Palo Alto Networks Firewall via SLS Integration
Palo Alto Networks NGFW via Strata Logging Service provides a cloud-delivered, scalable, and secure solution for log storage and analysis. This integration enables Cisco XDR with detection of various security events.
-
In the Cisco XDR navigation menu, choose Administration > Integrations.
-
On the Integrations page, click the Third-Party tab and navigate to the Palo Alto Networks Firewall via SLS integration.
-
Click the plus sign (+) in the lower-right corner of the card. The Palo Alto Networks Firewall via SLS integration page is displayed.
-
Expand the Integration Guide area and follow the instructions on how to add the Palo Alto Networks Firewall via SLS integration in Cisco XDR.
Incidents are groups of correlated events generated using data ingested from your integrated products. By correlating events which could be part of a larger threat into an incident, it reduces the time typically required to investigate individual security alerts or detections. For more information about Cisco XDR Incidents feature, see Incidents.
When you enable the Palo Alto Networks Firewall via SLS integration, Cisco XDR ingests the configured logs from Palo Alto Networks Firewall via SLS for incident correlation.
To view incidents with Palo Alto Networks Firewall via SLS data:
-
In the Cisco XDR navigation menu, choose Incidents.
-
Look for PAN Firewalls via Strata Logging Service in the Source column to find incidents generated with Palo Alto Networks Firewall via SLS data.
-
Select an incident and open the Incident Detail page.
-
Click on the Detection page to see events from Palo Alto Networks Firewall via SLS and other sources.
You can perform the following task after you integrate Palo Alto Networks Firewalls via SLS with Cisco XDR:
-
Detections - View the security events generated by Palo Alto Networks Firewalls via SLS to validate the data that is ingested by Cisco XDR for incident generation. For details, see Detections.