Integrate Palo Alto Networks Wildfire with Zscaler MDR via Email

Prev Next

Palo Alto Networks Wildfire provides critical insights into malicious file behavior. To integrate Palo Alto Networks Wildfire with Zscaler MDR via email, follow the procedure below from beginning to end.

Before connecting to Palo Alto Networks Wildfire to Zscaler MDR, make sure the following configuration requirement is met:

Create a Palo Alto Networks Wildfire user account using the Zscaler MDR email provided in Step 1.7.

Step 1: Zscaler MDR–Create a Zscaler MDR email for alerts

Create a Zscaler MDR provided-email to send Wildfire alerts for ingestion.

  1. In the Zscaler MDR portal, click Integrations. If you do not see the required integration, click See all integrations.

  2. In the search bar, type and then select Palo Alto Networks Wildfire.

  3. Click Configure.

  4. Select a display category.

  5. Under the Ingest Format/Method dropdown, select Palo Alto Networks Wildfire via Email.

    2.png

  6. Click Save Configuration. This will generate the email address you will use to send Palo Alto Wildfire alerts to.

    3.png

  7. Click Edit Configuration.

  8. With your alert source configured, click Activate.

  9. With your Zscaler MDR email generated, log in to Palo Alto Networks Wildfire.

Step 2: Palo Alto Customer Support Portal–Create a Wildfire User account

Create a Wildfire User account to enable Wildfire to send alerts to the Zscaler MDR alert collector.

  1. Login into the Palo Alto customer support portal with your Wildfire admin account.

  2. From the Members dropdown click WildFire Users.

  3. Click Add Wildfire Users.

  4. Enter the Zscaler MDR provided email address.

  5. Click Submit.

  6. Select the wildfire device you want to connect to Zscaler MDR.

    1.1.png

  7. Enter the required information.

  8. Click Submit.

To return to a pre existing integration:

  1. In the Zscaler MDR portal, click Integrations.

  2. Scroll down, and then select your third-party security source.

  3. Click Edit Configuration.

  4. Click View Alerts.

    1.2.png

  5. Click your Alert ID.

    1.3.png

  6. Click the Show original alert dropdown.

    1.4.png

  7. To activate the find command, press Control+F (or Command+F on a Mac).

  8. Type and search for sso.paloaltonetworks.com/welcome.

  9. From the HTML section, copy and save the URL.

    Example: https://sso.paloaltonetworks.com/welcome/testnumber://support.paloaltonetoworks.com/

    1.5.png

  10. To activate your new alert source, copy and paste the URL form Step 3.9 into a new browser window.

  11. Create a new password for your Wildfire account.

  12. Click Create My Account.

Step 4: Palo Alto Networks Wildfire–Configure email alerts

Adjust your Palo Alto Networks Wildfire settings to send generated alerts to your Zscaler MDR-provided email.

  1. Create a Wildfire user account using the Zscaler MDR email provided in Step 1.7.

  2. From your Wildfire dashboard, click Settings.

  3. In the Configure Alerts section, select the types of alerts you want to send Zscaler MDR. We recommend selecting Malware, Grayware, and Phishing as these are the most useful alerts to Zscaler MDR.
    4.png

    Note: If you send Benign alerts, Zscaler MDR will automatically mark them as “not a threat”.

  4. Click Update Notification.