Palo Alto Networks Cortex XSOAR

Integration version1.0.0

To find out if this integration is available in your organization, see your Datadog Integrations page or ask your organization administrator.

To initiate an exception request to enable this integration for your organization, email support@ddog-gov.com.

Overview

Palo Alto Networks Cortex XSOAR is a security orchestration, automation, and unifying incident response (SOAR) platform that helps teams automate incident handling, integrate security tools, and reduce remediation time.

This integration parses and ingests the following types of logs:

  • Audit Logs: Capture all administrative user activities within Palo Alto Networks Cortex XSOAR.
  • Incidents: Capture incident details, including severity, status, type, and ownership, to support tracking and investigation in Palo Alto Networks Cortex XSOAR.

Visualize detailed insights into these logs with out-of-the-box dashboards. This integration also includes Cloud SIEM detection rules to help you monitor and respond to potential security threats.

This integration collects the following metrics:

  • Automation Insight Metrics: Track playbook, task, and command execution activity, including counts, failures, and execution duration.
  • API Execution Metrics: Track API execution activity, including total calls and rate-limited requests.
  • SLA Metrics: Track incident response timelines, including mean time to detection, triage, containment, and resolution, along with counts of items within and outside SLA thresholds.

Visualize detailed insights into these metrics with out-of-the-box dashboards. This integration also includes monitors to alert you to any potential issues.

Setup

Generate API Key, API Key ID and API URL

  1. Sign in to Palo Alto Networks Cortex XSOAR platform.
  2. Navigate to Settings & Info > Settings > Integrations > API Keys.
  3. Click + New Key.
  4. Under Generate API Key:
    • Security Level: Select Standard.
    • Role: Select Read-Only.
  5. Click Generate.
  6. In the API Keys table, locate the ID field for the created API Key.
  7. Click Copy API URL to copy the API URL.

Connect your Palo Alto Networks Cortex XSOAR account to Datadog

  1. Add the following parameters:
    ParameterDescription
    API KeyThe Palo Alto Networks Cortex XSOAR API key.
    API Key IDThe Palo Alto Networks Cortex XSOAR API key ID.
    API URLThe Palo Alto Networks Cortex XSOAR API URL.
    Get IncidentsControl the collection of Incidents from Palo Alto Networks Cortex XSOAR. Enabled by default.
    Get Audit LogsControl the collection of Audit Logs from Palo Alto Networks Cortex XSOAR. Enabled by default.
    Get Automation Insight MetricsControl the collection of Automation Insights from Palo Alto Networks Cortex XSOAR. Enabled by default.
    Get API Execution MetricsControl the collection of API Executions from Palo Alto Networks Cortex XSOAR. Enabled by default.
    Get SLA MetricsControl the collection of SLA Insights from Palo Alto Networks Cortex XSOAR. Enabled by default.
  2. Click Save.

Data Collected

Logs

The Palo Alto Networks Cortex XSOAR integration collects and forwards incidents and audit logs to Datadog.

Metrics

palo_alto_networks_cortex_xsoar.api_execution.count
(count)
Total number of API executions.
palo_alto_networks_cortex_xsoar.api_execution.rate_limited_api_call_count
(count)
Total number of rate-limited API calls.
palo_alto_networks_cortex_xsoar.command_execution.count
(count)
Total number of command executions.
palo_alto_networks_cortex_xsoar.command_execution.failed_count
(count)
Total number of failed command executions.
palo_alto_networks_cortex_xsoar.playbook_execution.avg_duration
(gauge)
Average duration of playbook executions.
Shown as second
palo_alto_networks_cortex_xsoar.playbook_execution.count
(count)
Total number of playbook executions.
palo_alto_networks_cortex_xsoar.playbook_execution.failed_count
(count)
Total number of failed playbook executions.
palo_alto_networks_cortex_xsoar.sla.late_count
(count)
Total number of late SLA incidents.
palo_alto_networks_cortex_xsoar.sla.mean_time_to_containment
(gauge)
Average time taken to control incidents as per SLA.
Shown as second
palo_alto_networks_cortex_xsoar.sla.mean_time_to_detection
(gauge)
Average time taken to detect incidents as per SLA.
Shown as second
palo_alto_networks_cortex_xsoar.sla.mean_time_to_resolution
(gauge)
Average time taken to resolve incidents as per SLA.
Shown as second
palo_alto_networks_cortex_xsoar.sla.mean_time_to_triage
(gauge)
Average time taken to triage incidents as per SLA.
Shown as second
palo_alto_networks_cortex_xsoar.sla.within_count
(count)
Total number of incidents within SLA.
palo_alto_networks_cortex_xsoar.task_execution.count
(count)
Total number of task executions.
palo_alto_networks_cortex_xsoar.task_execution.failed_count
(count)
Total number of failed task executions.

Events

The Palo Alto Networks Cortex XSOAR integration does not include any events.

Troubleshooting

Need help? Contact Datadog support.