XSOAR Sessions and Submissions option

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

XSOAR Sessions and Submissions option

L2 Linker

Hi,

 

I came across this documentation regarding XSOAR

https://docs.paloaltonetworks.com/cortex/cortex-xsoar/6-9/cortex-xsoar-threat-intel-management-guide...

 

The Sessions & Submissions tab enables you to use your sessions and submissions data for investigation and analysis. Sessions and submissions data is available for customers with a TIM license and at least one of the following products:

 

  • Palo Alto Networks Firewall
  • WildFire
  • Cortex XDR
  • Prisma SaaS
  • Prisma Access

    Sessions refers to firewall sessions, while Submissions  refers to logs of samples reported to Wildfire from other Palo Alto Networks products. Sessions data shows you connections from one endpoint to another, and submissions data shows you if a file was found on a specific endpoint.
     
    We are using PaloAlto Firewall. Does this mean I send traffic sessions from the PaloAlto firewall to XSOAR and it checks the IPs (realtime or periodically) e.g. source or destination is in the indicator list present in Threat Intel section on XSOAR?
    How does this integration work?
     
    Thanks

     

  •  
  •  
  •  
  •  
1 accepted solution

Accepted Solutions

L2 Linker

Hi, 

 

No, XSOAR does not process or enrich this info, you will only be able to view and query the sessions data generated from your PAN firewall and listed other products.

 

View solution in original post

1 REPLY 1

L2 Linker

Hi, 

 

No, XSOAR does not process or enrich this info, you will only be able to view and query the sessions data generated from your PAN firewall and listed other products.

 

  • 1 accepted solution
  • 1034 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!