Skip to main content

PAN-OS to Cortex Data Lake Monitoring - Cron Job

Supported versions

Supported Cortex XSOAR versions: 6.0.0 and later.

This playbook verifies that your FWs sent logs to the Cortex Data Lake in the last 12 hours. An email notification will be sent if it's not the case. This playbook is designed to run as a job.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

  • Mail Sender (New)

Scripts#

  • FW-to-CDL-monitoring
  • IncreaseIncidentSeverity

Commands#

  • createNewIncident
  • send-mail
  • closeInvestigation
  • setIncident

Playbook Inputs#


NameDescriptionDefault ValueRequired
fw_serialsA comma-separated list of FW serials to monitor. Only applicable if no Panorama integration specified.${incident.fwserials}Optional
panorama_integrationName of the Panorama integration to gather the list of monitored FWs. If none specified, the list of serials must be provided manually as "fw_serials".${incident.panoramaintegration}Optional
email_notificationEmail address to send a notification to in case detected problem.${incident.email}Optional

Playbook Outputs#


There are no outputs for this playbook.

Playbook Image#


![CDL FW Monitoring - cron job](Insert the link to your image here)