<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Prisma Cloud Compute Sentinel Integration with Azure Functions in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/prisma-cloud-compute-sentinel-integration-with-azure-functions/m-p/464714#M450</link>
    <description>&lt;P&gt;&lt;SPAN&gt;I am looking to integrate Prisma Cloud Compute (Twistlock) container runtime alerts with Azure Sentinel via Azure Functions instead of Logic Apps. Has anyone tested this and if so, could you provide the steps on how this can be done?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;LI-PRODUCT title="Prisma Cloud" id="Prisma_Cloud"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Aug 2022 18:42:10 GMT</pubDate>
    <dc:creator>ThilinaSenevirathna</dc:creator>
    <dc:date>2022-08-03T18:42:10Z</dc:date>
    <item>
      <title>Prisma Cloud Compute Sentinel Integration with Azure Functions</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/prisma-cloud-compute-sentinel-integration-with-azure-functions/m-p/464714#M450</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I am looking to integrate Prisma Cloud Compute (Twistlock) container runtime alerts with Azure Sentinel via Azure Functions instead of Logic Apps. Has anyone tested this and if so, could you provide the steps on how this can be done?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;LI-PRODUCT title="Prisma Cloud" id="Prisma_Cloud"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 18:42:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/prisma-cloud-compute-sentinel-integration-with-azure-functions/m-p/464714#M450</guid>
      <dc:creator>ThilinaSenevirathna</dc:creator>
      <dc:date>2022-08-03T18:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Cloud Compute Sentinel Integration with Azure Functions</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/prisma-cloud-compute-sentinel-integration-with-azure-functions/m-p/510082#M539</link>
      <description>&lt;P&gt;Greetings ThilinaSenevirathna,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope that this message finds you well! In trying to help you with your use case I have gotten some insight with the help of a colleague as to a process flow of what you are looking for:&lt;BR /&gt;&lt;SPAN&gt;Step 1: Set up webhook alert to Azure API Management with alert payload specified to runtime alerts &lt;BR /&gt;Step 2: Configure Azure Functions behind Azure API Management service to ingest webhook payload from the Prisma console &lt;BR /&gt;Step 3: Use Azure Functions to parse out relevant data to be ingested in the Microsoft Sentinel service &lt;BR /&gt;Step 4: Verify that Microsoft Sentinel has ingested the relevant data from the original Prisma webhook alert payload&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;The core of what will solve for this use case is parsing out the relevant JSON fields from the webhook alert payload that is ingested from Prisma cloud into your Azure environment through the coded parsing logic in you Azure Function. Here is some documentation from the Azure website that may be helpful in setting up an API endpoint for your Azure Function via the API Management service:&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-us/azure/api-management/import-function-app-as-api" target="_blank"&gt;https://docs.microsoft.com/en-us/azure/api-management/import-function-app-as-api&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;In addition to this I was able to find this document to help with the configuration of Microsoft Sentinel being able to ingest data from an Azure Function:&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-us/azure/sentinel/connect-azure-functions-template?tabs=ARM" target="_blank"&gt;https://docs.microsoft.com/en-us/azure/sentinel/connect-azure-functions-template?tabs=ARM&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Even though this document is centered around connecting to an application REST-API endpoint to ingest the logs as the payload via an Azure Function into Microsoft Sentinel, the logical basis of this may be useful in setting up the webhook integration with the runtime alert as the payload.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards,&lt;/P&gt;
&lt;P&gt;Avery&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 20:05:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/prisma-cloud-compute-sentinel-integration-with-azure-functions/m-p/510082#M539</guid>
      <dc:creator>AKing9</dc:creator>
      <dc:date>2022-07-27T20:05:25Z</dc:date>
    </item>
  </channel>
</rss>

