Prisma Cloud

Version: 1.2
Updated: Nov 09, 2023
Receive alerts from Prisma Cloud CSPM and perform configuration searches to retrieve resource information, identify misconfigurations, gain operational insights and uncover policy and compliance violations.
Actions
- Get Alert Details (Enrichment) - Returns information about an alert for the specified ID.
- List Alert Filters (Enrichment) - Returns a list of all valid filters.
- List Alerts (Enrichment) - Returns a list of alerts from the Prisma Cloud Platform that matches the specified filters.
- Search Config (Enrichment) - Returns the result of a RQL config query.
Prisma Cloud configuration
Prisma Cloud requires an API access key to enable programmatic access to the REST API. By default, only the System Admin has API access and can enable API access for other administrators. To generate an access key, see Create and Manage Access Keys.
Configure Prisma Cloud in Automation Service and Cloud SOAR
Before you can use the integration, you must configure it so that the vendor can communicate with Sumo Logic. For general guidance, see Configure Authentication for Integrations.
- Access App Central and install the integration.
- Select the installed integration in the Integrations page.
Classic UI. In the main Sumo Logic menu, select Automation and then select Integrations in the left nav bar.
New UI. In the main Sumo Logic menu, select Automation > Integrations. You can also click the Go To... menu at the top of the screen and select Integrations. - Select the integration.
- Hover over the resource name and click the Edit button that appears.
- In the Add Resource dialog, enter the authentication needed by the resource. When done, click TEST to test the configuration, and click SAVE to save the configuration.
For information about Prisma Cloud, see Prisma Cloud documentation.
Category
Cloud Security Posture Management
Change Log
- November 9, 2023 - First upload