<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to Query Prisma Cloud Compute for Alerts? I am not interested in Prisma Cloud Alerts. in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-it-possible-to-query-prisma-cloud-compute-for-alerts-i-am-not/m-p/519921#M773</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/183942"&gt;@CloudEngineer&lt;/a&gt;&amp;nbsp;&amp;nbsp; dude, you were correct the whole time.&amp;nbsp; &lt;SPAN&gt;The Prisma Cloud Compute SecurityHub Alert Provider works perfectly fine.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I got misinformation from support case &lt;SPAN&gt;02326773&lt;/SPAN&gt;.&amp;nbsp; Here is how I determined that the Registry Scanned CVEs and Compliance vulnerabilities were generating Alerts and propogating them to AWS SecurityHub/Findings Console.&amp;nbsp; I entered this Filter criteria and then I could see the CVE-Alerts.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TommyHunt_0-1667331233072.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/45064iB00B6368FEE1FB21/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="TommyHunt_0-1667331233072.png" alt="TommyHunt_0-1667331233072.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I still have NO explanation for those errors that I cited at the beginning of this&lt;/P&gt;</description>
    <pubDate>Tue, 01 Nov 2022 19:34:18 GMT</pubDate>
    <dc:creator>TommyHunt</dc:creator>
    <dc:date>2022-11-01T19:34:18Z</dc:date>
    <item>
      <title>Is it possible to Query Prisma Cloud Compute for Alerts? I am not interested in Prisma Cloud Alerts.</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-it-possible-to-query-prisma-cloud-compute-for-alerts-i-am-not/m-p/517037#M720</link>
      <description>&lt;P&gt;Is it possible to Query Prisma Cloud Compute for Alerts? I am not interested in Prisma Cloud Alerts.&lt;/P&gt;
&lt;P&gt;If yes then, which API call?&lt;/P&gt;
&lt;P&gt;I can't find it here... &lt;A href="https://prisma.pan.dev/api/cloud/cwpp/" target="_blank"&gt;https://prisma.pan.dev/api/cloud/cwpp/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 21:14:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-it-possible-to-query-prisma-cloud-compute-for-alerts-i-am-not/m-p/517037#M720</guid>
      <dc:creator>TommyHunt</dc:creator>
      <dc:date>2022-10-06T21:14:58Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to Query Prisma Cloud Compute for Alerts? I am not interested in Prisma Cloud Alerts.</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-it-possible-to-query-prisma-cloud-compute-for-alerts-i-am-not/m-p/517297#M722</link>
      <description>&lt;P class=""&gt;Hello, Compute doesn't have an API endpoint for alerts.&lt;/P&gt;
&lt;P class=""&gt;Compute is Stateless, so it does not have a list of active alerts that can be pulled down. In compute, alerts get pushed to integrations that are set up. We&amp;nbsp;have alert profiles inside which we have alert providers, and we can configure the profiles to send a bunch of alert information related to compliance, vulnerabilities, WAAS, etc., to these alert providers.&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;We have separate API endpoints for vulnerabilities, compliance, WAAS, runtime, images, etc., that you can query.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2022 13:09:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-it-possible-to-query-prisma-cloud-compute-for-alerts-i-am-not/m-p/517297#M722</guid>
      <dc:creator>bpachauli</dc:creator>
      <dc:date>2022-10-10T13:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to Query Prisma Cloud Compute for Alerts? I am not interested in Prisma Cloud Alerts.</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-it-possible-to-query-prisma-cloud-compute-for-alerts-i-am-not/m-p/517457#M723</link>
      <description>&lt;P&gt;Thanks for your confirmation; ya know what is sad is that there does exist an Alert Provider for AWS SecurityHub but it does not forward/publish Alerts of CVEs as reported by scanners.&amp;nbsp; Webhook Alert Provider is not an option since we want to minimize attack surface from the public internet.&amp;nbsp; So, I can query the registries API for the vulnerabilities.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 13:46:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-it-possible-to-query-prisma-cloud-compute-for-alerts-i-am-not/m-p/517457#M723</guid>
      <dc:creator>TommyHunt</dc:creator>
      <dc:date>2022-10-11T13:46:25Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to Query Prisma Cloud Compute for Alerts? I am not interested in Prisma Cloud Alerts.</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-it-possible-to-query-prisma-cloud-compute-for-alerts-i-am-not/m-p/517494#M726</link>
      <description>&lt;P&gt;Hi Tommy,&lt;/P&gt;
&lt;P&gt;I'd like to know what alerts you are looking for? While its true that there isn't a single consolidated alerts API endpoint for Compute, you can still use the relevant individual APIs to gather what you want which would ultimately match your configured rules and ultimately trigger an alert to be sent to a desired integration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for the AWS SecurityHub integration, could you please clarify what you mean "does not publish Alerts of CVEs as reported by scanners?" It will should forward your requested information as I understand it. I have seen the findings sent to SecurityHub so I'd be very interested in understanding more.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CloudEngineer_0-1665511251908.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44580iA3F42386BE3A507F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CloudEngineer_0-1665511251908.png" alt="CloudEngineer_0-1665511251908.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 18:02:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-it-possible-to-query-prisma-cloud-compute-for-alerts-i-am-not/m-p/517494#M726</guid>
