This feature isn’t available to all Palo Alto Networks Cortex XCOR users and
might not be visible in your app. For information about enabling this feature in your
environment, contact Cortex XCOR Support.
Create the Azure principal
Configure Azure to allow Cortex XCOR to access metrics in Azure. To do so:-
Ensure the Azure Managed Identity principal is assigned the built-in
Readerrole for every subscription within scope. TheReaderrole is more restrictive than theMonitoringReaderrole. It’s important to create a dedicated Managed Identity to isolate the Azure API quota used by Cortex XCOR. -
Contact Cortex XCOR Support to obtain the
specific
credential_issuerandcredential_subjectfor your tenant. -
Copy both the
credential_issuerandcredential_subjectvariables exactly as specified to allow authentication between your Cortex XCOR tenant and Azure. -
When creating the Azure principal, grant it access to subscriptions using one of
the following options:
- Management group-based: Access can be granted at the Azure Management Group level. This is the preferred approach, as it means that the subscriptions that Cortex XCOR has access to are kept in sync with the management group. As subscriptions are added and removed from the management group, these changes will be automatically reflected in Cortex XCOR. The same principal can also be granted access to multiple management groups.
- Subscription-based: Access can be granted at the subscription level. In this case, the principal is granted access to individual subscriptions. This approach provides the most control, but has the downside that the list of subscriptions granted to the principal must be kept up to date by the customer. Cortex XCOR won’t be able to ingest Azure metric data for subscriptions that haven’t been assigned to the principal.
-
After provisioning the Azure Managed Identity, provide Palo Alto Networks with
the two
Terraform outputs defined in the following examples:
azure_tenant_idandidentity_client_id. These outputs specify the ID of your Azure tenant and the client ID of the Azure Managed Identity, respectively. Cortex XCOR requires both values to complete the integration.
Terraform examples
The following examples show how you can integrate Azure using one of the previously mentioned methods:- Management group
- Individual subscription
The following Terraform code provides an example of how to create an Azure principal
and grant it access to the subscriptions within a management group.
Terraform example
Set up Cortex XCOR to receive Azure data
After configuring Azure to enable access to metrics, you must configure Cortex XCOR to receive and process those metrics. To access the Cortex XCOR API directly, see the Cortex XCOR API for Azure metrics.View Azure metrics integrations
To list or view Azure metrics integrations, use one of the following options:- Chronoctl
- API
To list your Azure metrics integrations using Chronoctl, use
this command:To view a Azure metrics integration, use this command:Replace
SLUG with the unique identifier of the Azure metrics integration.Create or update an Azure metrics integration
You can create or update your Azure metrics integration with Cortex XCOR by applying a configuration file with Chronoctl or Terraform. You must add your account principal to a Cortex XCOR team with SysAdmin permissions.- Chronoctl
- Terraform
- API
To create a Azure metrics integration using Chronoctl, use
this command:Replace Replace
FILENAME with the name of your Chronoctl configuration file.To update a Azure metrics integration, use this command:FILENAME with the name of your Chronoctl configuration file.The input file uses the following structure:Chronoctl example
NAME: (string) The name of the Azure integration.SLUG: (string) The unique identifier of the Azure integration.TENANT_ID: (UUID) The ID of the Azure tenant that hosts the managed identity principal.CLIENT_ID: (UUID) The OAuth 2.0 client ID of the managed identity principal.RESOURCE_TYPE_NAME: (string) Name of the resource type.METRIC_NAME: (list(string)) List of metric names to be targeted. These apply to this resource type. Leave unset to retrieve all metrics.LOCATION: (list(string)) Locations to be ingested for this integration. Applies to all subscriptions. Leave unset to retrieve all locations.SUBSCRIPTION_ID: (list(string)) Subscriptions to be targeted for this integration. Leave unset to retrieve all subscriptions.USAGE_METRICS_ENABLED: (Boolean) Enables collection of azure usage metrics under this principal (Microsoft.Compute,Microsoft.Network,Microsoft.Storage).COUNT_METRICS_ENABLED: (Boolean) Enables Azure count metrics for the configured resources.PROPAGATE_TAGS: (Boolean) Specifies whether Azure resource, group, and subscription tags should be propagated as metric labels.
Delete an Azure integration
Delete an Azure integration using one of the following methods:- Chronoctl
- API
Metric information
Cortex XCOR ingests a wide range of Azure metrics. See the list of available Azure metrics.Metrics availability
Azure metrics are displayed in Cortex XCOR with a several minute delay from their timestamps in Azure. On average, delays range anywhere from five minutes for most metrics to 10 minutes for very high cardinality metrics. These delays are caused by a number of factors external to Cortex XCOR, including each metric’s scrape interval and latency within Azure. To accommodate these delays, use the PromQLoffset modifier
to add offsets to your monitors.
Additionally, delays can impact aggregation rules, and it might not be possible
to aggregate metrics with particularly long delays.
Metric labels
You can request custom labels for your Azure metrics asdefaultLabels. To add
custom labels, contact Cortex XCOR Support.
When importing metrics, some defaultLabels might conflict with prefixes which
already exist in Cortex XCOR (for example, job). When this occurs,
Cortex XCOR adds the prefix exported_ to the source labels to prevent
conflicts.
Find Azure metrics in Metrics Explorer
Use Metrics Explorer to find and review the status of your ingested metrics.-
All Azure metrics start with the prefix
azure_. Search for this prefix to display all Azure metrics in the platform. -
Search supports substrings. For example, if the original Azure metric name
contains a substring like
storageAccounts, searching for the substring returns the Azure metric, along with other metrics containing the substring.