Enter Password



aiFWall Logo aiFObserve

Distributed, Contextual Visibility & Governance for Enterprise AI Traffic. No Agents, No APIs, No

Palo Alto Cortex XDR OTLP Capture Guide For Unified aiFObserve

Best Capture Source

Export Cortex XDR/XSIAM network, cloud, endpoint, and alert events through an OTLP-capable collector or normalized JSON-to-OTLP pipeline. Preserve original event fields so network and identity evidence are not flattened away.

Basic Logging

event timestamp
source and destination IP
source and destination port
protocol
action or verdict
host, URL, domain, or application
username or actor
device or endpoint ID
alert/rule name
bytes sent and received, if available

Extended Logging

User And App Identity

OTLP Mapping Notes

Store Cortex/XSIAM-specific values as attributes. Preserve event.original, service.name, host.name, cloud.region, and network semantic fields.

VALIDATION NOTE: the identity and network field claims above (actor/user fields, device_name as an identity fallback, host/URL/domain resolution) were confirmed end-to-end against the real converter.

Source