<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RQL Custom queries for AWS needed URGENTLY in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/rql-custom-queries-for-aws-needed-urgently/m-p/523733#M833</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I would suggest opening a support case with the relevant account information so we can go ahead and hop on a call with you to determine some of your use cases and work with you on getting these RQL's constructed as well as walk you through some of the RQL related documents we have available.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Support Portal Link:&amp;nbsp;&lt;A href="https://support.paloaltonetworks.com/" target="_blank"&gt;https://support.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Dec 2022 18:19:37 GMT</pubDate>
    <dc:creator>RichVega</dc:creator>
    <dc:date>2022-12-09T18:19:37Z</dc:date>
    <item>
      <title>RQL Custom queries for AWS needed URGENTLY</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/rql-custom-queries-for-aws-needed-urgently/m-p/523604#M830</link>
      <description>&lt;P&gt;I am new to RQL and I need to build custom queries quickly for compliance reporting an would appreciate if any SME can help with providing RQL queries for the below, rather than myself spending sleepless nights to re-invent the wheel when an expert somewhere would take them 5 min. Kindly assist&lt;/P&gt;
&lt;P&gt;Custom RQL queries needed for :&lt;/P&gt;
&lt;P&gt;=========================&lt;/P&gt;
&lt;P&gt;1) Ensure the unused Key Pairs and Security Groups from AWS console are removed.&lt;BR /&gt;2) Ensure that you create Separate Keys and Groups for each set of Application Instance. Don’t use single Security Group and Key Pairs for the entire region&lt;BR /&gt;3) Ensure PEM keys for SSH are not shared with User&lt;BR /&gt;4) Ensure that you always have source IP address specified in the IAM Policies.&lt;BR /&gt;5) Ensure IAM instance roles are used for AWS resource access from instance-to-instance.&lt;BR /&gt;6) Ensure User Activity is monitored for the Audit purposes.&lt;BR /&gt;7) Ensure CloudTrail logs are encrypted at rest&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; Ensure a log metric filter and alarm exist for security group changes&lt;BR /&gt;9) Ensure appropriate subscribers to each SNS topic&lt;BR /&gt;10) Ensure PEM keys for SSH are not shared with User&lt;BR /&gt;11) Ensure the usage of different CMK per type of data based on its classification and region&lt;BR /&gt;12) Ensure that their is a private connection between VPC and S3 and the traffic never leaves the Amazon network&lt;BR /&gt;13) Ensure the In-Transit data encryption in the communication between datacenters and Amazon AWS&lt;BR /&gt;14) Ensure that where used secure SSL Ciphers when connecting between the EC2 instance and ELB&lt;BR /&gt;15) Ensure standard / approved AMI used to launch the EC2 Instances&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;appreciate the quick response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks&lt;/P&gt;
&lt;P&gt;FK&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2022 09:41:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/rql-custom-queries-for-aws-needed-urgently/m-p/523604#M830</guid>
      <dc:creator>FKisambu</dc:creator>
      <dc:date>2022-12-08T09:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: RQL Custom queries for AWS needed URGENTLY</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/rql-custom-queries-for-aws-needed-urgently/m-p/523733#M833</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I would suggest opening a support case with the relevant account information so we can go ahead and hop on a call with you to determine some of your use cases and work with you on getting these RQL's constructed as well as walk you through some of the RQL related documents we have available.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Support Portal Link:&amp;nbsp;&lt;A href="https://support.paloaltonetworks.com/" target="_blank"&gt;https://support.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 18:19:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/rql-custom-queries-for-aws-needed-urgently/m-p/523733#M833</guid>
      <dc:creator>RichVega</dc:creator>
      <dc:date>2022-12-09T18:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: RQL Custom queries for AWS needed URGENTLY</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/rql-custom-queries-for-aws-needed-urgently/m-p/523761#M835</link>
      <description>&lt;P&gt;Thank you for the response. I am currently unable to create support cases for some reason. During the recent Office Hours, someone took my email and they said they would look into it. Not heard from them since.&lt;/P&gt;
&lt;P&gt;Kindly assist.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 10 Dec 2022 13:37:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/rql-custom-queries-for-aws-needed-urgently/m-p/523761#M835</guid>
      <dc:creator>FKisambu</dc:creator>
      <dc:date>2022-12-10T13:37:16Z</dc:date>
    </item>
    <item>
      <title>Re: RQL Custom queries for AWS needed URGENTLY</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/rql-custom-queries-for-aws-needed-urgently/m-p/523808#M837</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/254055"&gt;@FKisambu&lt;/a&gt;,&amp;nbsp; you will likely require professional services to develop these custom rules or do it yourself.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on my experience,&amp;nbsp; RQL as Prisma Cloud Policies are good for detecting and alerting.&amp;nbsp; Use the native remediation, if possible.&lt;/P&gt;
&lt;P&gt;Another option is to automate the remediation then simply code a "daemon"&amp;nbsp;in a popular programming language like python or bash; schedule to run periodically; poll the Alert APIs; implement your decision-making policies then take appropriate action within that daemon.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 14:43:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/rql-custom-queries-for-aws-needed-urgently/m-p/523808#M837</guid>
      <dc:creator>TommyHunt</dc:creator>
      <dc:date>2022-12-13T14:43:15Z</dc:date>
    </item>
  </channel>
</rss>

