For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex XDR 3.x

Ingest data from Prisma Access

Learn how to ingest detection data from Prisma Access.

Notice

Ingestion of logs and data requires a Cortex XDR Pro per GB license.

You can forward data from Prisma Access to Cortex XDR. When your Cortex XDR tenant begins receiving detection data, it begins stitching logs with other Palo Alto Networks-generated logs to form stories. Use the XQL Search to query the data.

Collection of data from multiple accounts is supported. Super User permissions on both the Cortex XDR tenant accounts and the Prisma Access accounts are required for this use case.

New tenants (and tenants upgraded from XDR to XSIAM) will work with the new direct integration of Next-Generation Firewall and Panorama into Cortex. For such tenants, there’s no option to use the Strata Logging Service integration.

For tenants where customers have integrated directly with Strata Logging Service, the configured integrations, such as Next-Generation Firewall and Prisma Access, can be migrated to Cortex XDR in either of the following ways before the license expires:

  • More than two weeks before the license for existing integrations with Strata Logging Service expires, manually migrate the integrations, using the corresponding Migrate Devices buttons on the Collection Integrations page. Make sure you select all your devices to connect directly to Cortex XDR.

  • Two weeks prior to the end of your Strata Logging Service license, Cortex XDR will automatically migrate your integrations to your Strata Logging Service.

    Note

    Roll-back of Strata Logging Service integration migration is not supported.

Prerequisite

The logs ingested by Prisma Access are the same as the logs ingested by Next-Generation Firewall. For more information, refer to Ingest data from Next-Generation Firewall.

To ingest detection data from Prisma Access:

  1. Select SettingsConfigurationsData CollectionCollection Integrations.

  2. In the Prisma Access configuration, click Add Instance.

    Note

    Cortex XDR does not validate your Prisma Access account credentials. You must ensure the account has been deployed in order for data to stream.

  3. In the Connect Prisma Access dialog box, you can choose to connect Prisma Access to this account or other accounts.

    • To connect Prisma Access to this account, click Connect.

    • To connect Prisma Access to other accounts, click Connect Prisma Access from other accounts and select the account from the accounts listed. Click Connect.

    Connection can take up to several minutes.

    On the Collection Integrations page, expand Prisma Access to track the status of your instance.

  4. Validate that your data is streaming.

    To ensure the data is streaming into your tenant, using XQL, query Next-Generation Firewall raw datasets panw_ngfw_<*>_raw, using the field: is_prisma_mobile.

  5. (Optional) Manage your Instance.

    After you create the Prisma Access instance, on the Collection Integrations page, expand the Prisma Access integration to track the connection, or, if you want, to Delete the instance.

Last updated

Was this helpful?