IBM Security QRadar SOAR

 View Only
  • 1.  Panorama API Account Permissions

    Posted Mon August 21, 2023 11:17 AM

    Hello,

    I am looking for a list of permissions needed for the API account on the Panorama host so the Panorama App on SOAR will have access to what it needs. Currently, I get an error when testing our configuration stating the location vsys is not available via the API URL. The documentation for this app is not clear and does not state what permissions should be given to the API account. 

    The documentation for this app is listed here: resilient-community-apps/fn_pa_panorama at main · ibmresilient/resilient-community-apps

    GitHub remove preview
    resilient-community-apps/fn_pa_panorama at main · ibmresilient/resilient-community-apps
    Source code for IBM SOAR Apps that are available on our App Exchange - resilient-community-apps/fn_pa_panorama at main · ibmresilient/resilient-community-apps
    View this on GitHub >

    Any help would be greatly appreciated.

    Thank you,

    Connor



    ------------------------------
    Connor Herndon
    ------------------------------


  • 2.  RE: Panorama API Account Permissions

    Posted Thu August 31, 2023 08:34 AM

    The README for the integration regarding the API permissions is shown in the second attached image. 

    When creating a API key on SOAR it would need the permissions shown in the first attached image.



    ------------------------------
    Richard Swierk
    ------------------------------



  • 3.  RE: Panorama API Account Permissions

    Posted Thu August 31, 2023 08:46 AM

    Richard,

    Thank you for sharing. While this is correct information for the API key on SOAR, I need the permissions for the API account on the Panorama side so that SOAR can call the API functions on Panorama. I spoke with a SOAR architect who informed me that this app needs an update and dev is working on it. 

    Best,

    Connor



    ------------------------------
    Connor Herndon
    ------------------------------



  • 4.  RE: Panorama API Account Permissions

    Posted Thu August 31, 2023 09:13 AM

    The Panorama REST API permissions needed are Objects and Network.



    ------------------------------
    Richard Swierk
    ------------------------------



  • 5.  RE: Panorama API Account Permissions

    Posted Tue November 14, 2023 10:35 AM

    HI  Connor,

       Have you resolved this issue and any update when the new updated Version of Panorama app will be available on App Exchange ?

    Thanks

    Muhammad Umer



    ------------------------------
    Muhammad Umer
    ------------------------------



  • 6.  RE: Panorama API Account Permissions

    Posted Thu August 31, 2023 10:16 AM

    Hello Connor,

    The link below will help ;

    https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-panorama-api/get-started-with-the-pan-os-xml-api/get-your-api-key

    The administrator account need roles to be applied to it . see link below on how to  enable API access for an administrator account ;

    https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-panorama-api/get-started-with-the-pan-os-xml-api/enable-api-access

    Thanks,

    Prince.



    ------------------------------
    Prince Amoako
    ------------------------------