<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XSOAR Sessions and Submissions option in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-sessions-and-submissions-option/m-p/521860#M1429</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No, XSOAR does not process or enrich this info, you will only be able to view and query the sessions data generated from your PAN firewall and listed other products.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 21 Nov 2022 12:24:02 GMT</pubDate>
    <dc:creator>sramesh-7</dc:creator>
    <dc:date>2022-11-21T12:24:02Z</dc:date>
    <item>
      <title>XSOAR Sessions and Submissions option</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-sessions-and-submissions-option/m-p/519675#M1357</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I came across this documentation regarding XSOAR&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xsoar/6-9/cortex-xsoar-threat-intel-management-guide/unit42-intel/unit42-sessions-and-submissions" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xsoar/6-9/cortex-xsoar-threat-intel-management-guide/unit42-intel/unit42-sessions-and-submissions&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class=""&gt;&lt;EM&gt;&lt;EM&gt;The&amp;nbsp;&lt;SPAN&gt;Sessions &amp;amp; Submissions&amp;nbsp;tab enables you to use your sessions and submissions data for investigation and analysis. Sessions and submissions data is available for customers with a TIM license and at least one of the following products:&lt;/SPAN&gt;&lt;/EM&gt;&lt;/EM&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;UL&gt;
&lt;LI class=""&gt;
&lt;DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV&gt;&lt;EM&gt;Palo Alto Networks Firewall&lt;/EM&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class=""&gt;
&lt;DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV&gt;&lt;EM&gt;WildFire&lt;/EM&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class=""&gt;
&lt;DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV&gt;&lt;EM&gt;Cortex XDR&lt;/EM&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class=""&gt;
&lt;DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV&gt;&lt;EM&gt;Prisma SaaS&lt;/EM&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class=""&gt;
&lt;DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV&gt;&lt;EM&gt;&lt;EM&gt;Prisma Access&lt;/EM&gt;&lt;/EM&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;DIV class=""&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;EM&gt;&lt;EM&gt;Sessions&amp;nbsp;&lt;EM style="font-family: inherit;"&gt;refers to firewall sessions, while&amp;nbsp;&lt;EM&gt;Submissions&amp;nbsp;&lt;EM style="font-family: inherit;"&gt;&amp;nbsp;refers to logs of samples reported to Wildfire from other Palo Alto Networks products. Sessions data shows you connections from one endpoint to another, and submissions data shows you if a file was found on a specific endpoint.&lt;/EM&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/EM&gt;
&lt;DIV&gt;&amp;nbsp;
&lt;DIV&gt;We are using PaloAlto Firewall. Does this mean I send traffic sessions from the PaloAlto firewall to XSOAR and it checks the IPs (realtime or periodically) e.g. source or destination is in the indicator list present in Threat Intel section on XSOAR?
&lt;DIV&gt;How does this integration work?
&lt;DIV&gt;&amp;nbsp;
&lt;DIV&gt;Thanks&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class=""&gt;
&lt;DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class=""&gt;
&lt;DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class=""&gt;
&lt;DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class=""&gt;
&lt;DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 31 Oct 2022 14:17:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-sessions-and-submissions-option/m-p/519675#M1357</guid>
      <dc:creator>pottapitot</dc:creator>
      <dc:date>2022-10-31T14:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR Sessions and Submissions option</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-sessions-and-submissions-option/m-p/521860#M1429</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No, XSOAR does not process or enrich this info, you will only be able to view and query the sessions data generated from your PAN firewall and listed other products.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2022 12:24:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-sessions-and-submissions-option/m-p/521860#M1429</guid>
      <dc:creator>sramesh-7</dc:creator>
      <dc:date>2022-11-21T12:24:02Z</dc:date>
    </item>
  </channel>
</rss>

