forked from demisto/content
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[Marketplace Contribution] PAN-OS by Palo Alto Networks - Content Pac…
…k Update (demisto#31985) (demisto#33088) * "contribution update to pack "PAN-OS by Palo Alto Networks"" * Update Panorama.yml * Update Panorama.py * Update Panorama.yml * Update Panorama_test.py * Update Panorama.yml * Update Panorama.py * pre-commit * Update 2_1_21.md * Update 2_1_21.md * Apply suggestions from code review * rn * rn --------- Co-authored-by: xsoar-bot <67315154+xsoar-bot@users.noreply.github.com> Co-authored-by: amkoppad <82898085+amkoppad@users.noreply.github.com> Co-authored-by: MLainer1 <mlainer@paloaltonetworks.com> Co-authored-by: MLainer1 <93524335+MLainer1@users.noreply.github.com> Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
- Loading branch information
Showing
6 changed files
with
42 additions
and
29 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
26 changes: 12 additions & 14 deletions
26
Packs/PAN-OS/Integrations/Panorama/Panorama_description.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,56 +1,54 @@ | ||
The integration uses the Panorama XML API. | ||
To obtain an API Key, run the following REST command and copy the key: | ||
https://[PanoramaIP]/api/?type=keygen&user=[user]&password=[password] | ||
|
||
For more information, visit the [Palo Alto Networks documentation](https://docs.paloaltonetworks.com/panorama). | ||
|
||
--- | ||
You need to create a separate integration instance for Palo Alto Networks Firewall and Palo Alto Networks. Unless specified otherwise, all commands are valid for both Firewall and Panorama. | ||
|
||
--- | ||
### Firewall: Configure the vsys | ||
- The vsys is located in the Firewall URL; e.g., https://<server>#device::<vsys>::device/setup | ||
|
||
### Panorama: Configure a device group | ||
- Access the Panorama UI. | ||
- Go to **Panorama** > **Device Groups**. | ||
- Choose a device group name. | ||
|
||
--- | ||
### Fetch Incidents | ||
The Panorama integration now supports fetch incidents. | ||
The Panorama integration now supports fetch incidents. | ||
The incidents are fetched according to a number of different optional log type queries. The log types are: **Traffic, Threat, URL, Data, Correlation, System, Wildfire, Decryption**. | ||
|
||
|
||
##### Max incidents per fetch | ||
##### Max incidents per fetch | ||
The max incidents per fetch parameter specifies the maximum number of incidents to fetch **per** Log Type Query. | ||
|
||
##### Log Type | ||
The queries that will be included during the fetch are decided according to the "Log Type" parameter (Multiple select dropdown). | ||
The queries that will be included during the fetch are decided according to the "Log Type" parameter (Multiple select dropdown). | ||
- Selecting "All" will use all the log type queries in the fetch. | ||
- To choose a specific set of queries, select their log types from the dropdown (make sure "All" option is unselected). | ||
|
||
##### Log Type Query | ||
##### Log Type Query | ||
- Each log type has its own query field in the instance configuration. | ||
- Note that the default query values has some example text in it, make sure to enter a valid query. | ||
|
||
##### Log Type Query Examples | ||
|
||
| Log Type | Query Example | | ||
|---------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------| | ||
| Traffic | (addr.src in {source}) and (addr.dst in {destination}) and (action eq {action}) | | ||
|---------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------| | ||
| Traffic | (addr.src in {source}) and (addr.dst in {destination}) and (action eq {action}) | | ||
| Threat | (severity geq high) | | ||
| URL | ((action eq block-override) or (action eq block-url)) and (severity geq high) | | ||
| Data | ((action eq alert) or (action eq wildfire-upload-success) or (action eq forward)) and (severity geq high) | | ||
| Correlation | (hostid eq {host_id}) and (match_time in {last_x_time}) and (objectname eq {object_name}) and (severity geq '{severity}') and (src in {source_address}) | | ||
| System | (subtype eq {sub_type}) and (severity geq {severity}) | | ||
| System | (subtype eq {sub_type}) and (severity geq {severity}) | | ||
| Wildfire Submission | ((action eq wildfire-upload-fail) or (action eq wildfire-upload-skip) or (action eq sinkhole)) | | ||
| Decryption | (app eq {application}) and (policy_name geq {policy_name}) and ((src in {source}) or (dst in {destination})) | | ||
|
||
##### Classifiers and Mappers | ||
|
||
This integration supports a default Classifier (Panorama Classifier) and Mapper (Panorama Mapper) that handles incidents returned from the API. | ||
|
||
--- | ||
|
||
[View Integration Documentation](https://xsoar.pan.dev/docs/reference/integrations/panorama) | ||
--- |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,7 @@ | ||
#### Integrations | ||
|
||
##### Palo Alto Networks PAN-OS | ||
|
||
- Added the feature to append a filename string to the run-config and device state files for the following commands: | ||
***pan-os-platform-get-device-state*** | ||
***pan-os-get-running-config*** |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters