For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex Cloud Posture

Palo Alto Networks integrations

Cortex Cloud supports data ingestion and orchestration from other Palo Alto Networks products. These integrations are provided through unified Connectors, ensuring comprehensive visibility and seamless cross-platform security operations.

Notice

Data collection may require an add-on.

Ingestion methods

Integrations are handled via the following method:

  • Connectors: The strategic, unified approach for integrating Palo Alto Networks services. A connector consolidates multiple security capabilities, such as Data Security, Identity Posture, and Automation, into a single, guided configuration flow.

    • Availability: These connectors are available for tenants onboarded after July 26, 2026.

    • Legacy support: Existing tenants (onboarded prior to July 26, 2026) can achieve similar functionality by using the standalone Marketplace integrations linked within each product topic. For more information, see Marketplace.

Technical reference requirements for connectors

While the unified wizard handles the configuration for new connectors, you should refer to the Cortex Developer Docs for Marketplace (PAN DEV) for specific technical information related to the integration (now referred to as a sub-capability in the new connector world), such as:

  • Fetched incidents data

  • Available commands

  • Required incident fields and data schemas not provided in the wizard.

General requirements

Ensure you meet the following requirements before configuring your integrations:

  • Deploy the relevant Palo Alto Networks products.

  • Hold Super User permissions for your Customer Support Portal (CSP) account.

  • After your tenant has been activated, navigate to the Data Sources & Integrations page in Cortex Cloud to configure your integrations.

  • All devices and accounts allocated to your CSP accounts are available to integrate.

Supported Integrations

Cortex Cloud provides specific documentation and configuration steps for each Palo Alto Networks integration. Select an integration to view its supported ingestion methods and configuration requirements.

Last updated

Was this helpful?