Integrate Palo Alto Networks Wildfire with Red Canary via Email
    • 24 Jul 2024
    • 2 Minutes to read
    • PDF

    Integrate Palo Alto Networks Wildfire with Red Canary via Email

    • PDF

    Article summary

    Palo Alto Networks Wildfire provides critical insights into malicious file behavior. To integrate Palo Alto Networks Wildfire with Red Canary via email, follow the procedure below from beginning to end.

    Before connecting to Palo Alto Networks Wildfire to Red Canary, make sure the following configuration requirement is met:

    Create a Palo Alto Networks Wildfire user account using the Red Canary email provided in Step 1.7.

    Step 1: Red Canary–Create a Red Canary email for alerts

    Create a Red Canary provided-email to send Wildfire alerts for ingestion.

    1. From your Red Canary homepage, click Integrations. If you do not see the required integration, click See all integrations.

    2. In the search bar, type and then select Palo Alto Networks Wildfire.

    3. Click Configure.

    4. Select a display category.

    5. Under the Ingest Format/Method dropdown, select Palo Alto Networks Wildfire via Email.

      2.png

    6. Click Save Configuration. This will generate the email address you will use to send Palo Alto Wildfire alerts to.

      3.png

    7. Click Edit Configuration.

    8. With your alert source configured, click Activate.

    9. With your Red Canary email generated, log in to Palo Alto Networks Wildfire.

    Step 2: Palo Alto Customer Support Portal–Create a Wildfire User account

    Create a Wildfire User account to enable Wildfire to send alerts to the Red Canary alert collector.

    1. Login into the Palo Alto customer support portal with your Wildfire admin account.

    2. From the Members dropdown click WildFire Users.

    3. Click Add Wildfire Users.

    4. Enter the Red Canary provided email address.

    5. Click Submit.

    6. Select the wildfire device you want to connect to Red Canary.

      1.1.png

    7. Enter the required information.

    8. Click Submit.

    Step 3: Red Canary–Retrieve your Wildfire activation link 

    To return to a pre existing integration:

    1. From your Red Canary homepage, click Integrations.

    2. Scroll down, and then select your third-party security source.

    3. Click Edit Configuration.

    4. Click View Alerts.

      1.2.png

    5. Click your Alert ID.

      1.3.png

    6. Click the Show original alert dropdown.

      1.4.png

    7. To activate the find command, press Control+F (or Command+F on a Mac).

    8. Type and search for sso.paloaltonetworks.com/welcome.

    9. From the HTML section, copy and save the URL.

      Example: https://sso.paloaltonetworks.com/welcome/testnumber://support.paloaltonetoworks.com/

      1.5.png

    10. To activate your new alert source, copy and paste the URL form Step 3.9 into a new browser window.

    11. Create a new password for your Wildfire account.

    12. Click Create My Account.

    Step 4: Palo Alto Networks Wildfire–Configure email alerts

    Adjust your Palo Alto Networks Wildfire settings to send generated alerts to your Red Canary-provided email.

    1. Create a Wildfire user account using the Red Canary email provided in Step 1.7.

    2. From your Wildfire dashboard, click Settings.

    3. In the Configure Alerts section, select the types of alerts you want to send Red Canary. We recommend selecting Malware, Grayware, and Phishing as these are the most useful alerts to Red Canary.
      4.png

      Note: If you send Benign alerts, Red Canary will automatically mark them as “not a threat”.

    4. Click Update Notification.


    Was this article helpful?