- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-14-2014 12:53 PM
Is there a way to either export a complete list out of the Threat Vault or is there a list maintained somewhere of all the current threats? Looking for something that list the Threat ID, Name, and Severity. I need this to import into our SIEM so that when it receives the logs from the Palo Alto it is able to translate them correctly.
Thanks in advance.
05-14-2014 02:59 PM
Hello Karlh,
So far, there is no option to export the entire threat-vault from the PAN firewall. The database will be big enough, as It contains almost 40,000 threat. I would recommend you to consult with your Palo Alto SE for the same. He might help you with this.
Thanks
12-30-2019 11:42 AM
On latest v8 or higher
https[:]//IPADDRESS/api/?key=YOURKEY&type=op&cmd=<show><predefined><xpath>/predefined/threats/vulnerability</xpath></predefined></show>
On Older v7
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClSMCA0
12-30-2019 03:07 PM
Hello,
The threat vault info can be viewed on the PAN website.
https://threatvault.paloaltonetworks.com/
Regards,
12-31-2019 07:57 AM
When you integrate with SIEM it's nice to have a SOAR function to query an api for more info for example, I'm not aware of any api for the public threat vault.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!