For the complete documentation index, see llms.txt. This page is also available as Markdown.

Palo Alto Networks Prisma Cloud

Connect Palo Alto Networks Prisma Cloud to Radiant Security to forward cloud security alerts for AI triage.

Palo Alto Networks Prisma Cloud is a cloud-native application protection platform that secures cloud accounts, workloads, and services against misconfigurations, threats, and compliance gaps. Connecting Prisma Cloud forwards its security alerts to Radiant Security through the Prisma Cloud API. Radiant uses the alert data to triage these alerts in context, giving analysts faster verdicts on whether a flagged cloud resource or activity is a real risk or expected behavior.

At the end of this configuration, you provide Radiant Security with the following values:

  • API URL

  • Access Key ID

  • Secret Access Key

  • Prisma ID (optional)

Prerequisites

Generate API credentials in Prisma Cloud

  1. On the Prisma Cloud Console, select Settings > Access Control > Access Keys, then select Add > Access Key.

  2. Enter a Name for the key (e.g., Radiant Security Integration).

  3. Select Enable Expiration and set an expiry term that meets your compliance standards. Without expiration, the key never expires. Radiant recommends a one-year term.

  4. Click Save.

Copy and store the Access Key ID and Secret Access Key now. They cannot be retrieved later.

Get your API URL and Prisma ID

API URL

Your console URL changes by region. Find your region and copy the matching API URL from Prisma Cloud's API URLs reference.

Prisma ID (optional)

Provide the Prisma ID only in a multi-tenant environment.

  1. From the console, select Settings > License Information or Account Settings.

  2. On the License page, find the Prisma ID value and copy it.

Add the data connector in Radiant Security

  1. Log in to Radiant Security.

  2. From the navigation menu, select Settings > Data Connectors, then click + Add Connector

  3. Select Palo Alto Prisma Cloud from the list, then click Credentials.

  4. Under Credential Name, enter an identifiable name (e.g., Prisma Cloud API).

  5. Under Required Credentials, enter the values you collected:

    • API URL

    • Access Key ID

    • Secret Access Key

    • Prisma ID (optional)

  6. Click Add Connector to save the configuration.

Verify ingestion

After Palo Alto Networks Prisma Cloud begins forwarding, confirm alerts and events are reaching Radiant.

  1. In Radiant, navigate to Log Management.

  2. Filter by rs_connectorType:"pan_prisma".

  3. Confirm recent alerts and events appear.

Allow several minutes for alerts and events to be parsed, indexed, and available for search.

Last updated

Was this helpful?