Palo Alto Networks XSIAM Engineer — Question 8

How will Cortex XSIAM help with raw log ingestion from third-party sources in an existing infrastructure?

Answer options

Correct answer: B

Explanation

The correct answer is B because Cortex XSIAM specifically processes structured logs by separating key-value pairs and organizing them into a table format, enhancing data usability. Option A is incorrect because while it states that structured logs are unchanged, it fails to mention the significant processing that occurs. Option C is not accurate as it refers to unstructured logs, which do not receive metadata adjustments. Option D incorrectly asserts that unstructured logs are processed similarly to structured logs, which is not the case.