Skip to content
downpipes docs

Forward the downpipes audit trail to Cortex XSIAM

Cortex XSIAM (Palo Alto) receives the downpipes audit trail as an HTTP push; it does not poll a feed. You set up an HTTP collector on the Cortex side, which generates an ingestion URL and a token, then point the console push at that URL. On the scheduler tick the engine POSTs each batch of audit events to Cortex with the token in the Authorization header.

The one-time step is to create that collector: the HTTP Log Collector applet on a Broker VM, or the cloud Custom - HTTP Collector. Either issues the URL and token the engine posts to. There is no pull credential for this path, because Cortex is the receiver, not the poller.

Because the engine makes the outbound call, a Cloudflare Access perimeter on your console hostname never blocks this: there is no inbound request for Access to turn away.

What you need

  • A Cortex XSIAM account that can add an HTTP collector, either the HTTP Log Collector on a Broker VM or the cloud Custom - HTTP Collector.
  • Owner access to the downpipes console, and the ingestion URL and token that Cortex issues for that collector.

Set it up

  1. In Cortex XSIAM, add an HTTP collector: the HTTP Log Collector on a Broker VM, or the cloud Custom - HTTP Collector. Note the ingestion URL it generates and the token it issues.
  2. In the downpipes console, open Integrations and choose this vendor’s tile. Its push panel fixes Delivery to HTTP endpoint and Format to NDJSON (one raw audit event per line, shown below), with no picker to set either. Setting up the push is owner-only and asks for a fresh step-up sign-in. Paste the Cortex ingestion URL into Endpoint URL.
  3. If your collector is set to read a bare JSON array or the wrapped raw-json batch instead, skip this vendor’s tile and use Custom endpoint to pick that format yourself, pointed at the same Cortex ingestion URL; the destination, the test send and the retry behaviour are identical either way. From console 0.2.7, a push saved there shows under Custom endpoint, so run Test send and Enable from that tile. A JSON array push saved there before console 0.2.7 has no tag. The console shows it under the named tiles that send JSON array over HTTP, such as Elastic. To move it to Custom endpoint, set it up again from that tile.
  4. Leave Auth header name as Authorization, and paste the Cortex token as the Auth secret. Enter the token exactly as the Cortex collector screen shows it, including any scheme prefix it expects; if in doubt, copy it verbatim from that screen rather than adding a prefix.
  5. Clear Enabled so nothing drains until the connection is proven, then choose Configure to save. Leave Enabled ticked instead and the drain starts on the next tick. If a second owner must approve a save or an enable, nothing changes until they approve it.
  6. Choose Test send. The engine posts one synthetic audit-shaped event to Cortex and reports the response. A test send never advances the delivery cursor. With the event visible in Cortex, choose Enable, and from the next tick the engine forwards every audit event above the cursor.

What lands in Cortex

From this vendor’s tile, the engine POSTs newline-delimited JSON: one raw audit event object per line, no wrapper:

{"seq":4097,"ts":"2026-06-19T02:14:08.221Z","actorSubject":"https://acme.cloudflareaccess.com|7c2e...","actorEmail":"lead@acme.example","actorMethod":"access","sourceIp":"203.0.113.7","action":"restore-approve","outcome":"success","target":{"kind":"restore","runId":"run_01H...","redirectBinding":null,"planHash":"sha384:5e0f...a2","isLatest":true,"reason":"CHG-1042 roll back the bad deploy","approverEmail":"lead@acme.example","approverSubject":"https://acme.cloudflareaccess.com|7c2e..."},"prevHash":"sha384:11ab...90","hash":"sha384:22cd...01"}

Cortex parses the JSON on ingest, so the action, outcome, actorEmail and sourceIp fields are queryable without a mapping step on your side. If you would rather Cortex see a JSON array or the wrapped raw-json batch instead, set the push up from Custom endpoint with that format.

Good to know

  • Cortex receives, it does not poll. The token you paste is the one Cortex issued for its own HTTP collector, and the engine posts to Cortex on the scheduler tick, so there is no pull credential and no Access exemption to arrange for this path.
  • Delivery is at-least-once, not exactly-once. Every event carries a stable seq and a hash; dedup on either and a re-sent event lands as a duplicate you can drop rather than a second incident. The feed carries operator identity (member emails, source IPs, roles and approver emails) and no backup data or secret values, so apply your Cortex data-handling rules to it as you would any access log. For the shared push mechanics, see Forwarding the audit log to your SIEM.

Last updated .