Palo Alto XDR API

Palo Alto XDR API

API Documentation: https://docs-cortex.paloaltonetworks.com/p/XDR

API creation and configuration

  1. To generate a new api key or to use an existing one, go to Configuration ⇒ Integrations ⇒ API Keys.

  2. Set the Security Level to “Standard” and Role to “Investigator” and generate a new key.

  3. Once generated save the key Secret.

  4. Copy the API URL.

5.Copy all the info above in the RedCarbon ingestions page

Mapping

Severity

OriginalRC SeverityRebased
low105
medium4020
high7035
critical9045
DEFAULT4020