Push Security Logs

Connecting Push Security logs in your Panther Console

Overview

Panther ingests Push Securityarrow-up-right logs by configuring a webhook to post events to a Panther HTTP source.

How to onboard Push Security logs to Panther

Step 1: Create a Push Security source in Panther

  1. In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for “Push Security,” then click its tile.

    • In the slide-out panel, the Transport Mechanism dropdown in the upper-right corner will be pre-populated with the HTTP option.

  4. Click Start Setup.

    An arrow is drawn from a tile labeled "Push Security" in the background to a "Start Setup" button in the foreground.
  5. Follow Panther's instructions for configuring an HTTP Source.

After creating the HTTP source, the Panther Console will display your HTTP Source URL—store this and the Secret Key Value in a secure location, as you will need them in the next step.

Step 2: Create a new webhook in Push Security

Panther-managed detections

See Panther-managedarrow-up-right rules for Push Security in the panther-analysis GitHub repositoryarrow-up-right.

Supported log types

PushSecurity.Activity

PushSecurity.Controls

PushSecurity.Entities

Last updated

Was this helpful?