0
3.2.4
Australia, Zurich, Yokohama
Integration
The Palo Alto Networks XSIAM SIEM ingestion integration allows you to automatically retrieve incidents from XSIAM, convert them into security incidents, and enable automated response actions.
Automated Detection & Incident Creation :
Detect Palo Alto Networks XSIAM SIEM incidents that qualify as security incidents and automatically create security incidents in SIR.
Field Mapping for Seamless Data Flow :
Map XSIAM SIEM alert and entity fields to SIR security incident fields for consistent and structured incident handling.
Advanced Filtering Capabilities :
Filter incoming XSIAM SIEM incidents based on defined criteria to ingest only relevant security incidents.
Smart Incident Aggregation :
Group similar XSIAM SIEM incidents under existing open security incidents to avoid duplication and reduce operational overhead.
Scheduled Alert Ingestion :
Ingest XSIAM SIEM incidents into SIR at scheduled intervals to ensure regular and timely updates.
Comment Synchronization :
Synchronize comments between XSIAM SIEM incidents and SIR worknotes to maintain complete visibility and effective communication within incident workflows.
New:
- Admins can now configure bidirectional field sync between SIR and Palo Alto XSIAM. Up to 32 identified fields in PA XSIAM can be mapped and automatically synchronized with SIR on incident updates. A new UI enables admins to define field mappings, apply transformations, and manage which fields are included. A top-level option allows enabling or disabling automatic sync, and admins can fetch record details for specific incidents or cases to assist with mapping.
- A new interface supports SIR to XSIAM field mapping with transformation options. The mapping screen uses a four-column layout for target fields, source fields, transformation selection, and removal controls. Admins can reference either live SIR data or sample data when configuring mappings.
Not applicable for this application version.
To install the integration, perform the following steps:
- Install the com.glide.hub.integration.runtime, com.glide.hub.action_step.rest plugins first. If the necessary privileges are unavailable, raise a support ticket to install these plugins.
- After installing the plugins, install the Security Incident Response Dependency plugin (com.snc.si_dep).
- Install the Security Incident Response plugin