Azure-Sentinel/Playbooks/Ingest-Prisma
dicolanl 525d001024 Updating Deploy buttons and links part 1 2021-06-16 00:25:40 +00:00
..
azuredeploy.json update params 2020-05-15 12:47:15 -04:00
readme.md Updating Deploy buttons and links part 1 2021-06-16 00:25:40 +00:00

readme.md

Ingest-Prisma

author: Nathan Swift

This Logic App connector will act as a Webhook listener, Prisma can then send an array of events to it and it will send the events to Azure Sentinel - Prisma_CL

When setting up Prisma you will see the field "Auth Toekn", this field is not required to connect Prisma. Only copy the complete HTTP Listener URL into the Prisma Webhook URL field.

Once the Prisma Webhook Listener has been configure, in the Alert/Alert Rules section of Prisma, you will need to enable the Webhook to receive the new alerts.

Deploy to Azure Deploy to Azure Gov

Additional Post Install Notes:

Prisma configuration can be found: https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/configure-external-integrations-on-prisma-cloud/integrate-prisma-cloud-with-webhooks.html Prisma webhook implementation details can be found here: https://techcommunity.microsoft.com/t5/azure-sentinel/connecting-prisma-to-sentinel/m-p/1408693