palo alto cortex alert.md

For the complete documentation index, see llms.txt. Markdown versions of documentation pages are available by appending .md to page URLs; this page is available as Markdown.

Palo Alto Cortex

Palo Alto Cortex XSIAM/XDR

The Dropzone AI Platform integrates with the Palo Alto Cortex platform to monitor endpoints, gather data from cloud, network and identity sources, as well as analyze alerts.

Create an API Key

Palo Alto Cortex requires an API key to enable. You’ll need access to a Cortex user account with the ability to generate and manage API keys. If you don’t have the necessary permissions, please get in touch with your Cortex administrator for assistance.

To obtain an API Key, do the following:

Click Configurations

Add New Key

{% hint style="info" %} If you wish to allow Dropzone to use the Automatic Scanning feature in its Data Source integration, you will need to create a custom user role with additional permissions. See the "Create a Custom User Role" section for information. {% endhint %}

Assign the Privileged Investigator role

{% hint style="info" %} The Advanced API key hashes the key using a nonce, a random string, and a timestamp to prevent replay attacks. Dropzone does not require the advanced security level. {% endhint %}

Assign the Privileged Investigator role

Click Generate

Copy the API Key

Copy the API Key

Copy the API URL

Create a Custom User Role

To create a custom role in Palo Alto Cortex, do the following:

Click "Configurations"

Search "Roles"

Click "New Role"

Name the Role

Click "Configurations"

Assign the Role permissions

Generate the Role

Enable Palo Alto XSIAM

To enable the Alert Source integration, you will need the following information:

Dropzone Field Source
API FQDN The API URL you copied earlier
API Key ID The API key ID value you copied earlier
API Key The API key value you generated earlier

Integrations Dropdown

Click Available

The Palo Alto Cortex XSIAM tile

{% hint style="info" %} This must be the same as the security level you configured for the API key generated earlier. {% endhint %}

The Palo Alto Cortex XSIAM Alert Configuration (pt 1)

The Palo Alto Cortex XSIAM Alert Configuration (pt 2)

The Palo Alto Cortex XSIAM Alert Configuration (pt 3)

The Palo Alto Cortex XSIAM Alert Configuration (pt 4)

{% hint style="info" %} See the Palo Alto XSIAM Alerts and Incidents overviews for the definitions of type, name, and tag {% endhint %}

The Palo Alto Cortex XSIAM Alert Configuration (pt 4)

The Palo Alto Cortex XSIAM Alert Configuration (pt 5)

If you have any errors, engage your Dropzone AI support representative.

Enable Palo Alto Cortex XDR

To enable the Alert Source integration, you will need the following information:

Integrations Dropdown

Click Available

The Palo Alto Cortex XDR tile

{% hint style="info" %} This must be the same as the security level you configured for the API key generated earlier. {% endhint %}

The Palo Alto Cortex XDR alert configuration (pt 1)

The Palo Alto Cortex XDR Alert Configuration (pt 2)

The Palo Alto Cortex XDR Alert Configuration (pt 3)

{% hint style="info" %} See the Palo Alto XDR Alerts and Incidents overviews for the definitions of type, name, and tag {% endhint %}

The Palo Alto Cortex XDR Alert Configuration (pt 4)

The Palo Alto Cortex XDR Alert Configuration (pt 5)

The Palo Alto Cortex XDR Alert Configuration (pt 6)

If you have any errors, engage your Dropzone AI support representative.