Is there a way to either export a complete list out of the Threat Vault or is there a list maintained somewhere of all the current threats? Looking for something that list the Threat ID, Name, and Severity. I need this to import into our SIEM so that when it receives the logs from the Palo Alto it is able to translate them correctly.
Thanks in advance.
Hello Karlh,
So far, there is no option to export the entire threat-vault from the PAN firewall. The database will be big enough, as It contains almost 40,000 threat. I would recommend you to consult with your Palo Alto SE for the same. He might help you with this.
Thanks
+1
following if/when this is available.
On latest v8 or higher
https[:]//IPADDRESS/api/?key=YOURKEY&type=op&cmd=<show><predefined><xpath>/predefined/threats/vulnerability</xpath></predefined></show>
On Older v7
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClSMCA0
Hello,
The threat vault info can be viewed on the PAN website.
https://threatvault.paloaltonetworks.com/
Regards,
When you integrate with SIEM it's nice to have a SOAR function to query an api for more info for example, I'm not aware of any api for the public threat vault.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!