> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/integrations.md).

# Integrations

Cortex Xpanse integrates with third-party tools and services and other Palo Alto Networks products to support many use cases, including the following:

* Maintain accurate asset inventory—Integrate Expander with IT and IT security systems that require an accurate source of truth of your organization's public-facing assets.
* Generate notifications—Set up SIEM-configured notifications so you will be alerted on new assets and exposures quickly.
* Kick off investigations—Kick off investigations of exposures with IT tickets to drive remediation action and reduce the number of exposures on your network edge.
* Automate remediations—Cortex Xpanse Active Response uses automation integrations with playbooks to augment alert investigation and remediate risks automatically.

## Types of Integrations

Cortex Xpanse supports the following types of integrations:

| Type of Integration     | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | More Information                                                                                                                                                                                                                                                      |
| ----------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Collection Integrations | <p>Cortex Xpanse supports two types of collection integrations:</p><ul><li>Cloud Inventory integrations that ingest cloud compute instances from the major cloud providers (Amazon Web Services (AWS), Google Cloud Platform (GCP), MS Azure)</li><li>Prisma Cloud integration that ingests cloud resources from your Prisma Cloud inventory.</li></ul><p>Both of these collection integrations bring cloud context into Expander where it can be enriched with ASM data, providing a unified, normalized inventory of your cloud assets.</p> | <ul><li><a href="/pages/v1v57KD2Q6PMiYl37ZUJ">Configure Collection Integrations</a></li><li><a href="/pages/2ZWHPNG9aMG4cXZAmjtb">Ingest Cloud Resources from Prisma Cloud</a></li></ul>                                                                              |
| Automation Integrations | Automation integrations are used by Active Response playbooks to enrich an alert or respond to an alert with an action, such as sending notifications or remediating the alert by directly modifying the configuration of an asset, service, or networking infrastructure.                                                                                                                                                                                                                                                                    | <ul><li><a href="/pages/CLcvHtjjGeovyXnJrrTI#UUID-8de97a57-0ad7-40ec-cc78-86b24045fb5d_UUID-7104d590-d1a9-d4a3-6fa3-320c333c9c77">Supported Automation Integrations</a></li><li><a href="/pages/emd6SUADCvCKxcaHPt46">Configure Automation Integrations</a></li></ul> |
| Outbound Integrations   | Outbound integrations push or pull information from Xpanse into a third party security or workflow tool in order to integrate into to an organization’s existing vulnerability or incident response system.                                                                                                                                                                                                                                                                                                                                   | [Set up Outbound Integrations](#UUID-41c1d5c6-8368-4c59-7f37-db80efaba7b4_section-idm4573021523427234024349623851)                                                                                                                                                    |
| Expander REST APIs      | Expander includes a REST API capable of querying, exporting, and interacting with many areas of the product, including assets, services, alerts, and incidents. The API also supports actions such as user management and tagging. In addition to the Expander API, a Python SDK is also available for more rapid development.                                                                                                                                                                                                                | <ul><li><a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-Xpanse-REST-API">Cortex Xpanse REST API</a></li><li><a href="https://cortex-xpanse-python-sdk.readthedocs.io/en/latest/">Cortex Xpanse Python SDK</a></li></ul>                                    |

## Cortex Xpanse Outbound Integrations

Outbound integrations push or pull information from Xpanse into a third party security or workflow tool. These integrations enable you to to integrate Xpanse into to your organization’s existing vulnerability or incident response system. Cortex Xpanse provides the following outbound integrations:

* [Integrate with Cortex XSOAR](https://cortex.marketplace.pan.dev/marketplace/details/CortexXpanse/)—Forward risks from Expander to XSOAR via API where you can build custom playbooks to triage and remediate. This integration also includes commands to call Expander APIs for enrichment purposes.
* [Integrate a Syslog Receiver](/cortex-xpanse/onboard-and-configure-cortex-xpanse/post-deployment-steps/log-forwarding.md#UUID-78a09519-2c20-b9ea-08cd-b77221d03e02)—You can send alert data to third-party systems (such as IBM QRadar and Microsoft Sentinel) using syslog forwarding.
* Integrate with partner systems—Partner integrations are typically installed on customer systems or installed within vendor solutions through a third-party marketplace.

