Palo Alto Cortex XSOAR (Pro)
On this page
The Cortex XSOAR connector imports incidents from your XSOAR tenant as findings (Cortex XSOAR). DefectDojo creates a single Record for the tenant.
Prerequisites
An XSOAR API Key, created in the console under Settings > Integrations > API Keys. For Cortex XSOAR 8 / Cortex multi-tenant, also copy the API Key ID (sent as the x-xdr-auth-id header); leave it blank for XSOAR 6.
The key’s Role must grant read access to incidents — used to search incidents. A read-only role is the minimum.
Connector Mappings
- Enter your XSOAR API base URL in the Location field — for a Cortex-hosted tenant this is the FQDN from the API Keys page, for example
https://api-\<your-tenant\>.xsoar.paloaltonetworks.com; for a self-hosted XSOAR use your server’s base URL. - Enter the API Key.
- Optionally, enter the API Key ID (XSOAR 8 / Cortex multi-tenant only).
- Optionally, set a Minimum Severity to limit which findings are imported.
Each XSOAR incident becomes a finding under the tenant Record.