PaloAltoXDR

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


  1. Overview 1. Prerequisites 1. Deploy Palo Alot XDR playbook 1. Deployment Instructions 1. Post-Deployment Instructions 1. References
Attribute Value
Type Playbook
Solution Palo Alto - XDR (Cortex)
Source View on GitHub

⚠️ Not listed in Solution JSON: This content item was discovered by scanning the solution folder but is not included in the official Solution JSON file. It may be a legacy item, under development, or excluded from the official solution package.

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
CommonSecurityLog

Logic App Connectors

This playbook uses 5 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuremonitorlogs Managed 1 2
azuresentinel Managed 1 4
teams Managed 1 2
virustotal Managed 1 0
virustotal_1 Managed 0 1
Action parameters (URLs, paths, function IDs)

azuremonitorlogs (Managed)

Action Method Endpoint Other
Run_query_and_list_results post /queryData
Run_query_and_list_results_2 post /queryData

azuresentinel (Managed)

Action Method Endpoint Other
Entities_-_Get_Accounts post /entities/account
Entities_-_Get_Hosts post /entities/host
Entities_-_Get_IPs post /entities/ip
Add_comment_to_incident_(V3) post /Incidents/Comment

teams (Managed)

Action Method Endpoint Other
Post_message_in_a_chat_or_channel post /beta/teams/conversation/message/poster/Flow bot/location/@{encodeURIComponent('Channel')}
Post_message_in_a_chat_or_channel_2 post /beta/teams/conversation/message/poster/Flow bot/location/@{encodeURIComponent('Channel')}

virustotal_1 (Managed)

Action Method Endpoint Other
Get_an_IP_report get /api/v3/ip_addresses/connectorV2/@{encodeURIComponent(items('For_each_IP_in_incident')?['Address'])}

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Playbooks · Back to Palo Alto - XDR (Cortex)