category: Endpoint provider: Palo Alto Networks sectionorder: - Connect - Collect commonfields: id: Cortex XDR - IR version: -1 configuration: - display: Fetch incidents name: isFetch defaultvalue: 'true' type: 8 section: Collect required: false - display: Incidents Fetch Interval name: incidentFetchInterval defaultvalue: '1' type: 19 section: Collect required: false - display: Incident type name: incidentType type: 13 section: Collect required: false defaultvalue: 'Cortex XDR - Lite' - name: url type: 0 display: 'Server URL (copy URL from XDR)' section: Connect required: true - displaypassword: API Key ID name: apikey_id_creds type: 9 hiddenusername: true display: '' section: Connect required: false - display: '' name: apikey_creds type: 9 section: Connect required: false displaypassword: API Key hiddenusername: true - defaultvalue: 'false' display: Remove legacy incident fields name: dont_format_sublists type: 8 section: Collect required: false additionalinfo: Not selected for backwards compatibility. Recommended to select. This will remove duplicated incident fields under file_artifacts, network_artifacts, and alerts (like client_id, clientid.) - display: Incident Mirroring Direction name: mirror_direction required: false type: 15 section: Collect defaultvalue: None options: - None - Incoming - Outgoing - Both hidden: - marketplacev2 - platform additionalinfo: Not supported on Cortex platform. - additionalinfo: When selected, closing the Cortex XDR incident is mirrored in Cortex XSOAR. defaultvalue: 'true' display: Close Mirrored XSOAR Incident name: close_xsoar_incident type: 8 section: Collect advanced: true required: false - additionalinfo: "When selected, closing the Cortex XSOAR incident is mirrored in Cortex XDR. Notice: If not selected, but 'Close all related alerts in XDR' is selected, the incident will automatically be closed in Cortex XDR." defaultvalue: 'true' display: Close Mirrored Cortex XDR Incident name: close_xdr_incident type: 8 section: Collect advanced: true required: false - defaultvalue: '1' display: XDR mirroring delay in minutes name: xdr_delay type: 0 section: Collect required: false advanced: true additionalinfo: "In the event of a delay in mirroring incoming changes from XDR, use the xdr_delay parameter to extend the look-back period. However, be aware that this may result in increased latency when updating incidents." - display: Custom close-reason mapping (XSOAR -> XDR mirrored incident. Overwrites default close-reason mapping defined by Cortex XSOAR) section: Collect advanced: true additionalinfo: 'Define how to close the mirrored incidents from Cortex XSOAR into Cortex XDR with a custom close reason mapping. Enter a comma-separated list of close reasons (acceptable format {Cortex XSOAR close reason}={Cortex XDR close reason}) to override the default close reason mapping defined by Cortex XSOAR. Note that the mapping must be configured accordingly with the existing close reasons in Cortex XSOAR and Cortex XDR. Not following this format will result in closing the incident with a default close reason. Example: "Resolved=Other,Duplicate=Other". Refer to ../README.md for possible close-reasons - `XDR Incident Mirroring`.' name: custom_xsoar_to_xdr_close_reason_mapping defaultvalue: '' type: 0 required: false - display: Custom close-reason mapping (XDR -> XSOAR mirrored incident. Overwrites default close-reason mapping defined by Cortex XSOAR) section: Collect advanced: true additionalinfo: 'Define how to close the mirrored incidents from Cortex XDR into Cortex XSOAR with a custom close reason mapping. Enter a comma-separated list of close reasons (acceptable format {Cortex XDR close reason}={Cortex XSOAR close reason}) to override the default close reason mapping defined by Cortex XSOAR. Note that the mapping must be configured accordingly with the existing close reasons in Cortex XSOAR and Cortex XDR. Not following this format will result in closing the incident with a default close reason. Example: “Known Issue=Resolved, Duplicate Incident=Other". Refer to ../README.md for possible close-reasons - `XDR Incident Mirroring`.' name: custom_xdr_to_xsoar_close_reason_mapping defaultvalue: '' type: 0 required: false - display: API Key ID name: apikey_id type: 4 hidden: true section: Connect required: false - display: API Key name: apikey type: 4 section: Connect required: false hidden: true - additionalinfo: The timeout of the HTTP requests sent to Cortex XDR API (in seconds). defaultvalue: '120' display: HTTP Timeout name: timeout type: 0 section: Connect required: false advanced: true - display: Maximum number of incidents per fetch name: max_fetch type: 0 section: Collect required: false additionalinfo: The maximum number of incidents per fetch. Cannot exceed 100. defaultvalue: '10' - display: Only fetch starred incidents name: starred type: 8 section: Collect advanced: true required: false - defaultvalue: 3 days display: Starred incidents fetch window name: starred_incidents_fetch_window type: 0 section: Collect required: false additionalinfo: Starred fetch window timestamp (