Install and Configure
Install and configure Palo Alto Networks XSIAM integration for Security Operations application from the ServiceNow Store on your ServiceNow AI Platform® instance.
Before you begin
Role required: sn_si.admin, sn_si.ingestion_profile_admin
Note: Users with the sn_si.admin role can perform all operations available to a profile admin because this role inherits the required permissions by default.
Procedure
Download Security Incident Response Integration with Palo Alto Networks XSIAM integration from the ServiceNow® Store and install it.
Navigate to All > Security Operations > Integrations > Integration Configurations.
Search for Security Incident Response Integration with Palo Alto Networks XSIAM tile, and select Configure.
On the form, fill in the fields.
| Field | Description |
|---|---|
| Name | Name of the Cortex XSIAM integration. |
| Authorization Key | Secret API key to authenticate XSIAM API requests. The Authorization Key should have Instance Administrator role. |
| Key ID | API key ID associated with the authorization key. |
| API URL | URL of the XSIAM tenant. |
Select Submit.
The configured integration tile displays.