-
Notifications
You must be signed in to change notification settings - Fork 519
Open
Labels
Category: CDRIntegration:prisma_cloudPalo Alto Prisma CloudPalo Alto Prisma CloudTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]enhancementNew feature or requestNew feature or request
Description
As part of effort to leverage Cloud Detection and Response (CDR) workflows such as Elastic CSPM and CNVM for 3rd party integrations, both misconfigurations and vulnerabilities findings data from Palo Alto Prisma Cloud integration needs to be enriched just like previous enhancements for Wiz.
Tasks:
- Get access to Palo Alto Prisma Cloud instance.
- Optional: Deploy Palo Alto Prisma Cloud to SEI demo cluster.
- Analyse mappings for Palo Alto Prisma Cloud and get necessary clarifications.
- Palo Alto Prisma Cloud: Implement mappings for Cloud Security Workflows #15059
- Palo Alto Prisma Cloud: Implement transform for Cloud Security Workflows #15060
Success Criteria
The misconfigurations and vulnerabilities findings from Palo Alto Prisma Cloud integration should be part of the data view suggested and mapped to the ECS schema supported by Cloud Security features.
To develop ES and Kibana assets (transforms, ingest pipelines, data views, etc.) required to make the data from Palo Alto Prisma Cloud integration available in the Cloud Security features.
Metadata
Metadata
Assignees
Labels
Category: CDRIntegration:prisma_cloudPalo Alto Prisma CloudPalo Alto Prisma CloudTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]enhancementNew feature or requestNew feature or request