↳ GitHub sourceConnector
Palo Alto Cortex Xpanse (via Codeless Connector Framework)
Description
The Palo Alto Cortex Xpanse data connector ingests alerts data into Microsoft Sentinel.
- Declared status
- 1
- Declared author / publisher
- Microsoft
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
Read and Write permissions are required.
Workspace
Workspace
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
To ingest data from Palo Alto Cortex Xpanse to Microsoft Sentinel, click on **Add Domain**. Fill in the required details in the pop-up and click Connect. You will see connected domain endpoints in the grid below. To get the Auth ID and API Key, go to **Settings → Configuration → Integrations → API Keys** in the Cortex Xpanse portal and generate new credentials.
Add domain
Add domain
Domain Name
Enter the domain suffix to be used in the API endpoint, e.g., `example.crtx.us.paloaltonetworks.com`
API Key
Xpanse Auth ID
Connect Palo Alto Xpanse to Microsoft Sentinel
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
629d1d3↗- Source identifier
PaloAltoExpanseCCPDefinition
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC