Cortex Data Lake
Palo Alto Networks Strata Logging Service XSOAR Connector provides cloud-based, centralized log storage and aggregation for your organization on premise, virtual (private cloud and public cloud) firewalls, for Prisma Access, and for cloud-delivered services such as Cortex XDR.
- Category
- Analytics & SIEM
- Pack
- CortexDataLake
Configuration parameters
- refresh_token — Token
- reg_id — ID
- auth_key — Key
- credentials_auth_key —
- credentials_refresh_token —
- credentials_reg_id —
- credentials_client_secret —
- isFetch — Fetch incidents
- first_fetch_timestamp — First fetch time (<number> <time unit>, e.g., 12 hours, 7 days, 3 months, 1 year)
- fetch_table — Fetch Table
- firewall_severity — Severity of events to fetch (Firewall)
- firewall_subtype — Subtype of events to fetch (Firewall)
- fetch_fields — Fetch Fields
- filter_query — Fetch Filter
- incidentType — Incident type
- limit — Max. number of incidents fetched per query
- proxy — Use system proxy settings
- insecure — Trust any certificate (not secure)
- incidentFetchInterval — Incidents Fetch Interval
Commands (19)
- cdl-get-critical-threat-logs — Runs a query on the threat table according to preset queries.
- cdl-get-social-applications — Runs a query on traffic table where app_sub_category = "social networking".
- cdl-query-file-data — Searches the Cortex firewall.file_data table.
- cdl-query-gp-logs — Searches the GlobalProtect VPN log table.
- cdl-query-logs — Runs a query on any table or field.
- cdl-query-threat-logs — Searches the Cortex panw.threat table, which is the threat logs table for PAN-OS/Panorama.
- cdl-query-traffic-logs — Searches the Cortex firewall.traffic table. Traffic logs contain entries for the end of each network session.
- cdl-query-url-logs — Searches the URL log table.
- cdl-reset-authentication-timeout — Use this command in case your authentication calls fail due to internal call-limit, the command will reset the limit cache.
- cdl-search-by-file-hash — Runs a query on the threat table with the query 'SELECT * FROM `firewall.threat` WHERE file_sha_256 = <file_hash>'.
- sls-get-critical-threat-logs — Runs a query on the threat table according to preset queries.
- sls-get-social-applications — Runs a query on traffic table where app_sub_category = "social networking".
- sls-query-file-data — Searches the Cortex firewall.file_data table.
- sls-query-gp-logs — Searches the GlobalProtect VPN log table.
- sls-query-logs — Runs a query on any table or field.
- sls-query-threat-logs — Searches the Cortex panw.threat table, which is the threat logs table for PAN-OS/Panorama.
- sls-query-traffic-logs — Searches the Cortex firewall.traffic table. Traffic logs contain entries for the end of each network session.
- sls-query-url-logs — Searches the URL log table.
- sls-search-by-file-hash — Runs a query on the threat table with the query 'SELECT * FROM `firewall.threat` WHERE file_sha_256 = <file_hash>'.