About
Firewall alerts are often investigated separately from endpoint and identity activity, forcing security teams to switch between consoles and manually connect related events.
The Heimdal Palo Alto integration ingests, normalizes, and enriches relevant IPS and IDS alerts, making them available within the Threat-hunting and Action Center. Analysts can correlate network activity with EDR and ITDR signals, gain broader visibility across the attack surface, and manage investigations from a single interface.
Features
Streamlined integration setup
Connect Palo Alto to the Heimdal platform using the firewall’s API URL and credentials, with built-in connection testing before activation.
Firewall alerts in TAC
Review Critical and High Palo Alto IPS and IDS alerts under the dedicated External Firewall tab.
Aggregated and individual alerts
Group repeated alerts using a Hits count or inspect each notification separately, including its complete raw JSON log.
Investigation and response actions
Investigate, resolve, or exclude firewall alerts directly from TAC, including every alert contained within an aggregated group.
Globe and Map visibility
Visualize devices associated with Palo Alto alerts using source IP geolocation.
Granular firewall exclusions
Create temporary or permanent exclusion rules using primary and optional secondary criteria, managed from a centralized grid.
Benefits
Unified security visibility
Bring network, endpoint, and identity activity together for more complete threat investigations.
Reduced alert noise
Focus analysts on higher-priority firewall events while suppressing recurring or irrelevant notifications.
Faster investigations
Review alert context and take action without switching between separate security consoles.
Improved operational efficiency
Centralize firewall monitoring, investigation, response, and exclusion management within Heimdal.
Broader MXDR coverage
Extend Heimdal’s detection and response capabilities beyond endpoints and identities into the network layer.
Unify Your Security Operations with Heimdal
Connect Palo Alto firewall telemetry with Heimdal’s endpoint and identity security capabilities to investigate threats faster, reduce operational complexity, and respond with greater context.