↳ GitHub sourceConnector

Palo Alto Cortex Xpanse (via Codeless Connector Framework)

Description

The Palo Alto Cortex Xpanse data connector ingests alerts data into Microsoft Sentinel.
Declared status
1
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

To ingest data from Palo Alto Cortex Xpanse to Microsoft Sentinel, click on **Add Domain**. Fill in the required details in the pop-up and click Connect. You will see connected domain endpoints in the grid below. To get the Auth ID and API Key, go to **Settings → Configuration → Integrations → API Keys** in the Cortex Xpanse portal and generate new credentials.
Add domain
Add domain
Domain Name
Enter the domain suffix to be used in the API endpoint, e.g., `example.crtx.us.paloaltonetworks.com`
API Key
Xpanse Auth ID
Connect Palo Alto Xpanse to Microsoft Sentinel

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
PaloAltoExpanseCCPDefinition
Additional source files 2Solutions/Palo Alto Cortex Xpanse CCF/Data Connectors/CortexXpanse_ccp/CortexXpanse_ConnectorDefinition.jsonsource ↗Solutions/Palo Alto Cortex Xpanse CCF/Data/Solution_CortexXpanse.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.