      <dc:creator>CloudEngineer</dc:creator>
      <dc:date>2022-10-11T18:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to Query Prisma Cloud Compute for Alerts? I am not interested in Prisma Cloud Alerts.</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-it-possible-to-query-prisma-cloud-compute-for-alerts-i-am-not/m-p/517670#M729</link>
      <description>&lt;P&gt;Hi Brandon,&lt;/P&gt;
&lt;P&gt;In support CASE 02326773,&amp;nbsp; I asked...&lt;/P&gt;
&lt;P&gt;"However, I cannot find the Alerts that should have been generated by Prisma CloudCompute Console/Defend/Vulnerabilities/Images/CI/Rules...&lt;/P&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;P&gt;It appears that the CVEs did trigger Alert creation because now the Alert provider, AWSSecurityHub, is reporting this error...&lt;/P&gt;
&lt;P&gt;failed to add findings: [{ ErrorCode: "InvalidInput", ErrorMessage: "Finding does not adhere to Amazon Finding Format. data.Resources[0].Id should NOT be shorter than 1 characters, data.Resources[0].Id should NOT be shorter than 12 characters, data.Resources[0].Id should match pattern \"^arn:(aws|aws-cn|aws-us-gov):[A-Za-z0-9\\-]{1,63}:[a-z0-9\\-]*:([0-9]{12})?:.+$\", data.Resources[0].Id should match some schema in anyOf.", Id: "us-west-2/twistlock/vulnerabilities/" }]...&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. What the heck is wrong with the integration to Alert provider, AWSSecurityHub? remember that Test Alerts and runtime Alerts are sent successfully."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Support's response is this...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"Hello Tommy,&lt;BR /&gt;&lt;BR /&gt;Thank you for allowing me time to review the case.&lt;BR /&gt;&lt;BR /&gt;Based on our documentation, we have an existing issue, PCSUP 9241, and it is expected to be fixed in Lagrange release.&lt;BR /&gt;&lt;BR /&gt;Here is the link to the documentation for known issue in Prisma Cloud Compute:&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-release-notes/prisma-cloud-compute-release-information/prisma-cloud-compute-known-issues" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-release-notes/prisma-cloud-compute-release-information/prisma-cloud-compute-known-issues&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Please let me know if you have any further questions."&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you saw Alerts from twistlock scans of registries or images in the pipeline then can you show that to Umer Sheikh cause he thinks that its a known issue and although AlertProvider, AWSSecurityHub, is working,&amp;nbsp; we see no Alerts in SecurityHub related to registry scans with reported CVEs.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 18:46:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-it-possible-to-query-prisma-cloud-compute-for-alerts-i-am-not/m-p/517670#M729</guid>
      <dc:creator>TommyHunt</dc:creator>
      <dc:date>2022-10-12T18:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to Query Prisma Cloud Compute for Alerts? I am not interested in Prisma Cloud Alerts.</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-it-possible-to-query-prisma-cloud-compute-for-alerts-i-am-not/m-p/517686#M730</link>
      <description>&lt;P&gt;Hi Tommy,&lt;/P&gt;
&lt;P&gt;I've read through the PCSUP and I can summarize that if you are trying to send Compute's findings to an AWS Gov account then we are expecting a fix in the next major release (Lagrange) which may resolve the errors observed from AWS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are working on integrating with Security Hub in a typical commercial account then we can probably get this going with some additional configuration checks and testing since I have seen this integration work successfully.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, I noticed that your request mentioned alerts generated by CI rules. At this time, the Security Hub integration doesn't have an option to send CI alerts to Security Hub. Please have a look at this screenshot where I've shown that only Deployed and Registry scan results are available for Vulnerability Management:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2022-10-12 at 4.02.14 PM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44646i02EBA6676DE988F8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2022-10-12 at 4.02.14 PM.png" alt="Screen Shot 2022-10-12 at 4.02.14 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You'll see within "select rules to alert on" that only your Deployed / Registry rules are available to select.&lt;/P&gt;
&lt;P&gt;We also support sending findings for Runtime, Access, WAAS and CNNF.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Lastly, can you please confirm if you are using the self-hosted Compute console or Prisma Cloud Enterprise Edition (SaaS) ? I know you mentioned "Prisma Cloud Compute" which is generally our identification of the self-hosted product but I always like to be sure especially since that will change some of the authentication options.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 20:17:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-it-possible-to-query-prisma-cloud-compute-for-alerts-i-am-not/m-p/517686#M730</guid>
      <dc:creator>CloudEngineer</dc:creator>
      <dc:date>2022-10-12T20:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to Query Prisma Cloud Compute for Alerts? I am not interested in Prisma Cloud Alerts.</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-it-possible-to-query-prisma-cloud-compute-for-alerts-i-am-not/m-p/517791#M735</link>
