> For the complete documentation index, see [llms.txt](https://docs.onum.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.onum.com/listeners/listener-integrations/pull-data-from-http-endpoints/pull-data-from-palo-alto-networks-apis/pull-data-from-the-prisma-cloud-api.md).

# Pull data from the Prisma Cloud API

## Overview

Get a list of audit logs through the [Prisma Cloud Security API](https://pan.dev/prisma-cloud/api/cspm/get-audit-logs/) using the **HTTP Pull** Listener.

## HTTP Pull Listener configuration

In Falcon Onum, go to the **Listeners** area and click **New Listener > HTTP Pull**. Give a name to your new Listener and enter the following data:

### Parameters

Add the following parameter:

* **Name** - `PrismaCloudEndpoint`
* **Value** - Enter your Prisma Cloud URL.

### Secrets

You must define these credentials in Onum:

* `PrismaCloudAccessKeyId` will reference your Prisma Cloud Access Key ID.
* `PrismaCloudAccessKeySecret` will reference your Prisma Cloud Secret Key.

To do it, click **Add element** and enter a **Name** for the secret (in this case, `PrismaCloudAccessKeyId`). Then, click the **Value** field and select **New secret** to create a new one:

* Give the secret a **Name**.
* Turn off the **Expiration date** option.
* Click **Add new value** and paste the secret corresponding to the value.
* Click **Save**.

You can now select the secret you just created in the **Value** field list. Repeat the process for the `PrismaCloudAccessKeySecret`.

{% hint style="info" %}
Learn more about secrets in Onum in [this article](/settings/organization-settings/secrets-management.md).
{% endhint %}

### Setup

After entering the required parameters and secrets, you can choose to manually enter the rest of configuration fields, or simply paste the given YAML:

{% tabs %}
{% tab title="Config as YAML" %}
Toggle **ON** the **Config as YAML** option to enable a free text field where you can paste the following YAML:

```yaml
withTemporalWindow: true
temporalWindow:
  duration: 5m
  offset: 5m
  tz: UTC
  format: Epoch
withAuthentication: true
authentication:
  type: "token"
  token:
    request:
      method: POST
      url: "${parameters.PrismaCloudEndpoint}/login"
      headers:
        - name: Content-Type
          value: application/json
      bodyType: raw
      bodyRaw: |
        {
          "username": "${secrets.PrismaCloudAccessKeyId}",
          "password": "${secrets.PrismaCloudAccessKeySecret}"
        }
      responseType: json
    tokenPath: ".token"
    authInjection:
      name: "Authorization"
      in: "header"
      prefix: "Bearer "
withEnumerationPhase: false
collectionPhase:
  paginationType: "cursor"
  cursorSelector: ".nextPageToken"
  initialRequest:
    method: POST
    url: "${parameters.PrismaCloudEndpoint}/audit/api/v1/log"
    headers:
      - name: Accept
        value: application/json
      - name: Content-Type
        value: application/json
    responseType: json
    bodyType: raw
    bodyRaw: |
      {
        "timeRange": {
          "type": "absolute",
          "value": {
            "startTime": ${temporalWindow.from},
            "endTime": ${temporalWindow.to},
          }
        }
      }
  nextRequest:
    method: POST
    url: "{parameters.PrismaCloudEndpoint}/audit/api/v1/log"
    headers:
      - name: Accept
        value: application/json
      - name: Content-Type
        value: application/json
    responseType: json
    bodyType: raw
    bodyRaw: |
      {
        "timeRange": {
          "type": "absolute",
          "value": {
            "startTime": ${temporalWindow.from},
            "endTime": ${temporalWindow.to},
          }
        },
        "nextPageToken": ${pagination.cursor}
      }
  output:
    select: ".value"
    map: "."
    outputMode: element 
```

{% endtab %}

{% tab title="Manually configure" %}
**Temporal Window**

Toggle **ON** to add a temporal window for events. This repeatedly shifts the time window over which data is collected.

