For the complete documentation index, see llms.txt. This page is also available as Markdown.

About Palo Alto Networks integrations

Stream data directly from other Palo Alto Networks products to Cortex Cloud.

Cortex Cloud supports streaming data directly from Prisma Access accounts, Next-Generation Firewalls (NGFW), and Panorama devices to your Cortex Cloud tenants using the Strata Logging Service.

Ensure you have deployed Panorama and NGFW, and hold Super User permissions to your Customer Support Account (CSP).

After your tenant has been activated, navigate to the Data Sources & Integrations page to configure your integrations. All devices and accounts allocated to your CSP accounts are available to integrate.

Note

For Palo Alto Networks Integrations there is an option to turn on or off the collection of URL and File log types. For more information, see Collecting URL and File log types.

New tenants (and tenants upgraded from XDR to XSIAM) will work with the new direct integration of Next-Generation Firewall and Panorama into Cortex. For such tenants, there’s no option to use the Strata Logging Service integration.

For tenants where customers have integrated directly with Strata Logging Service, the configured integrations, such as Next-Generation Firewall and Prisma Access, can be migrated to Cortex Cloud in either of the following ways before the license expires:

  • More than two weeks before the license for existing integrations with Strata Logging Service expires, manually migrate the integrations, using the corresponding Migrate Devices buttons on the Data Sources & Integrations page. Make sure you select all your devices to connect directly to Cortex Cloud.

  • Two weeks prior to the end of your Strata Logging Service license, Cortex Cloud will automatically migrate your integrations to your Strata Logging Service.

    Note

    Roll-back of Strata Logging Service integration migration is not supported.

Last updated

Was this helpful?