About The Device
Cortex XDR provides consistent and strong security to your enterprise with the help of tight integration across endpoint security, detection & response, and Next-Generation Firewalls. It provides AI-based analytics that will help you to detect stealthy threats. It provides Managed Detection and Response Services.
Device Information
Entity | Particulars |
---|---|
Vendor Name | Palo Alto |
Product Name | Cortex XDR |
Type of Device | Cloud |
Collection Method
Log Type | Ingestion label | Preferred Logging Protocol - Format | Log Collection Method | Data Source |
---|---|---|---|---|
Palo Alto Cortex XDR Alerts | CORTEX_XDR | JSON | C2C | https://cloud.google.com/chronicle/docs/reference/feed-management-api#cortex-xdr |
Device Configuration
To Get your Cortex XDR API Key
In Cortex XDR, click Settings on the top right
Select + New Key
Select Security Level as Standard and Role as Viewer and click Generate
Copy the API key, and then click Done. This value represents your unique Authorization:{key}.
You will not be able to view the API Key again after you complete this step so ensure that you copy it before closing the notification.
To Get your Cortex XDR API Key ID
Navigate to API Keys > ID
Note your corresponding ID number. This value represents the x-xdr-auth-id:{key_id} token.
To Get your FQDN
Navigate to API Keys, Click Copy URL on the top right
Share the acquired Key, Key ID, and URL with the Adaptive MxDR Service Delivery Lead to configure the feed.
Integration Parameters
Parameters required from customer for Integration.
Property | Default Value | Description |
---|---|---|
AUTHENTICATION HTTP HEADERS | N/A | The HTTP header used to authenticate Cortex XDR API in key-value format. |
API HOSTNAME | N/A | The fully qualified domain name of your Cortex XDR instance. |
ENDPOINT | alerts | The API endpoint to connect to retrieve logs, which include |