Skip to main content

Prisma Incidents

Overview

Prisma Cloud is the industry’s most comprehensive cloud native security platform (CNSP), with the industry’s broadest security and compliance coverage for users, applications, data, and the entire cloud native technology stack throughout the development lifecycle and across hybrid and multi-cloud environments.

The Prisma Incidents connector fetches the Incidents generated by Prisma Cloud. Prisma Cloud Compute analyzes individual audits and correlates them together to surface unfolding attacks. These chains of related audits are called incidents.

Pre-requisites
  • Username
  • Password
  • Prisma URI
Steps to derive prerequisites:
Configurations

The following are the configurations to forward Prisma Incidents Connector logs to DNIF.‌

image 1-Nov-29-2023-08-56-21-9876-AM

Field Name Description
 Connector Name Enter a name for the connector
 Prisma URI Enter address for Prisma Cloud   Console
 Prisma Username Enter Username/access key ID to   access the API
 Prisma Password  Enter Password/secret key to access the API
  • Click Save after entering all the required details and click Test Connection, to test the configuration.
  • Connection successful message will be displayed on screen along with the time stamp.