Palo Alto Networks
Advanced Industrial Threat Defense with Nozomi Networks & Palo Alto Networks

Bring Nozomi Networks’ deep OT/IoT/IT visibility into Palo Alto Networks Cortex XSOAR to accelerate SecOps for critical infrastructure. The Nozomi Networks integration pack for Cortex XSOAR/XSIAM available in the Cortex Marketplace ingests Nozomi alerts and assets, synchronizes incidents, and lets analysts trigger lifecycle actions directly from playbooks in Palo Alto Networks XSOAR —so investigations move faster with rich industrial context.

Features
Incident Synchronization and Closed-Loop Actions
Automatically fetch and continuously sync incidents from Nozomi into Cortex XSOAR. Close incidents in Nozomi from XSOAR (e.g., as "change" or "security") to maintain a single source of truth across teams.
Asset & Context Enrichment for Playbooks
Enrich investigations with Nozomi asset data and entity queries—including quick lookups like “find IP by MAC”—to add precise OT/IoT context to detections and responses.
Built for Reliability at Scale
Recent updates add robust pagination (by record timestamps), configurable fetch sizes, proxy support, and improved error handling—reducing the chance of missed events in busy OT networks.