Prisma Cloud Discussions
Share ideas and post questions related to Prisma Cloud — the industry's most comprehensive cloud native security platform — and the compute capabilities available within it in this forum.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Prisma Cloud Discussions
Share ideas and post questions related to Prisma Cloud — the industry's most comprehensive cloud native security platform — and the compute capabilities available within it in this forum.
About Prisma Cloud Discussions
Share ideas and post questions related to Prisma Cloud — the industry's most comprehensive cloud native security platform — and the compute capabilities available within it in this forum.

Discussions

Welcome to the Prisma Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4995 Views
  • 1 replies
  • 1 Likes

Introducing PA Prisma to my Network

Hi everyone, I hope you are all well. This is my first time post here and very excited to have entered the Palo Alto world. I am working with a third party to implement Prisma into my network environment. The idea behind this is to scrap the Bluecoat proxy, WSS proxy (Broadcom are a nightmare) and provide easier and better connectivity for our r...

ziggu88 by L0 Member
  • 3196 Views
  • 1 replies
  • 0 Likes

Prisma Cloud Event Search API - Include data.items[].rawEvent in response

In my organization we have Prisma Cloud integrated into AWS Organization environment. Which is great for monitoring and pulling data from the entire AWS Org. I want to pull the count of all ec2 instances which are created using the RunInstances call. The event search works great for the number of times the RunInstances is called, but in the r...

THolmes by L0 Member
  • 4001 Views
  • 1 replies
  • 0 Likes

How to download the policy list containing the desired information?

In the past, when downloading in csv format from the Policy menu of Prisma Cloud, the following information was included and the Policy List could be checked. (Policy Name, Cloud Type, Severity, Policy Type, Mode, Compliance Standard, Labels, Saved Search Name, Description, Recommendation for Remediation, Status, Last Modified By, Last Modified ...

KRyu by L0 Member
  • 3417 Views
  • 1 replies
  • 0 Likes

403 Function is not supported when running on cloud on JFrog Artifactory

SymptomThere may be an issue that appears when trying to scan a publicly accessible JFrog Artifactory when using the JFrog Artifactory version registry settings. Error messagesIn Defend > Vulnerabilities > Registry, you will see an error message that reads something like this in red text under the list of registries:Registry Scan: failed t...

ECR scan failed with the message "Failed to query image"

Hi forks, I'm very new of PrismaCloud and CWPP category. I've tried scan image on ECR following below TECHDOCS but it failed with the error "Registry Scan: Failed to query image details hello-ykym latest failed unmarshaling registry manifest response invalid character '<' looking for beginning of value". I assume there is no '<', so have n...

How do I validate resources that have 443 publicly exposed have a WAF ?

If you have an AWS EC2 instance with 443 exposed to the internet, you would get an alert but what would be a good way to validate that a particular instance has a WAF protecting it? One thing I was thinking of would be to do a joins looking at the EC2 security group API and the AWS WAF API but is there some other way we can look through a cloud...

Unusual server port activity Internal Alerts Potential False Positives

I have the thresholds for Unusual Server Port Internal activity set to the most conservative settings to minimize false positives but it seems like the highest port consistently gets flagged as "unusual". In the example below there are 15 ports labeled as usual and the Kafka port (9092) is being flagged as unusual. Upon further investigation w...

UnusualHighPortActivity.png

PRISMA CLOUD APP For QRADAR Released on 7th Oct 2020

Hi Team, There is prisma cloud app released on 7th Oct 2020 on IBM App Exchange. Documentation does not cover any steps for configuration on Prisma cloud side and how log will send to Qradar on 514 port. Also what would be tcp payload size as IBM QRadar says, we can't set more than 16384. Kindly note we have on-prem EC (event collector). Conside...

PrismaCloud API: Resource Scan Info

HelloWe are getting resources information by the api call /resource/scan_info (POST method), but we want to get the resource.type and the cloud.service associated to the resource in the response.In the API reference there is a field named fields wich is defined as an array of specific fields to return, but we tried to use in several ways and we ...

MLópez by L0 Member
  • 2991 Views
  • 1 replies
  • 0 Likes

Is it possible to export a list of all the Kubernetes CIS benchmarks v1.4 that Prisma Cloud checks?

Hello, I have 5 questions, regarding the use of K8s CIS benchmarks v1.4 in Prisma Cloud, any help appreciated!! 1) Does anyone know if there is a way to export a list of all the Kubernetes CIS benchmarks v1.4 that Prisma Cloud checks? (exporting in an excel, csv, etc, I don't find the option)For reference: https://docs.paloaltonetworks.com/pris...

Screen Shot 2020-12-18 at 11.04.19 AM.png
Screen Shot 2020-12-18 at 11.07.03 AM.png
An_Ban by L0 Member
  • 3153 Views
  • 1 replies
  • 0 Likes

Configure Github enterprise API as oauth2.0

Hello all, I've been trying to configure github enterprise as provider on the OAUTH2.0 authentication page. For what I can experience the API URL is hardcoded to https://api.github.com/ as I can see in the logs. My question is if it's possible to configure this URL to point to a custom domain, since we are hosting a GHE instance on our side.The ...

Prisma Internet access from remote site

Hi everyone, hope you're all safe and well. My company is in the process of rolling out Palo Alto, Prisma and Global Protect worldwide. I've come across an issue that is causing me a bit of a headache. I hope someone can help. Current setupSite A - 172.35.0.0 /16Site B - 172.33.0.0 /16Site A has a Cacheflow proxy serverAT&T provide a MPLS WA...

BChana by L0 Member
  • 2428 Views
  • 1 replies
  • 0 Likes
  • 476 Posts
  • 61 Subscriptions
Top Liked Authors