Objective: Retrieve the latest version of SentinelOne's AI-SIEM project so you can access dashboard and parser templates locally.
Ctrl+Shift+P (Windows) or Cmd+Shift+P (macOS)https://github.com/Sentinel-One/ai-siem.gitđĄ Tip: Periodically run git pull to fetch updates from the repository.
âšī¸ Alternative: Use GitHub CLI: gh repo clone sentinel-one/ai-siem
Objective: Find and copy the JSON configuration for the Palo Alto firewall OCSF dashboard within the cloned repository.
dashboards â communitypalo_firewall_ocsf-latestmetadata.yaml - Prerequisites and metadatapalo_firewall_ocsf.conf - Dashboard configurationpalo_firewall_ocsf.confCtrl+A (or Cmd+A)Ctrl+C (or Cmd+C)đĄ Tip: Keep the content on your clipboard for the next step.
â ī¸ Important: Copy only the content between the curly braces { }.
Objective: Create a new dashboard in the Singularity console and paste the Palo Alto OCSF configuration.
Palo Alto Firewall OCSFđĄ Tip: Look for JSON editor under ⯠menu or > JSON tab.
â ī¸ Note: Ensure no extra characters at beginning or end of JSON.