Palo Alto Networks Integrations - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR Pro Administrator Guide

Product
Cortex XDR
License
Pro
Creation date
2023-07-31
Last date published
2023-11-28
Category
Administrator Guide

Cortex XDR supports streaming data directly from Prisma Access accounts and New-Generation Firewalls (NGFW) and Panorama devices to your Cortex XDR tenants using the Cortex Native Data Lake.

Ensure you have deployed Panorama and NGFW, and hold Super User permissions to your Customer Support Account (CSP).

Once your tenant has been activated, navigate to the Collection Integrations page to configure your integrations. All devices and accounts allocated to your CSP accounts are available to integrate.

Existing integrations with Cortex Data Lake (CDL) should be migrated to Cortex Native Data Lake. You can select to migrate manually in the Collection Integrations page, or DITA_variables: product_name will automatically migrate two weeks prior to the end of your current CDL contract.

Note

For Palo Alto Networks Integrations there is an option to turn on or off the collection of URL and File log types. For more information, see Collecting URL and File log types.