palo alto data.md

Palo Alto Networks Firewall

Palo Alto Networks Firewall

{% hint style="success" %} Note that this is different from the "Palo Alto Cortex XDR/XSIAM" cloud and EDR data and alert source. {% endhint %}

The Dropzone AI Platform integrates with Palo Alto Networks Firewall, a leading next-generation firewall solution. Integrating Palo Alto with Dropzone allows Dropzone to automatically investigate security incidents by analyzing network traffic data within the firewall ecosystem. Additionally, Dropzone can assess threat logs from Palo Alto Firewall, enabling deeper investigations into potential attacks and enhancing proactive threat detection and response.

Integrations Overview

To enable these integrations you will perform the following actions:

Create an Admin Role Profile

Navigate to Device

Navigate to Admin Roles

Click "Add"

Generate a new Admin Role Profile

Navigate to Administrators

Click "Add"

Create a new Administrator

Commit your changes

Generate an API Key

To obtain an API Key, do the following:

https://<FIREWALL_IP>/api/?type=keygen&user=<USERNAME>
curl -k http(s)://<host>:<port>/api/?type=keygen&user=<user>&password=<password>

Enable Palo Alto Firewall

To enable the Data Source integration, you will need the following information:

Dropzone Field Source
Server The same as your company server url in Palo Alto, eg https://<111.22.33.444>
API Key The API key value you generated earlier

Integrations Dropdown

Click Available

The Palo Alto Networks Firewall Tile

The Palo Alto Networks Firewall Data Configuration

If you have any errors engage your Dropzone AI support representative.