Cortex XSOAR
Cortex XSOAR: Security orchestration, automation, and response platform for threat detection and incident management.
To onboard such a source to Axoflow, complete the generic appliance onboarding steps.
Labels
Axoflow automatically adds the following labels to data collected from this source:
| label | value | 
|---|---|
| vendor | palo-alto-networks | 
| product | cortex-xsoar | 
| format | cef | 
Sending data to Splunk
When sending the data collected from this source to Splunk, Axoflow uses the following sourcetype, source, and index settings:
| sourcetype | source | index | 
|---|---|---|
| cef | tim:cef | infraops | 
Sending data to Google SecOps
When sending the data collected from this source to a dynamic Google SecOps destination, Axoflow sets the following log type: PAN_XSOAR.
Earlier name/vendor
Threat Intelligence Management (TIM)