Hello Everyone,
While integrating Palo Alto with Chronicle, I found a document from Palo Alto which states that the endpoint URL should be set as "https://malachiteingestion-pa.googleapis.com/v2/unstructuredlogentries:batchCreate" or according to region. My question is, by doing this, how do we specify the Log type? How will Chronicle identify that this is intended for Palo Alto Prisma Access logs or any other log type?
Reference: https://docs.paloaltonetworks.com/strata-logging-service/administration/forward-logs/forward-logs-to-an-https-server
Thanks in advance.
Aravind Sreekumar
