Cortex Cloud Discussions
Share ideas and post questions related to Cortex Cloud — the industry's most comprehensive cloud native security platform — and the compute capabilities available within it in this forum.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex Cloud Discussions
Share ideas and post questions related to Cortex Cloud — the industry's most comprehensive cloud native security platform — and the compute capabilities available within it in this forum.
About Cortex Cloud Discussions
Share ideas and post questions related to Cortex Cloud — the industry's most comprehensive cloud native security platform — and the compute capabilities available within it in this forum.

Discussions

Welcome to the Prisma Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 5043 Views
  • 1 replies
  • 1 Likes

Agentless scanning on Google Cloud platform

Hi All, Hope you are doing well. Anyone using Agentless scanning for their GCP env? I have a GCP environment with some restrictions ie org policies applied for skip default network creation, external IPs not allowed (but exempted for test project). the service account has appropriate permission (Permissions by feature (paloaltonetworks.com) fo...

ASachan1 by L1 Bithead
  • 2470 Views
  • 2 replies
  • 0 Likes

Unable to get container defender to detect denied IP address on host

For some reason I am unable to see any events being generated for denied IP addresses when running a container defender on one of our hosts. Did the following: installed a container defender on a linux host. created a host policy that targets the host where the container defender runs. Added google dns (8.8.8.8) to list of denied IP addresses...

Resolved! How to triage an EKS Cluster with Prisma Defender daemon set NOT appearing in the console?

So my co-worker has implemented some containerized solution and deployed it to EKS. I used my access key to create a defender.yaml for him. twistcli defender export kubernetes \--address ${PRISMA_CLOUD_COMPUTE_CONSOLE_API_ADDR} \--user ${PRISMA_ADMIN_USER} \--password ${PRISMA_SECRET} \--cluster-address ${PRISMA_CLOUD_COMPUTE_SVC_ADDR} And she d...

TommyHunt_0-1667403289928.png
TommyHunt_1-1667404246937.png
TommyHunt by L3 Networker
  • 14022 Views
  • 16 replies
  • 0 Likes

Resolved! PCC/Manage/Defenders/Deploy/Defender/Single Defender/Container Defender - App Embedded/Fargate task generates JSON unacceptable to AWS

Given that I navigate to PCCConsole/Manage/Defenders/Deploy/Defender/Single Defender/Container Defender - App Embedded/Fargate task And I paste the Fargate Task Definition JSON produced by AWS ECS When I push the 'Generate protected task' button And Copy Prisma's generated JSON And Paste it into the new revision of an existing Task Definition Th...

TommyHunt by L3 Networker
  • 5562 Views
  • 6 replies
  • 0 Likes

Prisma cloud[ERROR] Runtime.ImportModuleError: Unable to import module 'twistlock': Failed to import module: lambda_function Traceback (most recent ca

We are getting the following error in our Lambdas, [ERROR] Runtime.ImportModuleError: Unable to import module 'twistlock': Failed to import module: lambda_function Traceback (most recent call last): After troubleshooting, our team identifies that is due Prisma Defender, apparently the lambda handler was changed to twistlock.handler.

SPerry5 by L0 Member
  • 10124 Views
  • 10 replies
  • 1 Likes

In the Prisma i can see vulnerabilities pointing on files that are not there anymore

Hello everyone, In the Prisma compliance check, I see some vulnerabilities that seem outdated. For example, Prisma reports a vulnerable file that does not exist and, most likely, it's not there for a while. Is it a bug, or I'm missing something? -Andrey Please note you are posting a public message where community members and exp...

Show (X;Y) doesn't work trying to combine aws-ec2-describe-security-groups and aws-ec2-describe-vpcs

Hi All, I would really appreciate some help here, as I have tried hundreds of iterations to get this right and it isn't working. I followed the RQL guidance of the RQL example library, but even a basic example doesn't work with show(X;|Y;) I tried the following and it doesn't work: show (X;|Y;) - command doesn't work config from cloud.resource w...

EPienaar by L0 Member
  • 2640 Views
  • 1 replies
  • 0 Likes

Resolved! Given GET PCC/api/v22.06/registry/names, why does API return NULL for only the artifactory registry names?

Given this command curl -k \-u "${PRISMA_KEY_ID}" \-H 'Content-Type: application/json' \-X GET \"${PRISMA_CLOUD_COMPUTE_CONSOLE_API_ADDR}/api/v22.06/registry/names" When it is invoked Then it returns these ECR and artifactory regsitry names ["jfrog.nonprod.private.com/artifactory/docker-virtual/simple-ecs-task:latest",,"private5.dkr.ecr.us-west-...

TommyHunt by L3 Networker
  • 5059 Views
  • 6 replies
  • 0 Likes

Issue with nat policies in Prisma ION device

Here is the error on this issue, I cannot enable the NAT rule after upgrading the ION 2K device to the 5.4.13 version. NAT extension cannot be enabled for the device having support for nat policy. Having an issue with NAT extension cannot be enabled for the device having support

  • 478 Posts
  • 68 Subscriptions
Top Solution Authors
Top Liked Authors