  | Partner Integration                                 | Description                                                                                                                                                                                                      | More Information                                                                                                                                                                                                                                                                                                                                                                                                                  |
  | --------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
  | Jira Server                                         | Automatically forward new alerts along with guidance and related context from Expander to Jira as new tasks.                                                                                                     | Contact your Customer Success Manager for configuration details.                                                                                                                                                                                                                                                                                                                                                                  |
  | QRadar                                              | Automatically forward Xpanse- discovered risks to QRadar to support alert event creation, asset event creation, offense population, and asset details display.                                                   | [Cortex Xpanse for QRadar](https://exchange.xforce.ibmcloud.com/hub/extension/a00fc306563d8180bcd2da9a983c6752)                                                                                                                                                                                                                                                                                                                   |
  | Qualys VM                                           | Automatically import Xpanse assets as new asset groups in Qualys VMDR for scanning.                                                                                                                              | Contact your Customer Success Manager for configuration details.                                                                                                                                                                                                                                                                                                                                                                  |
  | Rapid7 InsightVM                                    | Automatically import assets detected by Cortex Xpanse into Rapid7 InsightVM console to be used as scan targets.                                                                                                  | [Cortex Xpanse Integration: InsightVM Documentation and User Guide](https://technologypartners.paloaltonetworks.com/English/integration/Cortex-XPANSE-Rapid7-InsightVM)                                                                                                                                                                                                                                                           |
  | ServiceNow Configuration Compliance (CC)            | Ingest security test results (i.e. alerts) into the ServiceNow CC module, Including checking for impacted assets in CMDB.                                                                                        | [Cortex Xpanse ServiceNow Configuration Compliance Documentation and User Guide v2.0.0](https://store.servicenow.com/sn_appstore_store.do#!/store/application/83e2e9131bd70510d5954225bd4bcbdb/2.0.1?referer=%2Fstore%2Fsearch%3Flistingtype%3Dallintegrations%253Bancillary_app%253Bcertified_apps%253Bcontent%253Bindustry_solution%253Boem%253Butility%253Btemplate%253Bgenerative_ai%253Bsnow_solution%26q%3Dexpander\&sl=sh) |
  | ServiceNow Configuration Management Database (CMDB) | Automatically ingest assets discovered by Xpanse to the ServiceNow CMDB. These assets are run through the CMDB’s correlation logic to merge with existing assets.                                                | [Cortex Xpanse Service Graph Connector for Xpanse (SGCX) (v2.0.0) Documentation and User Guide](https://technologypartners.paloaltonetworks.com/English/integration/Cortex-Xpanse-Service-Graph-Connector-CMDB)                                                                                                                                                                                                                   |
  | Splunk TA v5.0.0                                    | <p>Forward Xpanse-discovered assets, services, and risks for management, visualization, correlation, and alerting within Splunk.</p><p>The Cortex Xpanse TA can be installed through the Splunk Marketplace.</p> | [Cortex Xpanse Integration Guide for Splunk TA v5.x.x](https://technologypartners.paloaltonetworks.com/English/integration/Cortex-XPANSE-Splunk-TA)                                                                                                                                                                                                                                                                               |
  | Tenable.io                                          | Forward relevant assets that Xpanse discovers to Tenable.io for more detailed assessment and central vulnerability tracking.                                                                                     | <p><a href="https://technologypartners.paloaltonetworks.com/English/integration/Cortex-XPANSE-Tenable-io">Cortex Xpanse Integration: Tenable.io</a></p><p>Contact your Customer Success Manager to proceed with integration configuration.</p>                                                                                                                                                                                    |
  | Venafi TPP Integration                              | Correlate certificates in the Expander inventory with those in Venafi TTP to help customers understand gaps in their certificate management.                                                                     | Contact your Customer Success Manager for configuration details.                                                                                                                                                                                                                                                                                                                                                                  |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xpanse/integrations.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
