Read the overview for what happens to an event, then the input you need: ingest keys, Beats, syslog, CEF and LEEF, HTTP JSON, Splunk HEC, the catalog of recognised sources, the connectors and threat intelligence.
Data sources
Get events into XenXDR from anything that speaks syslog, Beats, HTTP or HEC, and from cloud identity providers.