Palo Alto Networks Threat Vault v2 Feed
ThreatVault Feed Pack.#
This Integration is part of theSupported versions
Supported Cortex XSOAR versions: 6.10.0 and later.
#
Threat Vault FeedThis integration uses the Threat Vault API to fetch predefined EDL (External Dynamic List) lists.
#
Configuration- Navigate to Settings > Integrations
- Search for PANW Threat Vault Feed.
- Click Add instance to create and configure a new integration instance.
#
Required Parameters- API Key: Your PANW Threat Vault API key.
- Base URL: The base URL for the PANW Threat Vault API.
- Fetch Interval: How often to fetch new data from the feed (in minutes).
#
UsageOnce configured, the integration will automatically fetch the specified EDL lists at the defined interval. The fetched data can be used in playbooks, indicators, and other Cortex XSOAR features.
#
Commands- threatvault-get-indicators: Manually fetch indicators from the PANW Threat Vault feed.
#
TroubleshootingIf you encounter any issues:
- Verify your API key is correct and has the necessary permissions.
- Check the integration's logs for any error messages.
- Ensure your network allows outbound connections to the PANW Threat Vault API endpoint.
For more information on using this integration, refer to the PANW Threat Vault documentation.