panther data.md

Panther

{% hint style="info" %} Panther is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis. {% endhint %}

The Dropzone platform integrates with the Panther security SIEM. Many customers ingest other alert sources into Panther (e.g. IDPs) and integrate Dropzone into Panther rather than the source systems.

Create an API Key

Panther requires an API key to enable.

To obtain an API Key, do the following:

Select API Tokens

API URL

Permission Purpose
Manage Alerts (optional) Allows Dropzone to add investigations results as Panther comments
Read Alerts Allows Access to alert information
View Rules Allows viewing the log rules setup in Panther
Query Data Lake Allows listing and issuing Data Explorer & Indicator Search queries
View Log Sources Allows viewing the Log sources setup
Read User Info Allows access to user information related to your Panther resources

Create API Token

Record the API Token

Enable Panther

To enable the Data Source integration, do the following:

Integrations Dropdown

Click Available

The Panther Tile

The Panther Data Source Configuration

{% hint style="info" %} The Panther API token activation is not instantaneous. If the connection fails initially try again after a few minutes. {% endhint %}

If you have any errors engage your Dropzone AI support representative.