Halcyon (v1.0.6)

Halcyon is a device management platform that helps organizations monitor, control, and secure their network of devices. It provides centralized tools for overseeing hardware and software inventory, deploying updates, enforcing security policies, and ensuring compliance across device environments.

Author
Cortex XSOAR
Support
xsoar
URL
https://www.paloaltonetworks.com/cortex
Default data source
Halcyon
Categories
Endpoint

Integrations (1)

Modeling rules (1)

README

Halcyon

Halcyon is a device management platform that helps organizations monitor, control, and secure their network of devices. It provides centralized tools for overseeing hardware and software inventory, deploying updates, enforcing security policies, and ensuring compliance across device environments.

What does this pack do?

This pack enables you to collect security alerts and events from the Halcyon platform and ingest them into Cortex XSIAM for analysis and correlation.

Key Features

Data Collected

Log Type Description Time Field
Alerts Security alerts from Halcyon lastOccurredAt
Events Operational events from Halcyon occurredAt

Dataset

All collected data is stored in the halcyon_halcyon_raw dataset in Cortex XSIAM.

Pack Contents

Integrations

Modeling Rules

Getting Started

  1. Obtain your Halcyon API credentials (username and password)
  2. Configure the Halcyon integration instance in Cortex XSIAM
  3. Enable event fetching to start collecting data

For detailed configuration instructions, see the Halcyon Integration README.

Requirements

Support

For support, please contact Cortex XSOAR support or visit the Palo Alto Networks support portal.