For the complete documentation index, see llms.txt. This page is also available as Markdown.

Ingest data from Prisma Access

Learn how to ingest detection data from Prisma Access.

Notice

Requires the Data Collection add-on.

You can forward data from Prisma Access to Cortex Cloud. When your Cortex Cloud tenant begins receiving detection data, it begins stitching logs with other Palo Alto Networks-generated logs to form stories. Use the XQL Search to query the data.

Collection of data from multiple accounts is supported. Super User permissions on both the Cortex Cloud tenant accounts and the Prisma Access accounts are required for this use case.

New tenants (and tenants upgraded from XDR to XSIAM) will work with the new direct integration of Next-Generation Firewall and Panorama into Cortex. For such tenants, there’s no option to use the Strata Logging Service integration.

For tenants where customers have integrated directly with Strata Logging Service, the configured integrations, such as Next-Generation Firewall and Prisma Access, can be migrated to Cortex Cloud in either of the following ways before the license expires:

  • More than two weeks before the license for existing integrations with Strata Logging Service expires, manually migrate the integrations, using the corresponding Migrate Devices buttons on the Data Sources & Integrations page. Make sure you select all your devices to connect directly to Cortex Cloud.

  • Two weeks prior to the end of your Strata Logging Service license, Cortex Cloud will automatically migrate your integrations to your Strata Logging Service.

    Note

    Roll-back of Strata Logging Service integration migration is not supported.

Prerequisite

Note

If you change a device region, you must first disconnect the device from Cortex Cloud and then reconnect it after the region change is complete.

The logs ingested by Prisma Access are the same as the logs ingested by Next-Generation Firewall. For more information, refer to Ingest data from Next-Generation Firewall.

To ingest detection data from Prisma Access:

  1. Navigate to SettingsData Sources & Integrations.

  2. On the Data Sources & Integrations page, click + Add New, search for Prisma Access, then hover over it and click Add or Add Instance.

    Note

    Cortex Cloud does not validate your Prisma Access account credentials. You must ensure the account has been deployed in order for data to stream.

  3. In the Connect Prisma Access dialog box, you can choose to connect Prisma Access to this account or other accounts.

    • To connect Prisma Access to this account, click Connect.

    • To connect Prisma Access to other accounts, click Connect Prisma Access from other accounts and select the account from the accounts listed. Click Connect.

    Connection can take up to several minutes.

    On the Data Sources & Integrations page, expand Prisma Access to track the status of your instance.

  4. Validate that your data is streaming.

    To ensure the data is streaming into your tenant, using XQL, query Next-Generation Firewall raw datasets panw_ngfw_<*>_raw using the field: is_prisma_mobile.

  5. (Optional) Manage your Instance.

    After you create the Prisma Access instance, on the Data Sources & Integrations page, expand the Prisma Access integration to track the connection, or, if you want, to Delete the instance.

Last updated

Was this helpful?