<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prisma Cloud Runtime and Cloud Security Integration to Microsoft Sentinel in Cortex Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-cloud-discussions/prisma-cloud-runtime-and-cloud-security-integration-to-microsoft/m-p/1241376#M1541</link>
    <description>&lt;P&gt;I have set up the new Sentinel CCF connector from Sentinel for Prisma CSPM and although I am getting the audit logs , this can be seen in the data type , however for the alerts data type it is not receiving anything. In the past the old Sentinel using Function App had the webhook configuration and alerts use to come fine. But since we are now using the new CCF connector does it still require the logic app and webhook to receive the alerts in the alert table or there is a new process to get the alert directly from the Prisma Cloud and if yes , could you help me with the config please?&lt;/P&gt;
&lt;P&gt;Paul&lt;/P&gt;</description>
    <pubDate>Thu, 06 Nov 2025 17:22:43 GMT</pubDate>
    <dc:creator>giorgimax</dc:creator>
    <dc:date>2025-11-06T17:22:43Z</dc:date>
    <item>
      <title>Prisma Cloud Runtime and Cloud Security Integration to Microsoft Sentinel</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-cloud-discussions/prisma-cloud-runtime-and-cloud-security-integration-to-microsoft/m-p/1232830#M1498</link>
      <description>&lt;P&gt;I am trying to integrate Palo Prisma Runtime Security and Cloud Security with all the alerts to Microsoft Sentinel&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try1:&amp;nbsp;Palo Alto Prisma Cloud CWPP (using REST API) - This is the data connector available from Microsoft, status is Connected but no data received although there are new alerts in Palo Prisma. Can advise what configuration is required in Palo Prisma i this is the recommended method.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try2:&amp;nbsp;Palo Prisma Manage Alert providers, Profile, Provider option only has Webhook&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try3: Palo Prisma Manage / Integration and Notification has Integration option to Azure Service Bus Queue and Webhook.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In Palo Prisma Cloud, I have runtime security, cloud security, IaC Security, CICD security modules turned on. Can help to advise what method to choose to ingest all security alerts to Microsoft Sentinel? Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2025 03:29:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-cloud-discussions/prisma-cloud-runtime-and-cloud-security-integration-to-microsoft/m-p/1232830#M1498</guid>
      <dc:creator>balaji31d</dc:creator>
      <dc:date>2025-06-30T03:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Cloud Runtime and Cloud Security Integration to Microsoft Sentinel</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-cloud-discussions/prisma-cloud-runtime-and-cloud-security-integration-to-microsoft/m-p/1232889#M1499</link>
      <description>&lt;P&gt;Hello!&lt;BR /&gt;You are correct.&amp;nbsp; There is technically not a direct integration with Azure Sentinel.&amp;nbsp; Your best best is to start with Cloud Security, or CSPM and use the webhook for integration.&amp;nbsp; The same goes, secondly, with Compute Security.&amp;nbsp; You should create the web hook integration for CSPM, then monitor for a bit to see that you are getting the alerts you want, and adjust as needed.&amp;nbsp; Once you're satisfied, you should then integrate with Compute, again, using the Webhook method.&amp;nbsp; Remember that, once you perform the integration in the Compute module, you will see results in the form of events, vulnerabilites, etc within the Compute module.&amp;nbsp; While some of these events will get "transmitted" to CSPM, keep in mind that a lot of them will not.&amp;nbsp; You will need to adjust your Alert Profile in the Compute module accordingly.&amp;nbsp; Hope this helps.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2025 13:26:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-cloud-discussions/prisma-cloud-runtime-and-cloud-security-integration-to-microsoft/m-p/1232889#M1499</guid>
      <dc:creator>JCalloway1</dc:creator>
      <dc:date>2025-06-30T13:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Cloud Runtime and Cloud Security Integration to Microsoft Sentinel</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-cloud-discussions/prisma-cloud-runtime-and-cloud-security-integration-to-microsoft/m-p/1232908#M1500</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;
&lt;P&gt;The flow is as follows:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Step 1: Set up webhook alert to Azure API Management with alert payload specified to runtime alerts&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Step 2: Configure Azure Functions behind Azure API Management service to ingest webhook payload from the Prisma console&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Step 3: Use Azure Functions to parse out relevant data to be ingested in the Microsoft Sentinel service&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Step 4: Verify that Microsoft Sentinel has ingested the relevant data from the original Prisma webhook alert payload&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2025 18:50:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-cloud-discussions/prisma-cloud-runtime-and-cloud-security-integration-to-microsoft/m-p/1232908#M1500</guid>
      <dc:creator>LMegrelis</dc:creator>
      <dc:date>2025-06-30T18:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Cloud Runtime and Cloud Security Integration to Microsoft Sentinel</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-cloud-discussions/prisma-cloud-runtime-and-cloud-security-integration-to-microsoft/m-p/1241376#M1541</link>
      <description>&lt;P&gt;I have set up the new Sentinel CCF connector from Sentinel for Prisma CSPM and although I am getting the audit logs , this can be seen in the data type , however for the alerts data type it is not receiving anything. In the past the old Sentinel using Function App had the webhook configuration and alerts use to come fine. But since we are now using the new CCF connector does it still require the logic app and webhook to receive the alerts in the alert table or there is a new process to get the alert directly from the Prisma Cloud and if yes , could you help me with the config please?&lt;/P&gt;
&lt;P&gt;Paul&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 17:22:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-cloud-discussions/prisma-cloud-runtime-and-cloud-security-integration-to-microsoft/m-p/1241376#M1541</guid>
      <dc:creator>giorgimax</dc:creator>
      <dc:date>2025-11-06T17:22:43Z</dc:date>
    </item>
  </channel>
</rss>

