Palo Alto XDR API

Palo Alto XDR API

This guide explains how to integrate Palo Alto Cortex XDR with RedCarbon.

Overview

The Palo Alto XDR integration allows RedCarbon to ingest incidents and alerts from the Cortex XDR platform via the public API.

Configuration

To configure the integration, you need to generate an API Key in the Cortex XDR management console.

Step 1: Generate an API Key

  1. Log in to the Cortex XDR management console.
  2. Navigate to Configuration > Integrations > API Keys.
  3. Click Generate New Key.

Step 2: Set Permissions

Configure the API key with the following settings:

  • Security Level: Standard
  • Role: Investigator (or a custom role with Incident Management: View permissions)

Create API Key

Step 3: Copy Credentials

Once the key is generated, copy the following information (it will not be shown again):

  • API Key ID (this is your API Key)
  • API Key (this is your Secret)
  • API URL (the base URL for your Cortex instance)

API Secret API URL

Step 4: Configure RedCarbon

  1. Log in to the RedCarbon Dashboard.
  2. Navigate to the customer's Integrations page.
  3. Select Palo Alto Cortex XDR.
  4. Paste the API Key ID, API Key (Secret), and API URL.
  5. Click Save and then Test.

Configure RedCarbon

Severity Mapping

Original SeverityRedCarbon Score
Low10
Medium40
High70
Critical90