* **Duration**<mark style="color:$primary;">**\***</mark> - `5m`
* **Offset**<mark style="color:$primary;">**\***</mark> - `5m`
* **Format**<mark style="color:$primary;">**\***</mark> - `UTC`

**Authentication**

Toggle **ON** and enter the following:

* **Type**<mark style="color:$primary;">**\***</mark> - `Token`
* **Token Retrieve Based Authentication**
  * **Request**
    * **Method**<mark style="color:$primary;">**\***</mark> - `POST`
    * **Url**<mark style="color:$primary;">**\***</mark> - `${parameters.PrismaCloudEndpoint}/login${parameters.PrismaCloudEndpoint}/login`
    * **Headers**
      * **Name** - `Content-Type`
      * **Value** - `application/json`
    * **Body Type**<mark style="color:$primary;">**\***</mark> - `Raw`
    * **Body Content**<mark style="color:$primary;">**\***</mark>

```
{
  "username": "${secrets.PrismaCloudAccessKeyId}",
  "password": "${secrets.PrismaCloudAccessKeySecret}"
}
```

* **Token path**<mark style="color:$primary;">**\***</mark> - `.token`
* **Auth Injection**
  * **In**<mark style="color:$primary;">**\***</mark> - `Authorization`
  * **Name**<mark style="color:$primary;">**\***</mark> - `Header`
  * **Prefix** - `"Bearer "`

**Collection Phase**

* **Pagination Type**<mark style="color:$primary;">**\***</mark> - `Cursor`
* **Cursor Selector**<mark style="color:$primary;">**\***</mark> - `.nextPageToken`
* **Initial Request**&#x20;
  * **Response Type**<mark style="color:$primary;">**\***</mark> - `JSON`
  * **Method**<mark style="color:red;">**\***</mark> - `POST`
  * **URL**<mark style="color:red;">**\***</mark> - `${parameters.PrismaCloudEndpoint}/audit/api/v1/log`
* **Headers**
  * **Name** - `Accept`
  * **Value** - `application/json`
  * **Name** - `Content-Type`
  * **Value** - `application/json`
* **Body Type**<mark style="color:$primary;">**\***</mark> - `Raw`
* **Body Content**<mark style="color:$primary;">**\***</mark>

```
{
  "timeRange": {
    "type": "absolute",
    "value": {
      "startTime": ${temporalWindow.from},
      "endTime": ${temporalWindow.to},
    }
  }
}
```

* **Next Request**&#x20;

  * **Response Type**<mark style="color:$primary;">**\***</mark> - `JSON`
  * **Method**<mark style="color:red;">**\***</mark> - `POST`
  * **URL**<mark style="color:red;">**\***</mark> - `${parameters.PrismaCloudEndpoint}/audit/api/v1/log`
  * **Headers**
    * **Name** - `Accept`
    * **Value** - `application/json`
    * **Name** - `Content-Type`
    * **Value** - `application/json`
  * **Body Type**<mark style="color:$primary;">**\***</mark> - `Raw`
  * **Body Content**<mark style="color:$primary;">**\***</mark>

  ```
  {
    "timeRange": {
      "type": "absolute",
      "value": {
        "startTime": ${temporalWindow.from},
        "endTime": ${temporalWindow.to},
      }
    },
    "nextPageToken": ${pagination.cursor}
  }
  ```
* **Output**&#x20;
  * **Select**<mark style="color:$primary;">**\***</mark> - `.value`
  * **Map** - `.`
  * **Output Mode**<mark style="color:$primary;">**\***</mark> - `element`
    {% endtab %}
    {% endtabs %}

When you're done, click **Create labels** to move on to the next step and define the required [Labels](https://app.gitbook.com/o/9sm794iTBacZSmhxRER6/s/kxZeV4nlXcIAjMGZxzLI/the-workspace/listeners/labels) if needed.
