Integrate Prisma Cloud with PagerDuty
Learn how to integrate Prisma® Cloud with PagerDuty to see alerts in your service or application.
Integrate Prisma® Cloud with PagerDuty to aid alerting, on-call scheduling, escalation policies, and incident tracking to increase uptime of your apps, servers, websites, and databases. When integrated, Prisma Cloud sends alerts to the PagerDuty service, notifying your incident response teams to investigate and remediate security incidents.
Create a new service in PagerDuty and get the integration key.
Log in to PagerDuty.
Click Services > Service Directory and create a + New Service.

Complete the Create a Service form.
Enter a Name, Description, and click Next.

Generate a new escalation policy or select an existing policy to the service and click Next.

Set the Alert Grouping options as you need and click Next.

Select the Events API V2 integration.

Click Create Service.
After creating a new service, you will be directed to its Integrations page.
Copy and save the Integration Key.
You will need to enter this integration key while setting up PagerDuty integration on Prisma Cloud.

For more information about integrations with PagerDuty, see PagerDuty Documentation.
Set up PagerDuty as an integration channel on Prisma Cloud.
Log in to Prisma Cloud.
Select Settings > Integrations & Notifications > Integrations.
Select Add Integration > Pager Duty from the list.
Enter the Integration Name and an optional Description.
Enter the Integration Key that you had saved while creating your PagerDuty service.

Click Next, review the Summary, and then Test Integration.

Save Integration after the testing is successful.
Prisma Cloud creates a test incident and sends it to your service in PagerDuty. To ensure that integration is successful, look for the test integration in your PagerDuty Service.

Modify an existing alert rule or create a new alert rule to send alert notifications to PagerDuty.
View Prisma Cloud in PagerDuty.
In PagerDuty, all the open alerts display the Incident State as Triggered and all the resolved alerts display the Incident State as Resolved.

Last updated
Was this helpful?

