---
title: Palo Alto Networks Cortex XSOAR
description: >-
  Gain insights into Palo Alto Networks Cortex XSOAR audit logs, incidents, and
  metrics.
breadcrumbs: Docs > Integrations > Palo Alto Networks Cortex XSOAR
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Palo Alto Networks Cortex XSOAR
Integration version1.0.0
{% callout %}
# Important note for users on the following Datadog sites: us2.ddog-gov.com

{% alert level="info" %}
To find out if this integration is available in your organization, see your [Datadog Integrations](https://app.datadoghq.com/integrations) page or ask your organization administrator.

To initiate an exception request to enable this integration for your organization, email [support@ddog-gov.com](mailto:support@ddog-gov.com).
{% /alert %}

{% /callout %}
            Palo Alto Networks Cortex XSOAR OverviewPalo Alto Networks Cortex XSOAR OverviewPalo Alto Networks Cortex XSOAR Audit LogsPalo Alto Networks Cortex XSOAR Audit LogsPalo Alto Networks Cortex XSOAR IncidentsPalo Alto Networks Cortex XSOAR IncidentsPalo Alto Networks Cortex XSOAR MetricsPalo Alto Networks Cortex XSOAR Metrics
## Overview{% #overview %}

[Palo Alto Networks Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar) is a security orchestration, automation, and unifying incident response (SOAR) platform that helps teams automate incident handling, integrate security tools, and reduce remediation time.

This integration parses and ingests the following types of logs:

- **Audit Logs**: Capture all administrative user activities within Palo Alto Networks Cortex XSOAR.
- **Incidents**: Capture incident details, including severity, status, type, and ownership, to support tracking and investigation in Palo Alto Networks Cortex XSOAR.

Visualize detailed insights into these logs with out-of-the-box dashboards. This integration also includes Cloud SIEM detection rules to help you monitor and respond to potential security threats.

This integration collects the following metrics:

- **Automation Insight Metrics**: Track playbook, task, and command execution activity, including counts, failures, and execution duration.
- **API Execution Metrics**: Track API execution activity, including total calls and rate-limited requests.
- **SLA Metrics**: Track incident response timelines, including mean time to detection, triage, containment, and resolution, along with counts of items within and outside SLA thresholds.

Visualize detailed insights into these metrics with out-of-the-box dashboards. This integration also includes monitors to alert you to any potential issues.

## Setup{% #setup %}

### Generate API Key, API Key ID and API URL{% #generate-api-key-api-key-id-and-api-url %}

1. Sign in to Palo Alto Networks Cortex XSOAR platform.
1. Navigate to **Settings & Info** > **Settings** > **Integrations** > **API Keys**.
1. Click **+ New Key**.
1. Under **Generate API Key**:
   - **Security Level**: Select **Standard**.
   - **Role**: Select **Read-Only**.
1. Click **Generate**.
1. In the **API Keys** table, locate the **ID** field for the created API Key.
1. Click **Copy API URL** to copy the API URL.

### Connect your Palo Alto Networks Cortex XSOAR account to Datadog{% #connect-your-palo-alto-networks-cortex-xsoar-account-to-datadog %}

1. Add the following parameters:
| Parameter                      | Description                                                                                             |
| ------------------------------ | ------------------------------------------------------------------------------------------------------- |
| API Key                        | The Palo Alto Networks Cortex XSOAR API key.                                                            |
| API Key ID                     | The Palo Alto Networks Cortex XSOAR API key ID.                                                         |
| API URL                        | The Palo Alto Networks Cortex XSOAR API URL.                                                            |
| Get Incidents                  | Control the collection of Incidents from Palo Alto Networks Cortex XSOAR. Enabled by default.           |
| Get Audit Logs                 | Control the collection of Audit Logs from Palo Alto Networks Cortex XSOAR. Enabled by default.          |
| Get Automation Insight Metrics | Control the collection of Automation Insights from Palo Alto Networks Cortex XSOAR. Enabled by default. |
| Get API Execution Metrics      | Control the collection of API Executions from Palo Alto Networks Cortex XSOAR. Enabled by default.      |
| Get SLA Metrics                | Control the collection of SLA Insights from Palo Alto Networks Cortex XSOAR. Enabled by default.        |
1. Click **Save**.

## Data Collected{% #data-collected %}

### Logs{% #logs %}

The Palo Alto Networks Cortex XSOAR integration collects and forwards incidents and audit logs to Datadog.

### Metrics{% #metrics %}

|  |
|  |
| **palo_alto_networks_cortex_xsoar.api_execution.count**(count)                           | Total number of API executions.                                      |
| **palo_alto_networks_cortex_xsoar.api_execution.rate_limited_api_call_count**(count) | Total number of rate-limited API calls.                              |
| **palo_alto_networks_cortex_xsoar.command_execution.count**(count)                       | Total number of command executions.                                  |
| **palo_alto_networks_cortex_xsoar.command_execution.failed_count**(count)               | Total number of failed command executions.                           |
| **palo_alto_networks_cortex_xsoar.playbook_execution.avg_duration**(gauge)              | Average duration of playbook executions.*Shown as second*            |
| **palo_alto_networks_cortex_xsoar.playbook_execution.count**(count)                      | Total number of playbook executions.                                 |
| **palo_alto_networks_cortex_xsoar.playbook_execution.failed_count**(count)              | Total number of failed playbook executions.                          |
| **palo_alto_networks_cortex_xsoar.sla.late_count**(count)                                | Total number of late SLA incidents.                                  |
| **palo_alto_networks_cortex_xsoar.sla.mean_time_to_containment**(gauge)                | Average time taken to control incidents as per SLA.*Shown as second* |
| **palo_alto_networks_cortex_xsoar.sla.mean_time_to_detection**(gauge)                  | Average time taken to detect incidents as per SLA.*Shown as second*  |
| **palo_alto_networks_cortex_xsoar.sla.mean_time_to_resolution**(gauge)                 | Average time taken to resolve incidents as per SLA.*Shown as second* |
| **palo_alto_networks_cortex_xsoar.sla.mean_time_to_triage**(gauge)                     | Average time taken to triage incidents as per SLA.*Shown as second*  |
| **palo_alto_networks_cortex_xsoar.sla.within_count**(count)                              | Total number of incidents within SLA.                                |
| **palo_alto_networks_cortex_xsoar.task_execution.count**(count)                          | Total number of task executions.                                     |
| **palo_alto_networks_cortex_xsoar.task_execution.failed_count**(count)                  | Total number of failed task executions.                              |

### Events{% #events %}

The Palo Alto Networks Cortex XSOAR integration does not include any events.

## Troubleshooting{% #troubleshooting %}

Need help? Contact [Datadog support](https://docs.datadoghq.com/help/).
