Prisma Access
Integrate with Prisma Access to monitor the status of the Service, alert and take actions.
Network Security · Palo Alto Networks - Strata Cloud Manager
Details
| ID | Prisma Access |
|---|---|
| Provider | Palo Alto Networks |
| Category | Network Security |
| From Version | 5.0.0 |
| Docker Image | demisto/netmiko:1.0.0.9067966 |
| Supported Modules | Agentix Cloud Runtime Security Cloud Posture Security XSIAM EDR Cortex Cloud |
README
Prisma Access Integration
Integrate with Prisma Access to monitor the status of the Service, alert and take actions.
The integration uses both the Panorama XML API and SSH into the PAN-OS CLI.
Common parameters
The Server Host or IP parameter is required by both.
SSH connection
The following commands require the SSH access to be configured:
- prisma-access-active-users
- prisma-access-cli-command
- prisma-access-query
The SSH connection requires the SSH Credentials for CLI, Password and SSH Port are provided.
SSH credentials should be your username and password for the PAN-OS CLI - they can be tested using a standalone SSH client to verify that you are able to connect to the CLI on the SSH port.
API connection
The following commands require the API access to be configured:
- prisma-access-logout-user
The API connection requires the API Port and API Key parameters as well as a Device Group or Vsys.
This integration was integrated and tested with version 9.0.7 of Prisma Access
Configure Prisma Access in Cortex
| Parameter | Description | Required |
|---|---|---|
| server | Server Host or IP (e.g., 10.1.1.9 or panorama.my.domain) | True |
| port | API Port (e.g 443) | False |
| key | API Key | False |
| insecure | Trust any certificate (not secure) | False |
| proxy | Use system proxy settings | False |
| device_group | Device group - Panorama instances only (write shared for Shared location) | False |
| vsys | Vsys - Firewall instances only | False |
| sshport | SSH Port | False |
| Username | SSH Credentials for CLI | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
prisma-access-logout-user
Force logout a specific user from Prisma Access
Base Command
prisma-access-logout-user
Input
| Argument Name | Description | Required |
|---|---|---|
| user | Username to logout. (Without domain name - e.g. jsmith) | Required |
| domain | Domain name of the user to logout. | Required |
| computer | Computer name to logout. | Required |
| tenant_name | The tenant name. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| PrismaAccess.LogoutUser | unknown | LogoutUser command results |
Command Example
!prisma-access-logout-user user="jsmith" domain="acme" computer="jsmithPC"
prisma-access-query
Run a query via the Prisma Access CLI
Base Command
prisma-access-query
Input
| Argument Name | Description | Required |
|---|---|---|
| query | Query to run. Example input: querystring limit=2000 action getGPaaSLast90DaysUniqueUsers | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| PrismaAccess.QueryResults | unknown | Query results |
Command Example
!prisma-access-query query="querystring limit=2 action getGPaaSActiveUsers"
prisma-access-cli-command (deprecated)
Run a custom CLI command on Prisma Access
Base Command
prisma-access-cli-command
Input
| Argument Name | Description | Required |
|---|---|---|
| cmd | CLI command to run (e.g. debug plugins cloud_services gpcs query querystring limit=9000 action getGPaaSLast90DaysUniqueUsers) | Required |
Context Output
There is no context output for this command.
Command Example
!prisma-access-cli-command cmd="show system info | match hostname"
prisma-access-active-users (deprecated)
Query currently active users.
Base Command
prisma-access-active-users
Input
| Argument Name | Description | Required |
|---|---|---|
| limit | Maximum number of entries to return. Default is 20. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| PrismaAccess.ActiveUsers | unknown | Active Users on Prisma Access |
Command Example
!prisma-access-active-users limit=10
Configuration parameters
server— Server Host or IP (e.g., 10.1.1.9 or panorama.my.domain) (required)port— API Port (e.g 443)key— API Keycredentials_key—insecure— Trust any certificate (not secure)proxy— Use system proxy settingsdevice_group— Device group - Panorama instances only (write shared for Shared location)vsys— Vsys - Firewall instances onlysshport— SSH PortUsername— SSH Credentials for CLI
Commands (4)
-
prisma-access-active-usersDeprecatedQuery currently active users.
-
prisma-access-cli-commandDeprecatedRun a custom CLI command on Prisma Access.
-
prisma-access-logout-userForce logout a specific user from Prisma Access.
-
prisma-access-queryDeprecatedRun a query via the Prisma Access CLI.
commonfields: id: Prisma Access version: -1 name: Prisma Access display: Prisma Access category: Network Security provider: Palo Alto Networks description: |+ Integrate with Prisma Access to monitor the status of the Service, alert and take actions. configuration: - display: Server Host or IP (e.g., 10.1.1.9 or panorama.my.domain) name: server type: 0 required: true - display: API Port (e.g 443) name: port defaultvalue: '443' type: 0 required: false - display: API Key name: key type: 4 hidden: true required: false - name: credentials_key type: 9 displaypassword: API Key hiddenusername: true required: false - display: Trust any certificate (not secure) name: insecure type: 8 required: false - display: Use system proxy settings name: proxy type: 8 required: false - display: Device group - Panorama instances only (write shared for Shared location) name: device_group type: 0 required: false - display: Vsys - Firewall instances only name: vsys type: 0 required: false - display: SSH Port name: sshport type: 0 required: false - display: SSH Credentials for CLI name: Username type: 9 required: false script: script: '' type: python commands: - name: prisma-access-logout-user arguments: - name: user required: true default: true description: Username to logout. (Without domain name - e.g. jsmith). - name: domain description: Domain name of the user to logout. For some users, this field is required. - name: computer required: true description: Computer name to logout. - name: tenant_name description: The tenant name. outputs: - contextPath: PrismaAccess.LogoutUser description: LogoutUser command results. description: Force logout a specific user from Prisma Access. compliantpolicies: - User Soft Remediation - name: prisma-access-query arguments: - name: query required: true description: 'Query to run. Example input: querystring limit=2000 action getGPaaSLast90DaysUniqueUsers.' outputs: - contextPath: PrismaAccess.QueryResults description: Query results. description: Run a query via the Prisma Access CLI. deprecated: true - name: prisma-access-cli-command arguments: - name: cmd required: true description: CLI command to run (e.g. debug plugins cloud_services gpcs query querystring limit=9000 action getGPaaSLast90DaysUniqueUsers). description: Run a custom CLI command on Prisma Access. deprecated: true - name: prisma-access-active-users arguments: - name: limit description: Maximum number of entries to return. Default is 20. defaultValue: '20' outputs: - contextPath: PrismaAccess.ActiveUsers description: Active Users on Prisma Access. description: Query currently active users. deprecated: true dockerimage: demisto/netmiko:1.0.0.9067966 subtype: python3 fromversion: 5.0.0 tests: - No tests (auto formatted) supportedModules: - cloud_posture - xsiam - cloud - agentix