Export Threat Vault information

cancel
Showing results for 
Search instead for 
Did you mean: 

Export Threat Vault information

Not applicable

Is there a way to either export a complete list out of the Threat Vault or is there a list maintained somewhere of all the current threats?  Looking for something that list the Threat ID, Name, and Severity.  I need this to import into our SIEM so that when it receives the logs from the Palo Alto it is able to translate them correctly.

Thanks in advance.

5 REPLIES 5

L7 Applicator

Hello Karlh,

So far, there is no option to export the entire threat-vault from the PAN firewall. The database will be big enough, as It contains almost 40,000 threat.  I would recommend you to consult with your Palo Alto  SE for the same. He might help you with this.

Thanks

L3 Networker

+1

following if/when this is available.

On latest v8 or higher

 

https[:]//IPADDRESS/api/?key=YOURKEY&type=op&cmd=<show><predefined><xpath>/predefined/threats/vulnerability</xpath></predefined></show>

 

On Older v7

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClSMCA0

Hello,

The threat vault info can be viewed on the PAN website.

 

https://threatvault.paloaltonetworks.com/

 

Regards,

When you integrate with SIEM it's nice to have a SOAR function to query an api for more info for example, I'm not aware of any api for the public threat vault.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!