Prisma Cloud Discussions
Share ideas and post questions related to Prisma Cloud — the industry's most comprehensive cloud native security platform — and the compute capabilities available within it in this forum.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Prisma Cloud Discussions
Share ideas and post questions related to Prisma Cloud — the industry's most comprehensive cloud native security platform — and the compute capabilities available within it in this forum.
About Prisma Cloud Discussions
Share ideas and post questions related to Prisma Cloud — the industry's most comprehensive cloud native security platform — and the compute capabilities available within it in this forum.

Discussions

Welcome to the Prisma Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 5002 Views
  • 1 replies
  • 1 Likes

Prisma Cloud enterprise edititon

Hello, This is in regards to Prisma Cloud Enterprise Edition integration with Microsoft Azure I would appreciate if any one could let me know what all services in Azure, Prisma Cloud Enterprise Edition supports for detection, Reporting, compliance and remediation. For e.g Azure defenders supports the following services: App Servic...

Detect Agent Installation via Prisma Cloud

We are looking to be able to check the following scenarios via Prisma Cloud.1) Is EDR / Anti-Virus installed on compute workloads2) Health status of the services3) Enable auto-remediation (installation) if not present. Has anyone worked through this scenario?

Defender for dockers installed via snap

Hello everyone.I'm using Ubuntu 20.04 LTS and I installed docker via snap to run containers. When I install a container defender on this host, I get the following error: invalid output path: directory "/var/lib/twistlock" does not exist.Failed to copy from container twistlock_data:/prisma-static-data/twistlock-defender.service to host at /var/li...

Prisma Cloud Compute API filtering

Hello, I'm using the Compute/Twistlock API to query image statuses, but I'd like to filter the fields returned to reduce the size of the payload, which contains many things I don't care about for now. I looked at https://cdn.twistlock.com/docs/api/twistlock_api.html#images_get and it mentions a fields query parameter which sounds perfect for my ...

AYANG by L0 Member
  • 7814 Views
  • 5 replies
  • 0 Likes

Credits for Defender

Hi, I want to ask how the credits work for Defender. If I have docker containers and host that scale up and down, how would the credits be calculated? There is a limit on the credits, so will the scaling up and running the defender stop at the limit of the credits? Thanks.

TChew by L0 Member
  • 2579 Views
  • 1 replies
  • 0 Likes

Prisma Cloud Integrations - Must have or Optional

I'm doing a cost analysis on multiple AWS security tools and Prisma Cloud Enterprise. From looking at the Prisma Cloud Admin Guide it looks like we can ingest logs from Amazon GuardDuty, AWS Inspector, and AWS Security Hub. Can Prisma Cloud Enterprise perform the same security functions as these tools or does it need to use these tools to perf...

John_J by L1 Bithead
  • 3306 Views
  • 1 replies
  • 0 Likes

Resolved! RQL find excessive sts:AssumeRole

Trying to put together a query to identify excessive assumeRole permissions. For example it would identify if the following is in a policy. "Action": ["sts:AssumeRole"],"Effect": "Allow","Resource": "*" I've been messing around with some queries, I haven't had any luck finding one that works. The following query will pickup policies where the "s...

Resolved! Prisma Cloud Qradar Integration Still Exist?

I had this link bookmarked a while ago and now it seems to have been taken down. Is there still native integration? I can't find any documentation around it and it does not show up as an option under enterprise settings->integrations. https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/configure-external-integrations-on...

How can i confirm whether log ingestion frm respective cloud accnts is successfully happening or not

Hello Guys, Can somebody please answer my query. From the cloud accounts section of Prisma Cloud UI, I can able to see all the status checks got passed for Config,Flow,Audit logs for one of the cloud accounts. However when I ran the simple query(Ex:- event where cloud.account="X.X.X.X") from investigate blade for audit/flow logs, there were no l...

MPalagiri_1-1605783030320.png
Capture.JPG

Resolved! AWS Serverless and IAM security checks

Hello Prisma Cloud Experts, I'm fairly new to CWPP and tried some native and free options and looking at commercial products now. VNETs, Traditional compute and private endpoints are not difficult to grasp, while the transition to serverless is slightly more complex. What parts of the Prisma Cloud product should the customer use when assessi...

SergGur by L2 Linker
  • 6590 Views
  • 2 replies
  • 0 Likes

Resolved! Time interval setting for Anomaly Settings

At first glance, it looks as if there is no real way to put a setting to the Anomaly Setting for "Port Scan Activity (External)". The rationale behind the question is, you're only looking at the amount of scans for the Conservative Moderate and Aggressive settings and looks at 500,200 and 50 ports respectively. 500 ports in a minute is obvious...

  • 476 Posts
  • 61 Subscriptions
Top Liked Authors