Details

This atomic belongs to the Palo Alto Cortex atomic group.

Restores a quarantined file on one or more endpoints in Palo Alto Cortex. Please refer to the Cortex documentation for information about required licenses and permissions.

Target: Palo Alto Cortex integration target or HTTP Endpoint for "api-your-instance.xdr.region.paloaltonetworks.com" with a path of "/public_api/v1"

Account Key: None if using an integration-provided target, API key and API key ID if using an HTTP Endpoint target

Steps:
[]> Build the authorization headers and request payload
[]> Request the file be restored
[]> Check if the request was successful:
[]> If it was, set the output variable
[]> If it wasn't, output an error

More information about this API: https://cortex-panw.stoplight.io/docs/cortex-xdr/5f2ae37ee7653-restore-file

About
Authorship
Cisco Managed