For the complete documentation index, see llms.txt. This page is also available as Markdown.

Palo Alto Networks Cortex XSIAM

Connect Palo Alto Networks Cortex XSIAM to Radiant Security to forward alerts and events for AI triage.

Palo Alto Networks Cortex XSIAM is an extended SIEM and XDR platform that detects intrusions, malicious activity, and policy violations across endpoints, network traffic, identities, and cloud workloads. Connecting Cortex XSIAM forwards alerts and events to Radiant Security via the XSIAM REST API. Radiant uses these alerts and events for AI triage, classifying and enriching each before it reaches an analyst.

At the end of this configuration, you provide Radiant Security with the following values:

  • API Key

  • API Key ID

  • FQDN

Prerequisites

Generate API credentials in Cortex XSIAM

Follow the Cortex XSIAM REST API guide to generate the three values you will provide to Radiant Security:

  • API Key: a new key created in the Cortex XSIAM console.

  • API Key ID: the identifier displayed alongside the API Key.

  • FQDN: the fully qualified domain name of your Cortex XSIAM tenant, in the form <customer>.xdr.us.paloaltonetworks.com.

If you do not see the option to add a new key, you do not have the permissions to create access keys. Sign in with a System Admin account.

Add the data connector in Radiant Security

  1. Sign in to Radiant Security.

  2. From the navigation menu, click Settings > Data Connectors, then click + Add Connector.

  3. Search for and select Palo Alto Cortex XSIAM REST API, then click Data Feeds.

  4. Under Select your data feeds, select the feeds to forward to Radiant: Palo Alto Cortex XSIAM Cases, and Palo Alto Cortex XSIAM Events. Click Credentials.

  5. Under Credential Name, enter an identifiable name for this credential (e.g., PAN Credentials). To reuse an existing credential, select it from the drop-down menu.

  6. Under Required Credentials, enter the following:

    • API Base URL: https://api-<YOUR_FQDN>, where <YOUR_FQDN> is the FQDN obtained in the previous section.

    • API Key: the API Key value copied from Cortex XSIAM.

    • API Key ID: the API Key ID value copied from Cortex XSIAM.

  7. Click Add Connector.

Verify ingestion

After Palo Alto begins forwarding, confirm cases and events are reaching Radiant.

  1. In Radiant, navigate to Log Management.

  2. Filter by the rs_connectorType for each data feed you enabled:

Data feed
Filter

Palo Alto Networks Cortex XSIAM Cases

rs_connectorType:"pan_cortex_xsiam_cases"

Palo Alto Networks Cortex XSIAM Events

rs_connectorType:"pan_cortex_xsiam_events"

  1. Confirm recent cases and events appear for each enabled feed.

Allow several minutes for cases and events to be parsed, indexed, and available for search.

Last updated

Was this helpful?