      <description>&lt;P&gt;Brandon, I am grateful for your help with this matter.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are a commercial enterprise;&amp;nbsp; we have nothing to do with AWS Gov and we have no AWS Gov accounts.&amp;nbsp; I suspect that is the Prisma SaaS default behavior when the integration is only partially or mis configured.&amp;nbsp;This gov issue isn't my request for help, however, it's an issue but would take me some time to recreate the configuration to trigger that behavior in the SaaS product.&amp;nbsp; So much to do, I prefer not to spend any time on this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My issue is very detailed...&lt;/P&gt;
&lt;P&gt;No one is saying that the integration doesn't work, I assert that THE INTEGRATION WORKS but only partially. You are saying that you've seen these VERY specific kinds of alerts that I report create errors; just seeing some/any Alerts being transferred to SecurityHub is insufficient evidence that my issue is to be dismissed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me describe it again because the support comments are scrambled eggs...&lt;/P&gt;
&lt;P&gt;PCC SaaS Alerts triggered by scans of ECS &amp;amp; Artifactory registries appear to NOT be Accepted by AWS due to this error being reported by Prisma's SecurityHub Alert provider...&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;failed to add findings: [{ ErrorCode: "InvalidInput", ErrorMessage: "Finding does not adhere to Amazon Finding Format. data.Resources[0].Id should NOT be shorter than 1 characters, data.Resources[0].Id should NOT be shorter than 12 characters, data.Resources[0].Id should match pattern \"^arn:(aws|aws-cn|aws-us-gov):[A-Za-z0-9\\-]{1,63}:[a-z0-9\\-]*:([0-9]{12})?:.+$\", data.Resources[0].Id should match some schema in anyOf.", Id: "us-west-2/twistlock/vulnerabilities/" }]&lt;/PRE&gt;
&lt;P&gt;The support guy says that error is a known issue in the product but I'm hoping that you've seen registry scans CVE-Alerts propagated to SecurityHub.&amp;nbsp; Webhooks are not an option, due to my firms' policies on exposing network endpoints to public ingress internet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our AlertProvider is configured to send registry vulnerabilities...&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TommyHunt_0-1665669491831.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44661i3B5CAE5D07C3219A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="TommyHunt_0-1665669491831.png" alt="TommyHunt_0-1665669491831.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I incorrectly used the language "CI",&amp;nbsp; because there are no equivalent "Fail/Report" rules for the Registry scans; whereas there are rules for "CI" and "Deployed" scans.&amp;nbsp; Within the alert profile,&amp;nbsp; I specified these "Deployed" rules be applied to Vulnerabilities; its not clear if these would have an effect on Registry Scans' CVE-Alerts.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TommyHunt_1-1665669827948.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44662iEA8E28AB47FDC8EB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="TommyHunt_1-1665669827948.png" alt="TommyHunt_1-1665669827948.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Our intention is to use registries' scans to govern images on their path-to-production; we want to BLOCK images with CVEs of severity, CRITICAL and HIGH.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We use&amp;nbsp;&lt;SPAN&gt;Prisma Cloud Enterprise Edition (SaaS).&amp;nbsp; Because of the two kinds of Alerts in this product, I use PCC to distinguish the kind of Alert that I am speak of.&amp;nbsp; Whew!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 14:18:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-it-possible-to-query-prisma-cloud-compute-for-alerts-i-am-not/m-p/517791#M735</guid>
      <dc:creator>TommyHunt</dc:creator>
      <dc:date>2022-10-13T14:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to Query Prisma Cloud Compute for Alerts? I am not interested in Prisma Cloud Alerts.</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-it-possible-to-query-prisma-cloud-compute-for-alerts-i-am-not/m-p/519921#M773</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/183942"&gt;@CloudEngineer&lt;/a&gt;&amp;nbsp;&amp;nbsp; dude, you were correct the whole time.&amp;nbsp; &lt;SPAN&gt;The Prisma Cloud Compute SecurityHub Alert Provider works perfectly fine.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I got misinformation from support case &lt;SPAN&gt;02326773&lt;/SPAN&gt;.&amp;nbsp; Here is how I determined that the Registry Scanned CVEs and Compliance vulnerabilities were generating Alerts and propogating them to AWS SecurityHub/Findings Console.&amp;nbsp; I entered this Filter criteria and then I could see the CVE-Alerts.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TommyHunt_0-1667331233072.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/45064iB00B6368FEE1FB21/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="TommyHunt_0-1667331233072.png" alt="TommyHunt_0-1667331233072.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I still have NO explanation for those errors that I cited at the beginning of this&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2022 19:34:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-it-possible-to-query-prisma-cloud-compute-for-alerts-i-am-not/m-p/519921#M773</guid>
      <dc:creator>TommyHunt</dc:creator>
      <dc:date>2022-11-01T19:34:18Z</dc:date>
    </item>
  </channel>
</rss>

