category: Network Security
provider: Palo Alto Networks
sectionorder:
- Connect
- Collect
commonfields:
id: SaasSecurity
version: -1
configuration:
- display: Server URL
name: url
defaultvalue: https://api.aperture.paloaltonetworks.com
additionalinfo: 'The instance configuration URL based on the server location:
US: https://api.aperture.paloaltonetworks.com
EU: https://api.aperture-eu.paloaltonetworks.com
APAC: https://api.aperture-apac.paloaltonetworks.com'
type: 0
required: true
section: Connect
- display: Client ID
displaypassword: Client Secret
name: credentials
type: 9
required: true
additionalinfo: The SaaS Security Client ID and Client Secret.
section: Connect
- display: Fetch incidents
name: isFetch
type: 8
required: false
section: Collect
supportedModules:
- agentix
- xsiam
- display: Incidents Fetch Interval
name: incidentFetchInterval
defaultvalue: "1"
type: 19
required: false
section: Collect
supportedModules:
- agentix
- xsiam
- display: Incident type
name: incidentType
type: 13
required: false
section: Collect
supportedModules:
- agentix
- xsiam
- additionalinfo: 'Selects which direction you want the incidents mirrored. You can mirror Incoming only (from SaaS Security to Cortex XSOAR), **Outgoing** only (from Cortex XSOAR to SaaS Security), or both **Incoming And Outgoing**.'
defaultvalue: None
display: Incident Mirroring Direction
hidden:
- marketplacev2
- platform
name: mirror_direction
options:
- None
- Incoming
- Outgoing
- Incoming And Outgoing
type: 15
required: false
section: Collect
- display: Number of incidents per fetch.
name: max_fetch
defaultvalue: "20"
type: 0
required: true
additionalinfo: "Important: The limit value can range from 10 to 200 and must be in multiples of 10."
section: Collect
supportedModules:
- agentix
- xsiam
- display: First fetch timestamp (