Palo Alto Networks Cortex
Deprecated. We recommend using the Cortex Data Lake integration instead. This framework manages all PA's cloud managed products
- Category
- Analytics & SIEM
- Pack
- DeprecatedContent
Configuration parameters
- token — Authentication Token (required)
- auth_id — Authentication ID (required)
- auth_key — Authentication Key (required)
- proxy — Use system proxy settings
- insecure — Trust any certificate (not secure)
- isFetch — Fetch incidents
- incidentType — Incident type
- fetch_query — Query for fetching events
- first_fetch_timestamp — First fetch time (<number> <time unit>, e.g., 12 hours, 7 days, 3 months, 1 year)
- traps_severity — Severity of events to fetch (Traps)
- firewall_severity — Severity of events to fetch (Firewall)
- firewall_subtype — Subtype of events to fetch (Firewall)
- xdr_severity — Severity of alerts to fetch (XDR Analytics)
- xdr_category — Category of alerts to fetch (XDR Analytics)
Commands (8)
- cortex-get-critical-threat-logs — Runs a query on the Cortex logging service, according to preset queries.
- cortex-get-social-applications — Runs a query on the Cortex logging service, according to preset queries.
- cortex-query-analytics-logs — Searches the Cortex tms.analytics table, which is the endpoint logs table for Traps Analytics.
- cortex-query-logs — Runs a query on the Cortex logging service.
- cortex-query-threat-logs — Searches the Cortex panw.threat table, which is the threat logs table for PAN-OS/Panorama.
- cortex-query-traffic-logs — Searches the Cortex panw.traffic table, which is the traffic logs table for PAN-OS and Panorama.
- cortex-query-traps-logs — Searches the Cortex tms.threat table, which is the threat logs table for the Traps endpoint protection and response.
- cortex-search-by-file-hash — Runs a query on the Cortex logging service, according to preset queries.