The Cortex XDR integration enables you to scan endpoints, upload IOCs, manage incidents, and validate API keys as part of Torq workflows.
Create an XDR API key
When you create an XDR API key, you'll need to copy and save several items that you'll need later to configure an XDR integration in Torq.
API key
API key ID
Cortex XDR URL
In your XDR portal, go to Settings > Configurations.
Expand the configuration panel, go to Integrations > API Keys, and click the + New Key button.
Configure the API key and click Save. Make sure you copy the API key and save it.
In the table, locate the API key you created and make note of the ID.
In the top-right corner, click Copy URL.
Create a Cortex XDR Integration in Torq
Go to Build > Integrations > Steps > Cortex XDR and click Add.
Fill in the fields with the values you copied earlier.
Integration name
Cortex XDR API Key
Cortex XDR API ID
Cortex XDR Base URL (https://api-fqdn) for example: https://api-.xdr.us.paloaltonetworks.com