Skip to content

Commit

Permalink
Merge pull request #224 from hlxsites/an-ag-update
Browse files Browse the repository at this point in the history
Updated the Trade Mark symbol to registered Symbol
  • Loading branch information
Aishbn authored Nov 13, 2023
2 parents e98bb30 + 07d2ddd commit 7a5dd3a
Show file tree
Hide file tree
Showing 145 changed files with 303 additions and 292 deletions.
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
== NAT gateway IP addresses

To ensure that Prisma Cloud Defenders can communicate with the Prisma Cloud Compute Console, and that you can access Prisma Cloud and the API for any integrations that you enabled between Prisma Cloud and your incidence response workflows, you may need to update the IP addresses in your allow lists.
To ensure that Prisma Cloud Defenders can communicate with the Prisma Cloud Compute Console, and that you can access Prisma® Cloud and the API for any integrations that you enabled between Prisma Cloud and your incidence response workflows, you may need to update the IP addresses in your allow lists.

Refer to https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/get-started-with-prisma-cloud/enable-access-prisma-cloud-console[access the Prisma Cloud console], for a comprehensive list of NAT gateway IP addresses and domains for all Prisma Cloud modules and capabilities.

Original file line number Diff line number Diff line change
Expand Up @@ -3,11 +3,11 @@
[#id9b1ef9b8-51a6-40dc-8afc-ceb2b8251b67]
== Integrate Prisma Cloud with Amazon GuardDuty

Learn how to integrate Prisma Cloud with Amazon GuardDuty.
Learn how to integrate Prisma® Cloud with Amazon GuardDuty.

Amazon GuardDuty is a continuous security monitoring service that analyzes and processes Virtual Private Cloud (VPC) Flow Logs and AWS CloudTrail event logs. GuardDuty uses security logic and AWS usage statistics techniques to identify unexpected and potentially unauthorized and malicious activity.

Prisma Cloud integrates with GuardDuty and extends its threat visualization capabilities. Prisma Cloud starts ingesting GuardDuty data, correlates it with the other information that Prisma Cloud already collects, and presents contextualized and actionable information through the Prisma Cloud app.
Prisma® Cloud integrates with GuardDuty and extends its threat visualization capabilities. Prisma Cloud starts ingesting GuardDuty data, correlates it with the other information that Prisma Cloud already collects, and presents contextualized and actionable information through the Prisma Cloud app.

[.procedure]
. Enable Amazon GuardDuty on your AWS instances (see https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_settingup.html[Amazon Documentation]).
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
[.task]
[#id80669b57-2586-4651-a17f-40a7fe7e15df]
== Integrate Prisma Cloud with Amazon S3
Learn how to integrate Prisma Cloud with Amazon S3.
Learn how to integrate Prisma® Cloud with Amazon S3.

Amazon S3 is widely used for storage and staging data. You can integrate Prisma Cloud with Amazon S3 to get notifications for configuration, audit, and anomaly policy violations.

Expand Down Expand Up @@ -58,9 +58,9 @@ image::integrate-amazon-s3-2.png[scale=50]

.. Log in to Prisma Cloud.

.. Select "Settings > Integrations".
.. Select *Settings > Integrations*.

.. "Add Integration > Amazon S3". A modal wizard opens where you can add the S3 integration.
.. *Add Integration > Amazon S3*. A modal wizard opens where you can add the S3 integration.
+
image::amazon-s3-int-1.png[scale=40]

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,9 +3,9 @@
[#id72fd0b2f-689a-4053-830c-ecb02efa5fbc]
== Integrate Prisma Cloud with Amazon SQS

Learn how to integrate Prisma Cloud with Amazon Simple Queue Service (SQS).
Learn how to integrate Prisma® Cloud with Amazon Simple Queue Service (SQS).

If you use Amazon Simple Queue Service (SQS) to enable custom workflows for alerts, Prisma Cloud integrates with Amazon SQS. When you set up the integration, as soon as an alert is generated, the alert payload is sent to Amazon SQS.
If you use Amazon Simple Queue Service (SQS) to enable custom workflows for alerts, Prisma® Cloud integrates with Amazon SQS. When you set up the integration, as soon as an alert is generated, the alert payload is sent to Amazon SQS.

The integration gives you the flexibility to send alerts to a queue in the same AWS account that you may have onboarded to Prisma Cloud or to a queue in a different AWS account. If you want to send alerts to an SQS in a different AWS account, you must provide the relevant IAM credentials—Access Key or IAM Role.

Expand Down Expand Up @@ -45,7 +45,7 @@ image::sqs-queue-details.png[scale=40]

. If you are using a Customer Managed Key to encrypt queues in Amazon SQS, you must configure the Prisma Cloud Role with explicit permission to read the key.

