Skip to main content

Prisma SASE by Palo Alto Networks

Download With Dependencies

Integrate with Palo Alto Networks Prisma SASE to query activity and take actions.

## Prisma Access Content Pack

This content pack enables XSOAR to integrate with Palo Alto Networks Prisma Access. It includes 2 integrations.

### Prisma Access Egress IP feed

Dynamically retrieve and allow IPs Prisma Access uses to egress traffic to the internet and SaaS apps.

This integration can be used as a TIM feed to fetch indicators, or if a playbook starts from a non-indicator trigger it can use the command to get the IPs.

### Prisma Access

Integrate with Prisma Access to query the status of the service and take actions.

The integration includes commands to:

  • Force logout a specific user from Prisma Access
  • List currently active users
  • Run a Prisma Access query (e.g. getGPaaSLast90DaysUniqueUsers)
  • Run a custom CLI command

The integration uses both the Panorama XML API and SSH into the PAN-OS CLI. SSH is based on the netmiko library and will use the netmiko docker image.

### Prisma SASE

Integrate with Prisma SASE to view or make changes to Prisma Access configurations.

The integration includes commands to:

  • Create, update, delete and get security rules.
  • Create, update, delete and get address objects.
  • Create, update, delete and get external dynamic lists.
  • Create, update, delete and get custom URL categories.
  • Create, update, delete and get tags.
  • Create, update, delete and get address groups.
  • Get configuration jobs.
  • Push all configuration jobs.

The integration uses the Prisma SASE Multi-tenant API documented here: Prisma SASE API.

Pack Contributors:

  • JD Plant

Contributions are welcome and appreciated. For more info, visit our Contribution Guide.




Cortex XSOARCortex XSIAM


CertificationRead more
Supported ByCortex
CreatedJuly 22, 2020
Last ReleaseMarch 22, 2023

Content packs are licensed by the Publisher identified above and subject to the Publisher’s own licensing terms. Palo Alto Networks is not liable for and does not warrant or support any content pack produced by a third-party Publisher, whether or not such packs are designated as “Palo Alto Networks-certified” or otherwise. For more information, see the Marketplace documentation.