AlienVault® USM Anywhere™

Configuring the AlienApp for Palo Alto Networks

Role Availability Read-Only Analyst Manager

When the AlienApp for Palo Alto Networks is enabled and connected to your Palo Alto Networks environment, you can launch app actions and create orchestration rules to send data from USM Anywhere to your Palo Alto device. See AlienApp for Palo Alto Networks Orchestration for more information about the orchestration actions supported by the AlienApp for Palo Alto Networks.

Note: To fully integrate USM Anywhere with your Palo Alto Networks device, you should also have the Palo Alto Networks PAN-OS log collection enabled so that USM Anywhere can retrieve and normalizeNormalization describes the translation of log file entries received from disparate types of monitored assets into the standardized framework of Event types and sub-types. the raw log data. See Collecting Logs from Palo Alto Networks for more information about enabling this raw log data retrieval.

Palo Alto Dynamic Address Groups

To Configure PAN-OS to be able to use Tags from USM Anywhere to add addresses to Dynamic Address Groups

The Dynamic Address Groups in PAN-OS allow you to group addresses by using a tag as an identifier to denote the alarm of product of a rule will be added to that Dynamic Address Group.

To allow for PAN-OS to autoimatically associate the tags you create in USM Anywhere with the PAN-OS Dynamic Address Groups, you first need to configure Dynamic Adress Groups in your policy.