.. On the Amazon console, select "KMS > Customer Managed Keys" and *Create Key*.
.. On the Amazon console, select *KMS > Customer Managed Keys* and *Create Key*.
+
Refer to the AWS documentation for details on https://docs.aws.amazon.com/kms/latest/developerguide/create-keys.html[creating keys].
+
Expand Down Expand Up @@ -74,9 +74,9 @@ When you add the above permissions to the CFT Templates and the account you run

.. Log in to Prisma Cloud.

.. Select "Settings > Integrations".
.. Select *Settings > Integrations*.

.. "Add Integration > Amazon SQS". A modal wizard opens where you can add the SQS integration.
.. *Add Integration > Amazon SQS*. A modal wizard opens where you can add the SQS integration.
+
image::amazon-s3-int-1.png[scale=40]

Expand Down Expand Up @@ -107,11 +107,11 @@ This IAM permissions for both options must include sqs:SendMessage and sqs:SendM

.. *Test* and *Save* the integration.
+
After you set up the integration successfully, you can use the Get Status link in "Settings > Integrations" to periodically check the integration status.
After you set up the integration successfully, you can use the Get Status link in *Settings > Integrations* to periodically check the integration status.
+
image::get-status.png[scale=15]

.. To edit the integration, on "Settings > Integrations", click the corresponding *edit* icon. The integration *Summary* page opens.
.. To edit the integration, on *Settings > Integrations*, click the corresponding *edit* icon. The integration *Summary* page opens.
+
image::amazon-sqs-int-2.png[scale=40]

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
[#id61f76ceb-9311-4af0-b3f8-58ff6598c822]
== Integrate Prisma Cloud with Amazon Inspector

Learn how to integrate Prisma Cloud with Amazon Inspector.
Learn how to integrate Prisma® Cloud with Amazon Inspector.

Prisma Cloud ingests vulnerability data and security best practices deviations from Amazon Inspector to provide organizations with additional context about risks in the cloud. You can identify suspicious traffic to sensitive workloads, such as databases with known vulnerabilities.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,11 +2,11 @@
[.task]
[#id910768c2-7e77-4c6b-af53-56ff7327fec1]
== Integrate Prisma Cloud with AWS Security Hub
Learn how to integrate Prisma Cloud with AWS Security Hub so that you can view and monitor your security posture on AWS Security Hub.
Learn how to integrate Prisma® Cloud with AWS Security Hub so that you can view and monitor your security posture on AWS Security Hub.

You can use AWS Security Hub as a central console to view and monitor the security posture of your cloud assets on AWS Security Hub.

Integrate Prisma Cloud with AWS Security Hub for centralized visibility into security and compliance risks associated with your cloud assets on the AWS Security Hub console.
Integrate Prisma® Cloud with AWS Security Hub for centralized visibility into security and compliance risks associated with your cloud assets on the AWS Security Hub console.

As part of the integration, Prisma Cloud monitors your assets on your AWS cloud and sends alerts about resource misconfigurations, compliance violations, network security risks, and anomalous user activities directly to the AWS Security Hub console so that you have a comprehensive view of the cloud assets deployed on your AWS accounts.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,9 +3,9 @@
[#idb37367ae-f85a-4117-909d-8c9f6e70255a]
== Integrate Prisma Cloud with Azure Service Bus Queue

Learn how to integrate Prisma Cloud with Azure Service Bus Queue.
Learn how to integrate Prisma® Cloud with Azure Service Bus Queue.

Prisma Cloud can send alerts to a queue on the Azure Service Bus messaging service. To authorize access, you can either use a Shared Access Signature for limiting access permissions to the Service Bus namespace or queue, or use the service principal credentials associated with the Azure Cloud account you have onboarded to Prisma Cloud. If you plan to use the service principal that uses Azure Active Directory to authorize requests, you must include the additional role— https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#azure-service-bus-data-sender[Azure Service Bus Data Sender]— and enable send access to the Service Bus namespace and queues.
Prisma® Cloud can send alerts to a queue on the Azure Service Bus messaging service. To authorize access, you can either use a Shared Access Signature for limiting access permissions to the Service Bus namespace or queue, or use the service principal credentials associated with the Azure Cloud account you have onboarded to Prisma Cloud. If you plan to use the service principal that uses Azure Active Directory to authorize requests, you must include the additional role— https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#azure-service-bus-data-sender[Azure Service Bus Data Sender]— and enable send access to the Service Bus namespace and queues.

When configured, as soon as an alert is generated, the entire alert payload is sent to the queue.

