Palo Alto Cortex
Palo Alto Cortex XSIAM/XDR
The Dropzone AI Platform integrates with the Palo Alto Cortex platform to monitor endpoints, gather data from cloud, network and identity sources, as well as analyze alerts.
Create an API Key
Palo Alto Cortex requires an API key to enable. You’ll need access to a Cortex user account with the ability to generate and manage API keys. If you don’t have the necessary permissions, please get in touch with your Cortex administrator for assistance.
To obtain an API Key, do the following:
Log in to your Palo Cortex console
In the bottom left corner, navigate to Settings > Configurations

In the Search bar, input "API Keys," then click "API Keys"

In the upper right, click "+ New Key"

Under "Role," assign the API Key the Privileged Investigator role

Under "Comment," name the API key something memorable, such as "Dropzone AI"
Select your desired Security Level: Advanced or Standard
If you wish to assign the key an expiration date, check the box labeled "Enable Expiration Date" and input your desired expiration date

In the bottom left corner, click "Generate"

Copy the API Key shown for use later in the Dropzone UI where it is called "API Key"

In the API Keys table, locate the ID number for the newly generated API Key. Copy it for use later in the Dropzone UI where it is called "API Key ID"

In the top right hand corner, click "Copy API URL"

Save the URL for use later in the Dropzone UI where it is called "API FQDN"
Create a Custom User Role
To create a custom role in Palo Alto Cortex, do the following:
Navigate to Settings > Configurations

In the search bar, search Roles

In the upper left, click "+ New Role"

Under "Role Name," name the Role something memorable, such as Dropzone AI Investigator

In the "Components" section, click the arrow next to "Configurations"

Assign the Role the following permissions:
Data Management: View/Edit
Public API: View

In the bottom left corner, click "Save"

When creating your API key, assign it both the Privileged Investigator Role and the custom role
Enable Palo Alto XSIAM
To enable the Alert Source integration, you will need the following information:
API FQDN
The API URL you copied earlier
API Key ID
The API key ID value you copied earlier
API Key
The API key value you generated earlier
Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app
In the bottom left hand corner, navigate to Settings > Integrations

Click "Available"

In the Search bar, search Palo Alto Cortex XSIAM, then click "Configure"

Under the Alert Source heading, input the API FQDN, API Key ID, and API Key
Select your authentication method

Under "Enabled Severities," select the severity levels you wish Dropzone to ingest

Under "Incident Statuses," select which incident statuses you wish Dropzone to ingest

If you wish, you may further filter your alerts, incidents and cases. To do so, under "Description Regex Filters," click "Add Item" and input a custom regex pattern to filter results. In the "Description Filter Mode," choose whether to include or exclude items matching the filters. For further information on this feature, engage your Dropzone representative

Input your desired log ingestion delay, poll interval and poll lookback

Click "Test & Save" to finish
If you have any errors, engage your Dropzone AI support representative.
Enable Palo Alto Cortex XDR
To enable the Alert Source integration, you will need the following information:
API FQDN
The API URL you copied earlier
API Key ID
The API key ID value you copied earlier
API Key
The API key value you generated earlier
Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app
In the bottom left hand corner, navigate to Settings > Integrations

Click "Available"

In the Search bar, search Palo Alto Cortex XDR, then click "Configure"

Under the Alert Source heading, input the API FQDN, API Key ID, and API Key
Select your desired log ingestion delay (in minutes)

Under "Enabled Severities," select the severity levels you want Dropzone to investigate alerts for

Under "Incident Statuses," select which incident statuses you wish Dropzone to ingest

Input your desired Poll interval and lookback

Click "Test & Save" to finish
If you have any errors, engage your Dropzone AI support representative.
Last updated
Was this helpful?