<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Palo Alto Networks Application for QRadar in App for QRadar Articles</title>
    <link>https://live.paloaltonetworks.com/t5/app-for-qradar-articles/palo-alto-networks-application-for-qradar/ta-p/118455</link>
    <description>&lt;H2&gt;&lt;STRONG&gt;Overview&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Palo Alto Networks and IBM have partnered to deliver advanced security reporting and analytics to the the widely used IBM® QRadar® SIEM. Integrate QRadar seamlessly with the Palo Alto Networks platform to streamline operations and improves security. The Palo Alto Networks app for QRadar enables these capabilities by allowing the security operations team to reduce, prioritize, and correlate Palo Alto Networks events using the QRadar dashboard, and leverage offenses and offense workflows created automatically, enabling rapid response to the most critical threats from a single dashboard.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;System Requirements:&lt;/STRONG&gt;&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;IBM QRadar version 7.2.8 or higher&lt;/LI&gt;
&lt;LI&gt;Palo Alto Networks PAN-OS 7.0 or higher&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Installation Steps:&lt;/STRONG&gt;&lt;/H3&gt;
&lt;OL&gt;
&lt;LI&gt;&amp;nbsp;&lt;STRONG&gt;Download the Palo Alto Networks app for QRadar from the IBM App Exchange:&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;A title="Palo Alto Networks App for QRadar | IBM" href="https://exchange.xforce.ibmcloud.com/hub/extension/Palo%20Alto%20Networks:Palo%20Alto%20Networks%20App%20for%20QRadar" target="_blank" rel="noopener"&gt;https://exchange.xforce.ibmcloud.com/hub/extension/Palo%20Alto%20Networks:Palo%20Alto%20Networks%20App%20for%20QRadar&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Upload and install the app on IBM QRadar using the following documentation from IBM:&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;A title="Uploading your app | IBM" href="https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.1/com.ibm.apps.doc/t_Qapps_upload.html" target="_blank" rel="noopener"&gt;https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.1/com.ibm.apps.doc/t_Qapps_upload.html&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Configure the Palo Alto Networks firewall&amp;nbsp;to send syslogs to IBM QRadar:&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;A title="Creating a Syslog destination on your Palo Alto PA Series device | IBM" href="https://www.ibm.com/support/knowledgecenter/en/SS42VS_DSM/t_dsm_guide_palo_alto_syslog_dest.html?cp=SS42VS_7.3.0" target="_self"&gt;https://www.ibm.com/support/knowledgecenter/en/SS42VS_DSM/t_dsm_guide_palo_alto_syslog_dest.html?cp=SS42VS_7.3.0&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;LEEF log format is the recommended setup however, if your company can not use LEEF logging standard for QRadar, we have an extension available for PAN-OS standard log format available here: &lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A title="LEEF Log Format To Standard Log Format Extension | LIVEcommunity" href="https://live.paloaltonetworks.com/t5/App-for-QRadar-Articles/LEEF-Log-Format-to-Standard-Log-Format-Extension/ta-p/145391" target="_self"&gt;https://live.paloaltonetworks.com/t5/App-for-QRadar-Articles/LEEF-Log-Format-to-Standard-Log-Format-Extension/ta-p/145391&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No further configuration is needed. Logs sent from the Palo Alto Networks firewall in the default syslog format are automatically identified by QRadar and the app.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Demo Video&lt;/H2&gt;
&lt;P&gt;&lt;div class="video-embed-center video-embed"&gt;&lt;iframe class="embedly-embed" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FB4ZKSPEjxHo%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DB4ZKSPEjxHo&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FB4ZKSPEjxHo%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" width="200" height="112" scrolling="no" title="Demo: Palo Alto Networks App for QRadar" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture;" allowfullscreen="true"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Support&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;IBM QRadar&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;See Getting Support for IBM Security QRadar products in the IBM Support site&lt;BR /&gt;&lt;A title="QRadar: Links &amp;amp; Important Support Resources " href="http://www-01.ibm.com/support/docview.wss?uid=swg21616144" target="_blank" rel="noopener"&gt;http://www-01.ibm.com/support/docview.wss?uid=swg21616144&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Palo Alto Networks firewall support&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Open a ticket with Palo Alto Networks TAC at:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A title="Opening a Case With Customer Support | Knowledgebase " href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClNSCA0" target="_blank" rel="noopener"&gt;Opening a Case with Customer Support&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 26 Aug 2019 19:50:40 GMT</pubDate>
    <dc:creator>btorresgil</dc:creator>
    <dc:date>2019-08-26T19:50:40Z</dc:date>
    <item>
      <title>Palo Alto Networks Application for QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/app-for-qradar-articles/palo-alto-networks-application-for-qradar/ta-p/118455</link>
      <description>&lt;P&gt;Palo Alto Networks and IBM have partnered to deliver advanced security reporting and analytics to the the widely used IBM® QRadar® SIEM. Integrate QRadar seamlessly with the Palo Alto Networks platform to streamline operations and improves security.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 19:50:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/app-for-qradar-articles/palo-alto-networks-application-for-qradar/ta-p/118455</guid>
      <dc:creator>btorresgil</dc:creator>
      <dc:date>2019-08-26T19:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks Application for QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/app-for-qradar-articles/palo-alto-networks-application-for-qradar/tac-p/173465#M6</link>
      <description>&lt;P&gt;The 3rd url in the installation steps in moved, can that be made available.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2017 17:15:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/app-for-qradar-articles/palo-alto-networks-application-for-qradar/tac-p/173465#M6</guid>
      <dc:creator>mhaaris17</dc:creator>
      <dc:date>2017-08-28T17:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks Application for QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/app-for-qradar-articles/palo-alto-networks-application-for-qradar/tac-p/173467#M7</link>
      <description>&lt;P&gt;Thanks I have updated the URL.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2017 17:33:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/app-for-qradar-articles/palo-alto-networks-application-for-qradar/tac-p/173467#M7</guid>
      <dc:creator>panguyen</dc:creator>
      <dc:date>2017-08-28T17:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks Application for QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/app-for-qradar-articles/palo-alto-networks-application-for-qradar/tac-p/506912#M25</link>
      <description>&lt;P&gt;Hi, It seems like the current app is deprecated because of old O/S . Is there any plan to publish new app ? Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 01:34:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/app-for-qradar-articles/palo-alto-networks-application-for-qradar/tac-p/506912#M25</guid>
      <dc:creator>sakapur</dc:creator>
      <dc:date>2022-06-29T01:34:48Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks Application for QRadar</title>
      <link>https://live.paloaltonetworks.com/t5/app-for-qradar-articles/palo-alto-networks-application-for-qradar/tac-p/558842#M26</link>
      <description>&lt;P&gt;We use Qradar as our SIEM and need to know if there are plans to update this app to work with newer versions of QRadar anytime soon?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 16:41:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/app-for-qradar-articles/palo-alto-networks-application-for-qradar/tac-p/558842#M26</guid>
      <dc:creator>Matt-Mercer</dc:creator>
      <dc:date>2023-09-20T16:41:56Z</dc:date>
    </item>
  </channel>
</rss>

