Palo Alto Networks Cortex XSIAM
Connect Palo Alto Networks Cortex XSIAM to Radiant Security to forward alerts and events for AI triage.
Last updated
Was this helpful?
Connect Palo Alto Networks Cortex XSIAM to Radiant Security to forward alerts and events for AI triage.
Palo Alto Networks Cortex XSIAM is an extended SIEM and XDR platform that detects intrusions, malicious activity, and policy violations across endpoints, network traffic, identities, and cloud workloads. Connecting Cortex XSIAM forwards alerts and events to Radiant Security via the XSIAM REST API. Radiant uses these alerts and events for AI triage, classifying and enriching each before it reaches an analyst.
At the end of this configuration, you provide Radiant Security with the following values:
API Key
API Key ID
FQDN
Follow the Cortex XSIAM REST API guide to generate the three values you will provide to Radiant Security:
API Key: a new key created in the Cortex XSIAM console.
API Key ID: the identifier displayed alongside the API Key.
FQDN: the fully qualified domain name of your Cortex XSIAM tenant, in the form <customer>.xdr.us.paloaltonetworks.com.
Copy the API Key value when it is generated. It cannot be retrieved later.
If you do not see the option to add a new key, you do not have the permissions to create access keys. Sign in with a System Admin account.
Sign in to Radiant Security.
From the navigation menu, click Settings > Data Connectors, then click + Add Connector.
Search for and select Palo Alto Cortex XSIAM REST API, then click Data Feeds.
Under Select your data feeds, select the feeds to forward to Radiant: Palo Alto Cortex XSIAM Cases, and Palo Alto Cortex XSIAM Events. Click Credentials.
Under Credential Name, enter an identifiable name for this credential (e.g., PAN Credentials). To reuse an existing credential, select it from the drop-down menu.
Under Required Credentials, enter the following:
API Base URL: https://api-<YOUR_FQDN>, where <YOUR_FQDN> is the FQDN obtained in the previous section.
API Key: the API Key value copied from Cortex XSIAM.
API Key ID: the API Key ID value copied from Cortex XSIAM.
Click Add Connector.
After Palo Alto begins forwarding, confirm cases and events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by the rs_connectorType for each data feed you enabled:
Palo Alto Networks Cortex XSIAM Cases
rs_connectorType:"pan_cortex_xsiam_cases"
Palo Alto Networks Cortex XSIAM Events
rs_connectorType:"pan_cortex_xsiam_events"
Confirm recent cases and events appear for each enabled feed.
Allow several minutes for cases and events to be parsed, indexed, and available for search.
Last updated
Was this helpful?
Was this helpful?