right-click to Investigate in XQL.
Configuration
Settings
| Setting | Type | Required | Description |
|---|---|---|---|
| Tenant FQDN | string | Yes | Your XSIAM tenant API FQDN (e.g. api-example.xdr.us.paloaltonetworks.com). Hostname only — do not include a scheme or path. |
| Enable Gzip Compression | boolean | No | Off by default (requests are sent uncompressed). Turn on only if your HTTP Log Collector is configured for gzip. A mismatch causes HTTP 500. |
| Allow Insecure Connection | boolean | No | Skip TLS verification. Not recommended outside local testing. |
Secrets
| Secret | Type | Required | Description |
|---|---|---|---|
| HTTP Collector API Key | string | Yes | The per-collector API key generated in the XSIAM UI. Sent as the raw Authorization header value. |
Troubleshooting
| HTTP status | Meaning |
|---|---|
| 200 | Success. Response body is {"error":"false"}. |
| 401 | API key is wrong, or the collector has been disabled. |
| 404 | Wrong tenant FQDN or path. |
| 413 | Batch exceeded 10 MB — should not occur under default batch settings. |
| 429 | Rate limit exceeded (400 req/s per customer). |
| 500 | Log-format or compression mismatch between the request and the collector's UI configuration. |
Last modified on