Skip to main content

Cortex XDR

Endpoint Protection

The Cortex XDR Connector fetches and synchronizes extended detection and response (XDR) security data from Palo Alto Networks Cortex XDR. It connects to the Cortex XDR public API using API Key authentication (standard or advanced) and maps retrieved objects to the Brinqa Data Model.

Data retrieved from Cortex XDR Connector

Connector ObjectRequiredMaps to Data Model
AssetYesAsset
AlertYesAlert
Alert DefinitionYesAlert Definition
EndpointYesHost
IncidentYesIncident
Incident DefinitionYesIncident Definition
SoftwareYesPackage
Installed SoftwareYesInstalled Package
ViolationYesViolation
Violation DefinitionYesViolation Definition
VulnerabilityYesVulnerability
Vulnerability DefinitionYesVulnerability Definition

Model relationships

note

For detailed steps on how to view the data retrieved from Cortex XDR Connector in the Brinqa Platform, see How to view your data.