Palo Alto Networks Cortex XDR
  • 01 Feb 2023
  • 1 Minute to read
  • Dark
    Light

Palo Alto Networks Cortex XDR

  • Dark
    Light

Article Summary

The Cortex XDR integration enables you to scan endpoints, upload IOCs, manage incidents, and validate API keys as part of Torq workflows.

Create an XDR API key

When you create an XDR API key, you'll need to copy and save several items that you'll need later for configuring an XDR integration in Torq.

  • API key
  • API key ID
  • Cortex XDR URL
  1. In your XDR portal, go to Settings > Configurations.Screenshot of accessing the settings configuration section in Cortex XDR.
  2. Expand the configuration panel, go to Integrations > API Keys, and click the + New Key button.Screenshot of navigating to the page to create a new API key in Cortex XDR.
  3. Configure the API key and click Save. Make sure you copy the API key and save it.
    1. Security Level: Standard
    2. Role: All Torq steps can be used with the Investigation Admin role.
    3. Comment: a short description of what this key will be used for.Screenshot of generating a new API key in Cortex XDR.
  4. In the table, locate the API key you created and make note of the ID.
  5. In the top-right corner, click Copy URL.

Create a Cortex XDR integration in Torq

  1. Go to the Integrations page, locate the Cortex XDR card, and click Add.
  2. Fill in the fields with the values you copied earlier.
    1. Integration name
    2. Cortex XDR API Key
    3. Cortex XDR API ID
    4. Cortex XDR Base URL (https://api-fqdn) for example: https://api-<company-name>.xdr.us.paloaltonetworks.com

Screenshot of creating a Cortex XDR integration in Torq.



Was this article helpful?

Changing your password will log you out immediately. Use the new password to log back in.
First name must have atleast 2 characters. Numbers and special characters are not allowed.
Last name must have atleast 1 characters. Numbers and special characters are not allowed.
Enter a valid email
Enter a valid password
Your profile has been successfully updated.