{
  "Name": "Palo Alto Cortex XDR",
  "Author": "Microsoft",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/CortexXDR_Logo.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [Palo Alto Cortex XDR](https://cortex-panw.stoplight.io/docs/cortex-xdr/branches/main/09agw06t5dpvw-cortex-xdr-rest-api) data connector allows ingesting logs from the Palo Alto Cortex XDR API into Microsoft Sentinel. The data connector is built on Microsoft Sentinel Codeless Connector Platform. It uses the Palo Alto Cortex XDR API to fetch agents, alerts, incidents, management and endpoint logs and it supports DCR-based [ingestion time transformations](https://docs.microsoft.com/azure/azure-monitor/logs/custom-logs-overview) that parses the received security data into a custom table, thus resulting in better performance.",
  "Analytic Rules": [
    "Analytic Rules/PaloAltoCortexXDR_High.yaml",
    "Analytic Rules/PaloAltoCortexXDR_Medium.yaml",
    "Analytic Rules/PaloAltoCortexXDR_Low.yaml"
  ],
  "Parsers": [
    "Parsers/PaloAltoCortexXDR.yaml"
  ],
  "Data Connectors": [
    "Data Connectors/CortexXDR_ccp/DataConnectorDefinition.json"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Palo Alto Cortex XDR",
  "Version": "3.0.5",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": false,
  "Is1PConnector": false
}
