Palo Alto Networks Prisma Cloud
Connect Palo Alto Networks Prisma Cloud to Radiant Security to forward cloud security alerts for AI triage.
Last updated
Was this helpful?
Connect Palo Alto Networks Prisma Cloud to Radiant Security to forward cloud security alerts for AI triage.
Palo Alto Networks Prisma Cloud is a cloud-native application protection platform that secures cloud accounts, workloads, and services against misconfigurations, threats, and compliance gaps. Connecting Prisma Cloud forwards its security alerts to Radiant Security through the Prisma Cloud API. Radiant uses the alert data to triage these alerts in context, giving analysts faster verdicts on whether a flagged cloud resource or activity is a real risk or expected behavior.
At the end of this configuration, you provide Radiant Security with the following values:
API URL
Access Key ID
Secret Access Key
Prisma ID (optional)
On the Prisma Cloud Console, select Settings > Access Control > Access Keys, then select Add > Access Key.
Enter a Name for the key (e.g., Radiant Security Integration).
Select Enable Expiration and set an expiry term that meets your compliance standards. Without expiration, the key never expires. Radiant recommends a one-year term.
Click Save.
Copy and store the Access Key ID and Secret Access Key now. They cannot be retrieved later.
API URL
Your console URL changes by region. Find your region and copy the matching API URL from Prisma Cloud's API URLs reference.
Copy the Prisma Cloud API URL, not the Prisma Cloud admin console URL.
Prisma ID (optional)
Provide the Prisma ID only in a multi-tenant environment.
From the console, select Settings > License Information or Account Settings.
On the License page, find the Prisma ID value and copy it.
Log in to Radiant Security.
From the navigation menu, select Settings > Data Connectors, then click + Add Connector
Select Palo Alto Prisma Cloud from the list, then click Credentials.
Under Credential Name, enter an identifiable name (e.g., Prisma Cloud API).
Under Required Credentials, enter the values you collected:
API URL
Access Key ID
Secret Access Key
Prisma ID (optional)
Click Add Connector to save the configuration.
After Palo Alto Networks Prisma Cloud begins forwarding, confirm alerts and events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by rs_connectorType:"pan_prisma".
Confirm recent alerts and events appear.
Allow several minutes for alerts and events to be parsed, indexed, and available for search.
Last updated
Was this helpful?
Was this helpful?