Getting Wildfire Events into Playbooks

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Getting Wildfire Events into Playbooks

L3 Networker



Is there a way to get Wildfire Events in Panorama as a feed into XSOAR and there into a Playbook?

Right now I get those events as Mail and parse them that way - but I guess there is a more elegant way to do so...





L3 Networker

Hello Gfilippov

Thanks for your answer.

But I can't find any info, what to do on Panorama and what to do on XSOAR.

Right now, I do it via syslog...




L1 Bithead

Hey @r_buchwalder , We are currently working on a solution to ingest WF events/threat logs of PANOS to Cortex XSOAR as incidents. We are working our way through that, as we are limited to the number of logs we can get using the export API, contrary to syslog.
for reference:

Hello @bkatzir 

I'm not able to follow your github link - I do get a 404 message...


thanks for the Info anyway. Will have an eye on oncoming release notes.




Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!