NetWitness SASE, combined with Palo Alto Networks, provides unprecedented visibility into behavior and communication among devices and services in remote and distributed networks across on-premises, hybrid, and cloud deployments.
What NetWitness SASE does:
-
Minimize costs: Optimize storage and reduce operating costs using new compression algorithms, selective retention, and the ability to split network decoder components to limit what must run in the cloud.
About NetWitness SASE
NetWitness supports SASE and critical hybrid use cases across on-premises and in the cloud by partnering with Palo Alto Networks on technical integrations. NetWitness SASE Integrations give organizations complete visibility into encrypted traffic, remote users, and cloud workloads. With NetWitness SASE integrations, customers can achieve SASE flexibility, inherent security advantages, and complete visibility into threat detection and response.
NetWitness SASE provides the following capabilities:
-
Flexible, secure, real-time traffic monitoring: NetWitness SASE integrations capture all network traffic from remote users in near real-time, enabling immediate response to any potential threats. Regardless of the location of the data collected, the data is available in the detection engine, and analysts can easily find the anomalies. The customization opens available in NetWitness SASE reduce the risk of storing sensitive, personally identifiable information.
-
Get scalable, high-performance cloud security: With NetWitness SASE integrations, enhance total visibility and threat detection capabilities across your enterprise using well-known on-premises mechanisms such as rules, parsers, feeds, and machine learning. Perform searches and investigations and swiftly receive results with a single user interface. The integration supports forensic examinations on triggered detections and facilitates threat hunting against retained network communications, empowering analysts to combat unknown threats effectively.
-
Eliminate blind spots: NetWitness SASE integrations empower organizations to retain complete visibility into their cloud security stack, cost-effectively eliminating blind spots in their cloud traffic and maximizing the effectiveness of their security infrastructure investments. Organizations have the visibility and control they need over encrypted traffic to ensure compliance with their privacy, regulatory, and acceptable use policies, whether on-premises or in the cloud.
NetWitness SASE Integration with Palo Alto Architecture
As hybrid and remote work environments become the norm, Secure Access Service Edge (SASE) has emerged as the gold standard in network technology. It empowers modern workforces to securely access corporate resources from any location. By enabling full packet capture and log monitoring directly on SASE nodes and integrating them with on-premises, cloud, and SaaS sources, the NetWitness Platform ensures enterprise-grade security—regardless of where the data originates. With robust encryption and Zero Trust access baked in, SASE provides significant benefits to today’s distributed organizations.
Historically, network edge security has introduced blind spots for critical security technologies that perform threat detection, analysis, and response. Traditional network and security architectures were not built to handle the current landscape, where data and traffic come from globally distributed sources and thousands of devices. Network managers, accustomed to relying on VPNs and proxies, face new visibility challenges. These legacy solutions increase complexity, drive up costs, and struggle to scale efficiently as demand grows.
The NetWitness Platform SASE integration with Palo Alto Networks addresses these challenges, providing comprehensive visibility into all SASE data streams. SASE converges networking and security services in the cloud to ensure seamless, secure access for users, devices, and applications—anywhere. This architecture not only improves security but also enhances the user experience, empowering organizations to thrive in today’s decentralized work environments.
Configure Palo Alto Prisma Integration
There are two methods to configure Palo Alto Prisma Integration from NetWitness Platform.
Note: NetWitness recommends you to use the Centralized Content Management (CCM) method for a more streamlined deployment process.