Send logs from Cortex Data Lake to a Syslog receiver via API
13088
Created On 01/31/23 11:45 AM - Last Modified 07/11/25 20:15 PM
Objective
This document provides a reference regading the use of the Log Forwarding API for Cortex Data Lake
Environment
Cortex Data Lake
Procedure
To use the Log Forwarding APIs, you must be a new Managed Security Service Provider (MSSP) customer as of March 2022 and must have configured your multitenant hierarchy for a new deployment of Prisma Access.
After you have configured your tenants, these APIs can be used to add, modify, and delete syslog, HTTPS, and email log forwarding profiles.
However, take into account that the functionality exposed by these APIs can also be performed using the Cortex Data Lake user interface.
Additional Information
For reference about how to use the Log Forwarding APIs you can check the information within the document below:
https://pan.dev/cdl/docs/log-forwarding/