Cortex Data Lake
At the beginning of this book, we learned that we need to activate a Cortex Data Lake (CDL) instance to be used to receive logs from Prisma Access, but we still need to configure CDL for the log volume stored for each log type and retention period.
You can access CDL from the Palo Alto hub (https://apps.paloaltonetworks.com) and click the Cortex Data Lake tile:
Figure 10.1 – Palo Alto networks hub
On the Dashboard tab, you will see some general information regarding your CDL instance including the storage used and the number of connected firewalls. For a Prisma Access-only deployment, there will be no firewalls (0) listed; this number only reflects the number of physical or VM firewalls also connected to CDL.
Navigate to the Configuration tab to configure the Storage parameters:
Figure 10.2 – CDL dashboard
The default configuration will indicate that 0.00 MB of your available storage has...