Skip to main content

Cloud ConnectorsExabeam Cloud Connectors Configuration Guide

Table of Contents

Palo Alto Networks SaaS Security Cloud Connector

Palo Alto Networks’ security platform SaaS Security  (formerly known as Prisma SaaS or Aperture) is a cloud access security broker (CASB) service that helps secure and govern SaaS applications and prevent breaches and non-compliance. SaaS Security provides advanced data protection, consistency across applications, malware protection, user activity monitoring, data loss prevention, compliance assurance, data governance, and advanced threat prevention. For more information, see the SaaS Security documentation.

Prerequisites to Configure the Palo Alto Networks SaaS Security Cloud Connector

Before you configure the Palo Alto Networks SaaS Security connector you must complete the following prerequisites:

  • Obtain the client ID

  • Obtain the client secret

Obtain the Client ID and Client Secret

Palo Alto Networks SaaS Security APIs are authenticated via API client ID and client secret. You must obtain the API client ID and client secret to use while configuring the  SaaS Security connector.

To obtain an application key and client ID:

  1. Log in to  SaaS Security console as an administrator.

  2. Navigate to Settings > External Service.

  3. Click Add Client App to register an API client.

  4. Specify a name for the API client.

  5. Click Save. SaaS Security displays a client ID and a client secret.

    1. The value for a client secret appears in a pop-up only once. If you close the pop-up and lose the key value, you must regenerate the value. For more information, see the SaaS Security documentation.

    2. Record the values for a client ID and a client secret, represented by letters and numbers. Use the values to authenticate the API client while configuring the SaaS Security connector on the Exabeam Cloud Connector platform.

Configure the Palo Alto Networks SaaS Security Cloud Connector

Palo Alto Networks SaaS Security (formerly known as Prisma SaaS or Aperture) is a cloud access security broker (CASB) service that helps secure and govern SaaS applications and prevent breaches and non-compliance. SaaS Security provides advanced data protection, consistency across applications, malware protection, user activity monitoring, data loss prevention, compliance assurance, data governance, and advanced threat prevention. For more information, see the SaaS Security documentation.

The following table displays audit source API and security events supported by the connector.

Audit Source: API

Service or Module Covered

Events Included

Log Events

Any

All

Table 22. Audit source API and security events supported by the connector


To configure the SaaS Security connector to import data into the Exabeam Cloud Connector platform:

  1. Complete the Prerequisites to Configure the Palo Alto Networks SaaS Security Cloud Connector.

  2. Log in to the Exabeam Cloud Connectors platform with your registered credentials.

  3. Navigate to Settings > Accounts > Add Account.

  4. Click Select Service to Add, then select Palo Alto Aperture Palo Alto Networks from the list.

  5. In the Accounts section, enter the required information. Required fields are indicated with a red bar.

    1. Account Name – Specify a name for the Palo Alto Networks SaaS Security connector. For example, Corporate SaaS Security  CASB.

    2. (Optional) Description – Describe the SaaS Security connector. For example, Cloud access security broker service.

    3. Client ID – Enter the client ID that you obtained while completing prerequisites.

    4. Client Secret – Enter the client secret that you obtained while completing prerequisites.

  6. To confirm that the Exabeam Cloud Connector platform communicates with the service, click Test Connection.

  7. Click Done to save your changes. The cloud connector is now set up on the Exabeam Cloud Connector platform.

  8. To ensure that the connector is ready to send and collect data, Start the connector and check that the status shows OK.