# Palo Alto Cortex XSIAM Ships pipeline data to a Palo Alto Networks **Cortex XSIAM HTTP Log Collector**. Events land in the raw dataset (`{vendor}_{product}_raw`) bound to your collector's API key and are queryable from the XSIAM Query Builder (XQL). ## Requirements - A Cortex XSIAM tenant with the **Cortex - Analytics** pack enabled. - An **HTTP Log Collector** configured on the tenant, along with its generated API key. ## Create an HTTP Log Collector on Cortex XSIAM 1. In the Cortex XSIAM console, open **Settings → Data Sources & Integrations**. 2. Click **+ Add New**, then choose **HTTP**. 3. Give the collector a **Name**, **Vendor**, and **Product**. Raw events will land in the auto-created dataset `{vendor}_{product}_raw`. 4. Set **Log Format** to **JSON**. 5. Choose a **Compression** setting (gzip or uncompressed). This must match the connector configuration in Monad — the connector sends uncompressed by default; enable **Enable Gzip Compression** in the Monad settings if the collector is configured for gzip. 6. Click **Generate** to create the API key and **copy it immediately**. XSIAM only shows the key once; if you lose it you must regenerate it. 7. Save the collector. The tenant API FQDN is the hostname portion of your XSIAM API URL — e.g. `api-example.xdr.us.paloaltonetworks.com`. ## Details - **Endpoint:** `POST https:///logs/v1/event` - **Payload:** newline-delimited JSON (NDJSON), one event per line. - **Compression:** off by default. Turn on **Enable Gzip Compression** to send `Content-Encoding: gzip`; the collector's UI Compression setting must match. - **Auth:** the API key is sent as the raw `Authorization` header (not Bearer-prefixed). - **Batching:** up to 500 records or ~1 MiB per request (whichever comes first), flushed every 5 seconds. XSIAM enforces a hard 10 MB body limit and rate-limits at 400 requests/sec per customer. - **Vendor / product / dataset:** these are bound to the API key on the XSIAM side, not sent in the request. ## Verifying data in Cortex XSIAM - **Command Center** (`Settings → Monitoring`) — live ingestion rate and data-source status (~30 s refresh). - **Query Builder** (`Investigation → Query Builder`) — run `dataset = __raw | limit 50` to inspect the events Monad shipped. - **Dataset Management** (`Settings → Data Management`) — verify the dataset exists and check retention/storage. - **Health Issues** — surfaces ingestion errors; right-click to *Investigate in XQL*. ## Configuration #### Settings | Setting | Type | Required | Description | |---------|------|----------|-------------| | Tenant FQDN | string | Yes | Your XSIAM tenant API FQDN (e.g. `api-example.xdr.us.paloaltonetworks.com`). Hostname only — do not include a scheme or path. | | Enable Gzip Compression | boolean | No | Off by default (requests are sent uncompressed). Turn on only if your HTTP Log Collector is configured for gzip. A mismatch causes HTTP 500. | | Allow Insecure Connection | boolean | No | Skip TLS verification. Not recommended outside local testing. | #### Secrets | Secret | Type | Required | Description | |--------|------|----------|-------------| | HTTP Collector API Key | string | Yes | The per-collector API key generated in the XSIAM UI. Sent as the raw `Authorization` header value. | ## Troubleshooting | HTTP status | Meaning | |-------------|---------| | 200 | Success. Response body is `{"error":"false"}`. | | 401 | API key is wrong, or the collector has been disabled. | | 404 | Wrong tenant FQDN or path. | | 413 | Batch exceeded 10 MB — should not occur under default batch settings. | | 429 | Rate limit exceeded (400 req/s per customer). | | 500 | Log-format or compression mismatch between the request and the collector's UI configuration. |