Connect Palo Alto Cortex XDR

Elisity integrates with Palo Alto Networks Cortex XDR, an agent-based Endpoint Detection and Response (EDR) platform, as a method to enrich device discovery and identity. Once connected via API, Cloud Control Center pulls endpoint data from Cortex XDR into IdentityGraph for use as Core Effective Attributes when creating policies, enhancing the precision and accuracy of device classification and Policy Group matching.

The connector imports the Cortex XDR endpoint inventory — including hostname, operating system, agent version, isolation status, and tag membership — and makes those attributes available in IdentityGraph and as match criteria for Policy Group definition.

Prerequisites

  • A reachable Palo Alto Cortex XDR tenant.
  • The Cortex XDR API URL for that tenant, in the form https://api-<tenant>.xdr.<region>.paloaltonetworks.com.
  • A Cortex XDR Advanced API key and its matching API Key ID, generated against a role with read-only access to the Cortex XDR endpoint inventory. Step 1 below covers how to create both.
  • Outbound HTTPS connectivity from Cloud Control Center to the Cortex XDR API address. See Platform Connectivity Requirements.

Steps to Connect Palo Alto Cortex XDR

Step 1. Create an Advanced API key in the Cortex console by following the directions below, or by reading the Palo Alto Networks Cortex documentation.

a) Log in to the Cortex console and navigate to Settings > Configurations > Integrations > API Keys, then select + New Key.

b) On the General tab of the Generate API Key page, set Security Level to Advanced. Under Role, select a role with read-only access to the Cortex XDR inventory. Comment and Enable Expiration Date are optional.

NOTE:
The connector requires an Advanced API key. Advanced keys are signed on every request with a nonce and a timestamp to prevent replay. A key generated at the Standard security level fails verification when you add the connector.

NOTE:
If you set an expiration date on the API key, the connector stops returning data once the key expires and its status changes to Inactive. Track the expiration date and update the connector with a new key before it lapses.

c) Confirm the permissions granted by the selected role. The Components panel displays what that role allows. Expand INVENTORY and verify that the inventory components are set to View. The connector only reads endpoint data and never writes to Cortex XDR, so read-only access is sufficient.

NOTE:
Inventory > Agents > Agent Administrations set to View grants the read-only access to the endpoint inventory that the connector uses. Granting View across the remaining Inventory components is also supported and may be simpler to manage. Do not select View/Edit for Agent Administrations. That level exposes endpoint actions such as agent management, malware scans, and pausing protection, none of which the connector uses.

NOTE:
Leave the Scope tab unrestricted. Scoping the API key to a subset of endpoint groups limits the connector to those groups, and devices outside them are not enriched.

d) Select Generate, then copy the API key and select Close. This value is the API Key field in Cloud Control Center.

NOTE:
The API key is displayed only once. Save it to a secure location before closing the window. If the value is lost, generate a new key.

e) Collect the remaining two values that Cloud Control Center requires:

  • API Key ID — the number shown in the ID column for your new key on the API Keys page. This value is not part of the generated key dialog.
  • API URL — the API address of your tenant, in the form https://api-<tenant>.xdr.<region>.paloaltonetworks.com. Select Copy API URL on the API Keys page to copy it.

Step 2. Log into Elisity Cloud Control Center and navigate to IdentityGraph > Connectors, then select the + Add Connector button.

Step 3. A list of tiles slides out from the right side of the screen. Select Configure on the Palo Alto Cortex XDR tile.

Step 4. On the Required Configuration tab of the Add Palo Alto Cortex XDR page, complete the connector fields.

Field Description
Endpoint Name A name that identifies this connector instance, such as Cortex XDR - Corp Endpoints.
API URL The API address of your Cortex XDR tenant, for example https://api-acme.xdr.us.paloaltonetworks.com.
API Key ID The value from the ID column for this key on the Cortex XDR API Keys page, collected in Step 1e.
API Key The Advanced API key value copied from the Cortex console. The value is masked; select the eye icon to display it.
Description Free-form text describing the purpose of this connector instance.

Step 5 (optional). Select the Advanced Settings tab to define Query Exclusion Rules for this connector. These rules can also be changed after the connector exists.

Step 6. Select Add. Cloud Control Center verifies the supplied credentials against the Cortex XDR API before it creates the connector. If verification fails, correct the API URL, API Key ID, or API Key and select Add again.

A tenant can connect more than one Palo Alto Cortex XDR instance — for example, one instance per Cortex XDR tenant or region. Repeat Steps 2 through 6 for each Cortex XDR tenant you want to connect, and give each instance a distinct Endpoint Name. Additional instances appear as endpoints nested beneath the Palo Alto Cortex XDR row in the Connectors list. Select the expand arrow on the row to display them.

Advanced Settings

Two surfaces control how Cloud Control Center queries the Palo Alto Cortex XDR connector and how the data it returns is used. Query Exclusion Rules are configured on the Advanced Settings tab of the connector itself. Connector Data Purging and Trusted Connector are configured in the Global Settings dialog for the connector.

