Set up Device Security for Cortex XDR API Integration
Focus
Focus
Device Security

Set up Device Security for Cortex XDR API Integration

Table of Contents

Set up Device Security for Cortex XDR API Integration

Integrate Device Security with Cortex XDR directly using an API.
Where Can I Use This?What Do I Need?
  • Device Security (Managed by Strata Cloud Manager)
  • (Legacy) IoT Security (Standalone portal)
One of the following subscriptions:
  • Device Security subscription for an advanced Device Security product (Enterprise, OT, or Medical)
  • Device Security X subscription
To integrate Device Security directly with Cortex XDR, you need to configure the API credentials in the Device Security portal. If you want to integrate with Cortex XDR through Cortex XSOAR, see Set up Device Security and XSOAR for Cortex XDR Integration.
To set up Device Security to integrate with Cortex XDR using the Cortex XDR API, you need the following:
  • An owner or admin role
  • Standard API key for Cortex XDR
  • API key ID
  • URL of your Cortex XDR instance
You can obtain the API key, API key ID, and the URL by following the instructions in Set up Cortex XDR for Integration.
  1. Log in to the Device Security portal and navigate to IntegrationsCortex XDR Integration.
  2. Enable the Cortex XDR integration by selecting the toggle.
  3. Configure the Cortex XDR integration by entering the following:
    • Server URL: Enter the URL of your Cortex XDR instance.
    • API Key ID: Enter the API key ID for your Cortex XDR instance.
    • API Key: Enter the Standard API key for your Cortex XDR instance.
  4. Test and Save your configuration.
    In the Result section, check the Test Connection status. If the test connection failed, check your Cortex XDR URL and API credentials and Test and Save the updated configuration.
    If the test connection succeeded, Device Security begins ingesting device information from Cortex XDR and updating asset information within 24 hours.
  5. Check your Cortex XDR integration run status.
    After Device Security has had time to ingest data from Cortex XDR, you can check the status of the last run in the Result section of IntegrationsCortex XDR Integration. The Result section shows you if the last run succeeded or failed, and the start and end time for the run.
    The last run information does not appear if you have disabled the integration, even if the integration was previously enabled.