Skip to content

playbook palo alto xsiam use case documentation#2461

Merged
CharlesLR-sekoia merged 3 commits intomainfrom
palo_alto_xsiam
Nov 4, 2025
Merged

playbook palo alto xsiam use case documentation#2461
CharlesLR-sekoia merged 3 commits intomainfrom
palo_alto_xsiam

Conversation

@CharlesLR-sekoia
Copy link
Contributor

No description provided.

@github-actions
Copy link

github-actions bot commented Jul 23, 2025

Pull request was merged, preview was removed.

@CharlesLR-sekoia CharlesLR-sekoia changed the title first_version_for_review playbook palo alto xsiam use case documentation Oct 31, 2025
@squioc squioc requested a review from Copilot November 4, 2025 11:36
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds documentation for integrating Sekoia.io IOCs with Palo Alto XSIAM. The PR includes:

  • A new navigation entry in mkdocs.yml for the XSIAM integration page
  • Documentation file explaining how to push Sekoia.io IOCs to XSIAM Collection via playbooks
  • Supporting PNG images showing the workflow and configuration screens

Reviewed Changes

Copilot reviewed 2 out of 10 changed files in this pull request and generated 3 comments.

File Description
mkdocs.yml Adds navigation entry for PaloAlto Cortex XSIAM integration documentation
_shared_content/intelligence_center/integrations/paloalto_xsiam.md Complete integration guide with setup instructions, playbook configuration, and examples
docs/assets/intelligence_center/XSIAM/xsiam_playbook_workflow.png Workflow diagram image (binary file)
docs/assets/intelligence_center/XSIAM/xsiam_override_reliability.png Configuration screenshot image (binary file)

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

- **Configuration**:
- **Batch Size Limit**: `200`
- **Feed ID**: Paste the Feed ID from step 1 (e.g. `feed--xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx`).
- **Modified After**: an RFC-3339 timestamp (e.g. `2025-06-12T23:20:50.52Z`). We recommend to start with a week of history to avoid disruption of SOC Analysts processes.
Copy link

Copilot AI Nov 4, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Corrected spelling of 'Analysts' to 'Analyst' in 'SOC Analyst processes'.

Suggested change
- **Modified After**: an RFC-3339 timestamp (e.g. `2025-06-12T23:20:50.52Z`). We recommend to start with a week of history to avoid disruption of SOC Analysts processes.
- **Modified After**: an RFC-3339 timestamp (e.g. `2025-06-12T23:20:50.52Z`). We recommend to start with a week of history to avoid disruption of SOC Analyst processes.

Copilot uses AI. Check for mistakes.
| class_override | `{id}` | Open string, ≤36 characters |
| comment | `Valid from {valid_from} AND STIX Pattern: {pattern}` | Free text |
| severity_mapping | this field is *empty* but is applying the mapping explained in section **3.2.2.Severity mapping** | Use any of: LOW, MEDIUM, HIGH, CRITICAL, INFO |
| reliability_mapping | this field is *empty* but is applying the mapping explained in section **3.2.4.Reliabilit** | Use any of: A, B, C, D, E, F, G |
Copy link

Copilot AI Nov 4, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Corrected incomplete word 'Reliabilit' to 'Reliability' in section reference.

Suggested change
| reliability_mapping | this field is *empty* but is applying the mapping explained in section **3.2.4.Reliabilit** | Use any of: A, B, C, D, E, F, G |
| reliability_mapping | this field is *empty* but is applying the mapping explained in section **3.2.4.Reliability** | Use any of: A, B, C, D, E, F, G |

Copilot uses AI. Check for mistakes.

**Examples**

- Force all severities to LOW (i.e. all Confidence values highier than 0 will be traduced in "LOW"):
Copy link

Copilot AI Nov 4, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Corrected spelling of 'highier' to 'higher' and 'traduced' to 'translated'.

Suggested change
- Force all severities to LOW (i.e. all Confidence values highier than 0 will be traduced in "LOW"):
- Force all severities to LOW (i.e. all Confidence values higher than 0 will be translated into "LOW"):

Copilot uses AI. Check for mistakes.
Copy link
Contributor

@squioc squioc left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

I also validated this PR , but it seems that my approval is not enough :/

@CharlesLR-sekoia CharlesLR-sekoia merged commit ebe5a6a into main Nov 4, 2025
7 checks passed
@CharlesLR-sekoia CharlesLR-sekoia deleted the palo_alto_xsiam branch November 4, 2025 11:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants