Palo Alto Prisma Access
You can integrate Palo Alto Prisma Access with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Palo Alto Prisma Access product overview
Palo Alto Prisma Access is a cloud-delivered Secure Access Service Edge (SASE) platform that provides secure access to applications and data for users anywhere, converging network security (ZTNA 2.0, secure web gateway, firewall-as-a-service, and CASB) with SD-WAN in a single cloud service.
What we ingest
Sophos XDR collects Palo Alto Prisma Access logs from the Palo Alto Strata Logging Service (previously called Cortex Data Lake), forwarded to Sophos XDR over HTTP. The following log categories are collected:
- Web activity: URL filtering logs.
- Threat detections: Threat logs.
- Authentication and access: GlobalProtect, administrative sign-in, and user ID events.
Event and data types
We ingest the following event and data types from Palo Alto Prisma Access:
- Web activity: URL filtering logs, including the URL, category, and action. Normalized to HTTP telemetry.
- Threat detections: Threat logs (intrusion, antivirus, and other threat events), including the signature and affected endpoints. Normalized to network intrusion detection telemetry.
- Authentication and access: GlobalProtect VPN, administrative sign-in (system), and user ID mapping events, with the user and result. Normalized to authentication telemetry.
Data provided by this integration
Data provided by Palo Alto Prisma Access gets normalized to the following schemas:
authhttp
nids
For more information about using schemas in Data Lake Search, see Schemas and logical types.