Expand Down
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
[#id92ce74af-d099-406b-af8d-d808c593f73a]
== Integrate Prisma Cloud with Cortex XSOAR

Learn how to integrate Prisma Cloud with Cortex XSOAR (formerly Demisto^®^) to send alerts and enable multi-step automated remediation using Cortex XSOAR playbooks.
Learn how to integrate Prisma® Cloud with Cortex XSOAR (formerly Demisto^®^) to send alerts and enable multi-step automated remediation using Cortex XSOAR playbooks.

With the Prisma Cloud and Cortex XSOAR (formerly Demisto) outbound or push-based integration, you can send a Prisma Cloud alert generated by a policy violation to Cortex XSOAR. This integration enables your Security operations team to define custom playbooks or use the out-of-box playbooks on Cortex XSOAR to create multi-step workflows for incident management of your cloud resources; this is an alternative to the https://xsoar.pan.dev/docs/reference/integrations/red-lock[pull-based integration] that you can configure from Cortex XSOAR.
With the Prisma® Cloud and Cortex XSOAR (formerly Demisto) outbound or push-based integration, you can send a Prisma Cloud alert generated by a policy violation to Cortex XSOAR. This integration enables your Security operations team to define custom playbooks or use the out-of-box playbooks on Cortex XSOAR to create multi-step workflows for incident management of your cloud resources; this is an alternative to the https://xsoar.pan.dev/docs/reference/integrations/red-lock[pull-based integration] that you can configure from Cortex XSOAR.

Using the policy ID in the alert, Cortex XSOAR categorizes the alert as a specific incident type. For an incident type, the Prisma Cloud alert payload is mapped to a Cortex XSOAR layout that specifies the incident fields for data classification and mapping on Cortex XSOAR. The current list of incident types are: AWS CloudTrail Misconfiguration, AWS EC2 Instance Misconfiguration, AWS IAM Policy Misconfiguration, Azure AKS Misconfiguration, Azure Network Misconfiguration, Azure SQL Misconfiguration, Azure Storage Misconfiguration, GCP Compute Engine Misconfiguration, GCP Kubernetes Engine Misconfiguration, and Prisma Cloud. If the policy ID is not categorized to a specific incident type, it is automatically mapped to the generic Prisma Cloud incident type. Every incident type is mapped to a Cortex XSOAR layout and associated with a playbook to enable autoremediation of the violating resource, except for the generic Prisma Cloud incident type.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@
[.task]
[#id01b3074f-c0bf-4b25-ba8c-49ef0fec940c]
== Integrate Prisma Cloud with Google Cloud Security Command Center (SCC)
Learn how to integrate Prisma Cloud with Google Cloud Security Command Center (SCC).
Learn how to integrate Prisma® Cloud with Google Cloud Security Command Center (SCC).

Integrate Prisma Cloud with Google Cloud Security Command Center (SCC) for centralized visibility in to security and compliance risks associated with your cloud assets on the Google Cloud Platform (GCP).
Integrate Prisma® Cloud with Google Cloud Security Command Center (SCC) for centralized visibility in to security and compliance risks associated with your cloud assets on the Google Cloud Platform (GCP).

You can set up this integration for a GCP Organization that you are monitoring with Prisma Cloud. The alerts generated by Prisma Cloud for GCP accounts based on your alert rule are posted to Google Cloud SCC. To show Prisma Cloud alerts in Google Could SCC for cloud accounts of other cloud types (such as AWS and Azure), contact Prisma Cloud support on the https://live.paloaltonetworks.com/t5/Prisma-Cloud/ct-p/PrismaCloud[Palo Alto Networks LIVE Community].

Expand Down
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
[#idb53b7bec-bf66-42c0-91bb-ea4c92c801b6]
== Integrate Prisma Cloud with Jira

Learn how to integrate Prisma Cloud with Jira and receive Prisma Cloud alerts in your Jira accounts.
Learn how to integrate Prisma® Cloud with Jira and receive Prisma Cloud alerts in your Jira accounts.

Integrate Prisma Cloud with Jira and receive Prisma Cloud alert notifications in your Jira accounts. With this integration, you can automate the process of generating Jira tickets with your existing security workflow.
Integrate Prisma® Cloud with Jira and receive Prisma Cloud alert notifications in your Jira accounts. With this integration, you can automate the process of generating Jira tickets with your existing security workflow.

This integration works with all Jira Cloud and Jira On-Premises versions prior to 9.0.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,11 +2,11 @@
[.task]
[#id193acf38-9142-4da2-90e3-bd288626f7f5]
== Integrate Prisma Cloud with Microsoft Teams
Learn how to integrate Prisma Cloud with Microsoft Teams.
Learn how to integrate Prisma® Cloud with Microsoft Teams.

Microsoft Teams is a cloud-based team collaboration software that is part of the Office 365 suite of applications and is used for workplace chat, video meetings, file storage, and application integration.

