Documentation Index

Fetch the complete documentation index at: https://docs.safe.security/llms.txt

Use this file to discover all available pages before exploring further.

Palo Alto Networks Cortex XDR Connector Guide

Prev Next

Palo Alto Networks Cortex XDR is an extended detection and response platform that provides agent-based endpoint protection, behavior-based threat detection and rapid threat investigation for root cause analysis and response. The Balbix integration with PAN Cortex XDR  ingests IT infrastructure assets, software information, and user information for endpoints protected by Cortex XDR.

Balbix leverages AI to aggregate, normalize, and deduplicate ingested data, along with information integrated from your existing IT and cybersecurity tools. This creates a unified view of your entire asset inventory, including vulnerabilities and their business and operational context. Balbix’s AI models then analyze this data to provide insights such as deployment gap analysis, risk-based vulnerability prioritization (with detailed ranking and scoring), and risk quantification. This process delivers a comprehensive assessment of risk, whether for a single asset, groups of assets, or your entire enterprise, enabling more informed and effective security decisions.

Integration Summary

This table provides a summary of the Balbix integration for the Palo Alto Networks Cortex XDR connector.

Integration Type

Fetch: An inbound API integration used to fetch IT infrastructure assets, software, users, and patch information.

Types of Assets Fetched

Host devices including servers, virtual machines, desktops, laptops.

Types of Data Fetched

Asset names, hardware information, interface information (MAC address, IP address), OS information, software information, patch information, timestamps (patch_install_date), user account information.

Prerequisites

To configure the Balbix connector, you must first create Palo Alto Networks Cortex XDR API credentials with the appropriate permissions. These credentials are required for completing the configuration process.  

Here are the steps you need to complete:

  1. Create an API Key: Generate a unique API key to authenticate and access API resources securely.

  2. Get an API Key ID: Retrieve the identifier associated with your API key for use in API requests.

  3. Get the FQDN: Obtain the fully qualified domain name (FQDN) assigned to your tenant for configuration purposes.

Auth Permissions and Roles

  • Endpoint Management in the Views category

Create an API Key

To generate an API key from Palo Alto Networks Cortex XDR:

  1. In the Cortex XDR portal, go to Configurations > Integrations > API Keys.

  2. Click + New Key.

  3. Choose Standard as the security level.

  4. Choose a role that has endpoint management as a permission in the Views category.

  5. Click Generate.

  6. Copy the API key and securely save it for later use when setting up the PAN Cortex XDR connector.

  7. Click Done.

Get the API Key ID

The API Key ID is your unique token used to authenticate the API Key. You will need the key ID when configuring the Balbix connector.

  1. Locate your API key and its corresponding ID number in the API Keys table.

  2. Copy the API key ID and securely save it for later use when setting up the PAN Cortex XDR connector in Balbix.

Get the FQDN

The FQDN is a unique host and domain name assigned to each tenant and is needed to configure the Balbix connector. To obtain it, go to the API Keys table, click on your API key, and then click Copy URL.

Create and Configure the Connector

After you have completed the prerequisites, follow these steps to create and configure your Balbix connector for Palo Alto Networks Cortex XDR.

Field Mapping

Imported Field

Balbix Field

[device_id]

asset_id

[host_name]

host_name

[local_ip]

ip_address

[mac_address]

mac_address

[operating_system]

os_name

[os_version]

os_version

[softwares,application_name]

sw_product_name

[softwares,version]

sw_product_version

[softwares,vendor]

sw_product_vendor

[kbs,name]

patch_number

[kbs,install_date]

patch_install_date

[kbs,status]

patch_status

[user_names]

user_accounts

API Reference Documentation

To learn more about the Palo Alto Networks Cortex XDR API, see the references listed below: