- 24 Mar 2022
- 1 Minute to read
-
Print
-
DarkLight
-
PDF
Palo Alto Networks Cortex
- Updated on 24 Mar 2022
- 1 Minute to read
-
Print
-
DarkLight
-
PDF
The Palo Alto Networks Cortex adapter uses the Palo Alto Networks Cortex Hub to get information about Traps and GlobalProtect agents.
To connect the Palo Alto Cortex adapter, the adapter communicates with an Axonius Cloud endpoint that is authorized to get information from the Cortex hub.
Parameters
- API Key - An API key given by Axonius Cloud, as specified in the Creating API Key section.
- HTTPS Proxy (optional, default: empty) - A proxy to use when using the Palo Alto Cortex API.
- If supplied, Axonius will utilize the proxy when connecting to the Palo Alto Cortex API.
- If not supplied, Axonius will connect directly to the Palo Alto Cortex API.
- For details on the common adapter connection parameters and buttons, see Adding a New Adapter Connection.
Advanced Settings
Advanced settings can either apply for all connections for this adapter, or you can set different advanced settings and/or different scheduling for a specific connection, refer to Advanced Configuration for Adapters
- Number of weeks to fetch (optional, default: 2) - Specify the number of weeks for which Axonius will fetch history.
- If supplied, all connections for this adapter will fetch data for the specified number of weeks.
- If not supplied, all connections for this adapter will fetch will fetch 2 weeks of data.
For details on general advanced settings under the Adapter Configuration tab, see Adapter Advanced Settings.
Creating API Key
In order to authorize Axonius to pull data from Cortex Hub, follow these steps:
-
Log into Cortex Hub, then find the Axonius app and activate it.
-
After activating it, click on the Axonius app from the main portal
-
You will be redirected to the Axonius Cloud website. Log in or sign up to proceed
-
After logging in for the first time, the Axonius app will request for a readonly access for the logging services. Select 'Read Logging Services' and click Allow
-
In the Axonius Cloud website, click Integrations on the left menu to reach the integrations page. Then copy the API Key for the Palo Alto Networks Cortex integration
- In Axonius, go to the Palo Alto Networks Cortex adapter, then add a new client and paste the API Key.