Palo Alto Cortex | Dropzone AI Documentation

Palo Alto Cortex XSIAM/XDR

The Dropzone AI Platform integrates with the Palo Alto Cortex platform to monitor endpoints, gather data from cloud, network and identity sources, as well as analyze alerts.

Create an API Key

Palo Alto Cortex requires an API key to enable. You’ll need access to a Cortex user account with the ability to generate and manage API keys. If you don’t have the necessary permissions, please get in touch with your Cortex administrator for assistance.

To obtain an API Key, do the following:

Click Configurations

Add New Key

If you wish to allow Dropzone to use the Automatic Scanning feature in its Data Source integration, you will need to create a custom user role with additional permissions. See the "Create a Custom User Role" section for information.

The Advanced API key hashes the key using a nonce, a random string, and a timestamp to prevent replay attacks. Dropzone does not require the advanced security level.

Assign the Privileged Investigator role

Click Generate

Copy the API Key

Copy the API Key

Copy the API URL

Create a Custom User Role

To create a custom role in Palo Alto Cortex, do the following:

Click "Configurations"

Search "Roles"

Click "New Role"

Name the Role

Click "Configurations"

Assign the Role permissions

Generate the Role

Enable Palo Alto XSIAM

To enable the Alert Source integration, you will need the following information:

Dropzone Field

Source

API FQDN

The API URL you copied earlier

API Key ID

The API key ID value you copied earlier

API Key

The API key value you generated earlier

Integrations Dropdown

Click Available

The Palo Alto Cortex XSIAM tile

This must be the same as the security level you configured for the API key generated earlier.

The Palo Alto Cortex XSIAM Alert Configuration (pt 1)

The Palo Alto Cortex XSIAM Alert Configuration (pt 2)

The Palo Alto Cortex XSIAM Alert Configuration (pt 3)

The Palo Alto Cortex XSIAM Alert Configuration (pt 4)

See the Palo Alto XSIAM Alerts and Incidents overviews for the definitions of type, name, and tag

The Palo Alto Cortex XSIAM Alert Configuration (pt 4)

The Palo Alto Cortex XSIAM Alert Configuration (pt 5)

If you have any errors, engage your Dropzone AI support representative.

Enable Palo Alto Cortex XDR

To enable the Alert Source integration, you will need the following information:

Dropzone Field

Source

API FQDN

The API URL you copied earlier

API Key ID

The API key ID value you copied earlier

API Key

The API key value you generated earlier

Integrations Dropdown

Click Available

The Palo Alto Cortex XDR tile

This must be the same as the security level you configured for the API key generated earlier.

The Palo Alto Cortex XDR alert configuration (pt 1)

The Palo Alto Cortex XDR Alert Configuration (pt 2)

The Palo Alto Cortex XDR Alert Configuration (pt 3)

See the Palo Alto XDR Alerts and Incidents overviews for the definitions of type, name, and tag

The Palo Alto Cortex XDR Alert Configuration (pt 4)

The Palo Alto Cortex XDR Alert Configuration (pt 5)

The Palo Alto Cortex XDR Alert Configuration (pt 6)

If you have any errors, engage your Dropzone AI support representative.