Palo Alto Networks Cortex XDR
Palo Alto Networks Cortex XDR is a detection and response app that natively integrates network, endpoint, and cloud data to detect threats and stop sophisticated attacks.
Configuring the Connector for Palo Alto Networks Cortex XDR
To configure Lucidum to ingest data from Palo Alto Networks Cortex XDR:
Log in to Lucidum.
In the left pane, click Connector.
In the Connector page, click Add Connector.
Scroll until you find the Connector you want to configure. Click Connect. The Settings page appears.
In the Settings page, enter the following:
FQDN (required) - Specify the fully qualified domain name (FQDN). For example, https://***.xdr.us.paloaltonetworks.com/. For more details, see https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-API-Reference/APIs-Overview
API Key (required) - Specify an Advanced API key, generated in the Cortex XDR app. For more details on generating an Advanced Security Level API, see https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-API-Reference/APIs-Overview
API Key ID (required). Specify the API Key ID of an Advanced API key. For more details, see https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-API-Reference/APIs-Overview .
Verify SSL. For future use.
To test the configuration, click Test.
If the connector is configured correctly, Lucidum displays a list of services that are accessible with the connector.
If the connector is not configured correctly, Lucidum displays an error message.
Supported Actions
Isolate Endpoints
Unisolate Endpoints
Scan Endpoints
Cancel Scan Endpoints
Run Script from the Script Library