Prisma Cloud integrates with Microsoft Teams and monitors your assets and sends alerts on resource misconfigurations, compliance violations, network security risks, and anomalous user activities either as they happen or as a consolidated summary card—determined by how you configure alert notifications. Each alert message is a webhook notification that includes details such as the cloud type, policy name, and the resource that triggered the alert and the message card indicates the severity with a red (high), yellow (medium) or gray (low) line to help you quickly assess alert severity.
Prisma® Cloud integrates with Microsoft Teams and monitors your assets and sends alerts on resource misconfigurations, compliance violations, network security risks, and anomalous user activities either as they happen or as a consolidated summary card—determined by how you configure alert notifications. Each alert message is a webhook notification that includes details such as the cloud type, policy name, and the resource that triggered the alert and the message card indicates the severity with a red (high), yellow (medium) or gray (low) line to help you quickly assess alert severity.

[.procedure]
. Set up Microsoft Teams to view alert notifications from Prisma Cloud.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@
[.task]
[#id5c459fe7-787b-42a9-a3d0-19ab049c5777]
== Integrate Prisma Cloud with PagerDuty
Learn how to integrate Prisma Cloud with PagerDuty to see alerts in your service or application.
Learn how to integrate Prisma® Cloud with PagerDuty to see alerts in your service or application.

Integrate Prisma Cloud with PagerDuty to aid alerting, on-call scheduling, escalation policies, and incident tracking to increase uptime of your apps, servers, websites, and databases. When integrated, Prisma Cloud sends alerts to the PagerDuty service, notifying your incident response teams to investigate and remediate security incidents.
Integrate Prisma® Cloud with PagerDuty to aid alerting, on-call scheduling, escalation policies, and incident tracking to increase uptime of your apps, servers, websites, and databases. When integrated, Prisma Cloud sends alerts to the PagerDuty service, notifying your incident response teams to investigate and remediate security incidents.



Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,9 +3,9 @@
[#idab93ae38-2d2b-4048-8276-b6a14fb9b21d]
== Integrate Prisma Cloud with Qualys

Learn how to integrate Prisma Cloud with Qualys.
Learn how to integrate Prisma® Cloud with Qualys.

Prisma Cloud integrates with the Qualys platform to ingest and visualize vulnerability data for your resources that are deployed on the AWS and Azure cloud platforms.
Prisma® Cloud integrates with the Qualys platform to ingest and visualize vulnerability data for your resources that are deployed on the AWS and Azure cloud platforms.

[.procedure]
. Gather the information that you need to set up the Qualys integration on Prisma Cloud.
Expand Down
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
[#id7923e9e1-612f-4a18-a030-f3470aec2fce]
== Integrate Prisma Cloud with ServiceNow

Learn how to integrate Prisma Cloud with ServiceNow to help you prioritize and respond to Security incidents on ServiceNow.
Learn how to integrate Prisma® Cloud with ServiceNow to help you prioritize and respond to Security incidents on ServiceNow.

Integrate Prisma Cloud with ServiceNow and get automatically notified about Prisma Cloud alerts through ServiceNow tickets to prioritize incidents and vulnerabilities that impact your business. Prisma Cloud integrates with the ITSM module (incident table), the Security Incident Response module (sn_si_incident table), and the Event Management modules (em_event table) on ServiceNow to generate alerts in the form of ITSM Incident, Security Incident, and Event tickets. After you enable the integration, when Prisma Cloud scans your cloud resources and detects a policy violation, it generates an alert and pushes it to ServiceNow as a ticket. When you dismiss an alert on Prisma Cloud, Prisma Cloud sends a state change notification to update the ticket status on ServiceNow. This integration seamlessly fits in to the existing workflows for incident management (ITSM), security operations management (Security Incident Response) or event management for your organization.
Integrate Prisma® Cloud with ServiceNow and get automatically notified about Prisma Cloud alerts through ServiceNow tickets to prioritize incidents and vulnerabilities that impact your business. Prisma Cloud integrates with the ITSM module (incident table), the Security Incident Response module (sn_si_incident table), and the Event Management modules (em_event table) on ServiceNow to generate alerts in the form of ITSM Incident, Security Incident, and Event tickets. After you enable the integration, when Prisma Cloud scans your cloud resources and detects a policy violation, it generates an alert and pushes it to ServiceNow as a ticket. When you dismiss an alert on Prisma Cloud, Prisma Cloud sends a state change notification to update the ticket status on ServiceNow. This integration seamlessly fits in to the existing workflows for incident management (ITSM), security operations management (Security Incident Response) or event management for your organization.

The Prisma Cloud integration with ServiceNow is qualified with the most recent cloud-based GA versions of ServiceNow; the on-premise versions are not supported.

Expand Down
Loading

0 comments on commit 7a5dd3a

Please sign in to comment.