panther alert.md

Panther

{% hint style="info" %} Panther is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis. {% endhint %}

The Dropzone platform integrates with the Panther security SIEM. Many customers ingest other alert sources into Panther (e.g. IDPs) and integrate Dropzone into Panther rather than the source systems.

Create an API Key

Panther requires an API key to enable.

To obtain an API Key, do the following:

Select API Tokens

API URL

Permission Purpose
Manage Alerts (optional) Allows Dropzone to add investigations results as Panther comments
Read Alerts Allows Access to alert information
View Rules Allows viewing the log rules setup in Panther
Query Data Lake Allows listing and issuing Data Explorer & Indicator Search queries
View Log Sources Allows viewing the Log sources setup
Read User Info Allows access to user information related to your Panther resources

Create API Token

Record the API Token

{% hint style="danger" %} This value is not shown after you leave this page — be sure to record it immediately. {% endhint %}

Enable The Dropzone Alert Source Integration

To enable the Alert Source integration, do the following:

Integrations Dropdown

Click Available

The Panther Tile

The Panther Alert Source Configuration (pt 1)

{% hint style="info" %} The "Closed" status in the Dropzone UI is shown as "Invalid" in the Panther UI. {% endhint %}

The Panther Alert Source Configuration (pt 2)

The Panther Alert Source Configuration (pt 3)

The Panther Alert Source Configuration (pt 4)

The Panther Alert Source Configuration (pt 5)

The Panther Alert Source Configuration (pt 6)

The Panther Alert Source Configuration (pt 6)

{% hint style="info" %} The Panther API token activation is not instantaneous. If the connection fails initially, try again after a few minutes. {% endhint %}

If you have any errors engage your Dropzone AI support representative.