Palo Alto Networks Cortex XSIAM

Allow Radiant to collect alerts from Palo Alto Networks Cortex XSIAM

In this guide, you'll create API credentials in Cortex XSIAM to enable Radiant to collect alerts.

At the end of this configuration, you will provide Radiant Security with these items:

  • API Key

  • API Key ID

  • API URL (FQDN)

Prerequisites

Generate API credentials in Palo Alto

Follow the steps in the Cortex XSIAM guidearrow-up-right to generate the three items needed to enable the API connection with Radiant:

  1. Create a new API Key. Be sure to copy and store it carefully, as it cannot be retrieved later and can present a security risk if used in an unauthorized fashion.

circle-exclamation
  1. Get your Cortex XSIAM API Key ID.

  2. Get your FQDN. (it should have a similar form to <customer>.xdr.us.paloaltonetworks.com)

Add the data connector in Radiant Security

  1. From the navigation menu, click Settings > Data Connectors and click + Add Connector.

  2. Search for and select the Palo Alto Cortex XSIAM REST API option and then click Data Feeds.

  3. Under Select your data feeds, select the Palo Alto Cortex XSIAM Cases data feed and then click Credentials.

  4. Under Credential Name, give the credential an identifiable name (e.g. PAN Credentials). If you already have a credential in place, select it from the drop-down menu. Click Credentials.

  5. In the Required Credentials field, enter the API Base URL (https://api-<YOUR_FQDN>), API Key and API Key ID.

  6. Click Add Connector.

Last updated

Was this helpful?