Query Exclusion Rules

Query Exclusion Rules prevent Cloud Control Center from querying the connector for additional details about devices you do not want enriched. To change them after the connector exists, navigate to IdentityGraph > Connectors, locate the Palo Alto Cortex XDR connector, select Edit from the row's Actions (⋮) menu, and open the Advanced Settings tab.

Exclusion Rule Description
Subnet Enable this toggle and select the subnets to exclude. Devices attached from the selected subnets are not queried against Cortex XDR. Up to 100 subnets can be selected.
Virtual Edge Node Enable this toggle and select the Virtual Edge Nodes to exclude. Devices connected through the selected Virtual Edge Nodes are not queried against Cortex XDR. Up to 100 Virtual Edge Nodes can be selected.
Random MAC Enable this toggle to exclude devices that present a randomized MAC address. Randomized addresses are common on mobile, IoT, and BYOD endpoints, and they produce unreliable matches. This option is enabled by default.

Select Save Changes to apply the exclusion rules to the connector.

Global Settings

To open the Global Settings dialog, navigate to IdentityGraph > Connectors, locate the Palo Alto Cortex XDR connector, and select Global Settings from the row's Actions (⋮) menu. The settings below are on the Advanced Settings tab of that dialog.

Setting Description
Connector Data Purging When enabled, Cloud Control Center purges all data learned about a device from this connector if the device is no longer found when querying the connected application. Set the interval between purge events with the Time Period selector, which accepts a value between 1 and 90 days. The connector status changes from Up to Date to Stale if the device is no longer known by the connector but prior to the purge event.
Trusted Connector When enabled, enrichment from this source is set to Trusted for Policy Groups, and the connector is designated an authoritative identity source for Insights.

IdentityGraph also applies an Enrichment Lookback Window to each connector, which controls how recently a device must have been seen online to be eligible for enrichment. To learn more about that setting, review the IdentityGraph article.

Connector Status

The connector status reflects its health and availability based on recent query performance. To ensure accuracy and reduce false positives, the status is determined using a rolling 15-minute evaluation window. The current status is displayed in the Status column of the Connectors list.

Connector Status Levels:

  • Active: Normal operation with minimal query failures.
  • Degraded: Increased query failures detected, but the connector is still operational.
  • Inactive: The connector is unresponsive due to persistent failures.

Failures are defined as unsuccessful query responses, and the platform continuously monitors performance to update the status accordingly. These status changes are visible in the UI, event logs, and notifications pane for better troubleshooting. Email alerts can also be configured for connector status changes. If the connector has not been queried within the evaluation window, the last known status is retained.

Leveraging Palo Alto Cortex XDR with Elisity

When Elisity discovers a new asset on the network and the Palo Alto Cortex XDR connector is active, Cloud Control Center queries Cortex XDR via API for additional device attributes in order to enrich IdentityGraph. This enriched data is displayed on the IdentityGraph tab of the device.

Cortex XDR appears as a source card under KNOWN IN in the Trust Attributes section, and the attributes it contributes are listed on the Palo Alto Cortex XDR source card in the Connectors section. Where Cortex XDR is the source of a Core Effective Attribute, the attribute value is annotated with (Palo Alto Cortex XDR).

The following endpoint attributes are imported from Cortex XDR. Select Show More Attributes to display the full set of values reported for the device.

Attribute Description
Hostname The endpoint name reported by Cortex XDR. Populates the Hostname Core Effective Attribute.
Device Id The unique identifier Cortex XDR assigns to the endpoint.
Agent Version The version of the Cortex XDR agent installed on the endpoint.
Operating System and OS Version The operating system and version reported for the endpoint.
Tags The tags applied to the endpoint in Cortex XDR.
Isolation Status Whether Cortex XDR has isolated the endpoint from the network.
Operational Status The protection state Cortex XDR reports for the endpoint.
Scan Status The state of the most recent Cortex XDR scan of the endpoint.
Prevention Policy and Extensions Policy The Cortex XDR policies applied to the endpoint.
Last Update The time at which Cloud Control Center last refreshed this device's attributes from Cortex XDR.

Devices learned by Elisity before the connector was configured are automatically scheduled for enrichment during the next query cycle, based on their attachment timestamp. To manage enrichment for an individual device, select the options menu on the Cortex XDR source card under Trust Attributes and choose one of the following.

  • Refresh Attributes: Queries Cortex XDR immediately and updates the attributes contributed to this device.
  • Purge Attributes: Removes the attributes this connector contributed to this device.

Attributes imported from Cortex XDR can be used as match criteria in Policy Group definition. To learn more about how to leverage IdentityGraph Core Effective Attributes, review the IdentityGraph article. To learn more about how to leverage IdentityGraph Trust Attributes, review Leveraging Trust Attributes for Policy Group Definition.

Was this article helpful?
0 out of 0 found this helpful