Palo Alto Networks Cortex XSOAR

Cortex XSOAR is a security orchestration, automation, and response platform that integrates and automates threat detection and incident response.

Related Enforcement Actions Palo Alto Cortex XSOAR - Create Incident

Types of Assets Fetched

This adapter fetches the following types of assets:

  • Alerts/Incidents

Parameters

  1. Host Name or IP Address (required) - The hostname or IP address of the Palo Alto Networks Cortex XSOAR server that Axonius can communicate with via the Required Ports.

  2. API Version - Select between v6 and v8.

  3. Standard API Key (required) - An API Key associated with a user account that has permissions to fetch assets. For information on how to generate the API Key and API Key ID, see Get started with Cortex XSOAR 8 APIs.

  4. API Key ID (optional) - Your unique token used to authenticate the API Key.

  5. Verify SSL - Select whether to verify the SSL certificate of the server against the CA database inside of Axonius. For more details, see SSL Trust & CA Settings.

  6. HTTPS Proxy (optional) - Connect the adapter to a proxy instead of directly connecting it to the domain.

  7. HTTPS Proxy User Name (optional) - The user name to use when connecting to the value supplied in Host Name or IP Address via the value supplied in HTTPS Proxy.

  8. HTTPS Proxy Password (optional) - The password to use when connecting to the server using the HTTPS Proxy.

To learn more about common adapter connection parameters and buttons, see Adding a New Adapter Connection.

Advanced Settings

📘

Note

Endpoint Config - Filtering Options

  • Incident Lookback Days - Enter the number of days back to fetch incidents from. When configured, the adapter only fetches incidents created within the specified number of days. For example, if you set this to 30, only incidents created in the last 30 days are fetched. If left empty, all incidents are fetched regardless of creation date.
  • Incident Severity (default: All severities selected) - Filter fetched incidents by severity.
  • Incident Status (default: All statuses selected) - Filter fetched incidents by status.
  • Incident Query Filter - Filter fetched incidents using XSOAR query syntax, for example: True Positive - Operational or True Positive - Confirmed. Leave this field empty to fetch all incidents..

APIs

Axonius uses the Cortex XSOAR 8 API. However, you can also choose to use version 6 in the connection parameters.

Required Ports

Axonius must be able to communicate with the value supplied in Host Name or IP Address via the following ports:

  • TCP port 443

Version Matrix

This adapter was only tested with the versions marked as supported, but may work with other versions. Contact Axonius Support if you have a version that is not listed, which is not functioning as expected.

VersionSupportedNotes
8Yes--

Supported From Version

Supported from Axonius version 6.1


Did this page help you?