Palo Alto Networks Cortex XSOAR
Cortex XSOAR is a security orchestration, automation, and response platform that integrates and automates threat detection and incident response.
Related Enforcement Actions Palo Alto Cortex XSOAR - Create Incident
Types of Assets Fetched
This adapter fetches the following types of assets:
- Alerts/Incidents
Parameters
-
Host Name or IP Address (required) - The hostname or IP address of the Palo Alto Networks Cortex XSOAR server that Axonius can communicate with via the Required Ports.
-
API Version - Select between v6 and v8.
-
Standard API Key (required) - An API Key associated with a user account that has permissions to fetch assets. For information on how to generate the API Key and API Key ID, see Get started with Cortex XSOAR 8 APIs.
-
API Key ID (optional) - Your unique token used to authenticate the API Key.
-
Verify SSL - Select whether to verify the SSL certificate of the server against the CA database inside of Axonius. For more details, see SSL Trust & CA Settings.
-
HTTPS Proxy (optional) - Connect the adapter to a proxy instead of directly connecting it to the domain.
-
HTTPS Proxy User Name (optional) - The user name to use when connecting to the value supplied in Host Name or IP Address via the value supplied in HTTPS Proxy.
-
HTTPS Proxy Password (optional) - The password to use when connecting to the server using the HTTPS Proxy.
To learn more about common adapter connection parameters and buttons, see Adding a New Adapter Connection.
Advanced Settings
Note
- Advanced settings can apply to either all connections of this adapter, or to a specific connection. For more detailed information, see Advanced Configuration for Adapters.
- For more general information about advanced settings, see Adapter Advanced Settings.
Endpoint Config - Filtering Options
- Incident Lookback Days - Enter the number of days back to fetch incidents from. When configured, the adapter only fetches incidents created within the specified number of days. For example, if you set this to 30, only incidents created in the last 30 days are fetched. If left empty, all incidents are fetched regardless of creation date.
- Incident Severity (default: All severities selected) - Filter fetched incidents by severity.
- Incident Status (default: All statuses selected) - Filter fetched incidents by status.
- Incident Query Filter - Filter fetched incidents using XSOAR query syntax, for example:
True Positive - OperationalorTrue Positive - Confirmed. Leave this field empty to fetch all incidents..
APIs
Axonius uses the Cortex XSOAR 8 API. However, you can also choose to use version 6 in the connection parameters.
Required Ports
Axonius must be able to communicate with the value supplied in Host Name or IP Address via the following ports:
- TCP port 443
Version Matrix
This adapter was only tested with the versions marked as supported, but may work with other versions. Contact Axonius Support if you have a version that is not listed, which is not functioning as expected.
| Version | Supported | Notes |
|---|---|---|
| 8 | Yes | -- |
Supported From Version
Supported from Axonius version 6.1
Updated 19 days ago
