---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Palo Alto Networks - AutoFocus integration

# Palo Alto Networks - AutoFocus
integration {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Palo Alto Networks - AutoFocus
integration base system includes a workflow and a series of workflow activities you can use to
integrate Palo Alto Networks - AutoFocus with your
instance.

|-|-|
| Explore [Security Incident Response integrations](https://www.servicenow.com/docs/u3QrY4n1s0JS3e3ZEU5YvA "Security Incident Response (SIR) integrates with third-party security tools to create security incidents.") | Set up [Activate and configure Palo Alto Networks - AutoFocus integration](https://www.servicenow.com/docs/Qqi6nOWyHkZiacx9HIKIfA "The Integration Configuration feature allows you to quickly activate and set up third-party security integrations, including Palo Alto Networks - AutoFocus. Before you can use the Palo Alto Networks - AutoFocus, you must download it from the ServiceNow Store.") |
| Use * [Security Operations Palo Alto Networks - Check and Block Value Workflow](https://www.servicenow.com/docs/JX5uCZMnJzRI6S99L_esHw#check-and-block-values "As security incidents are created and triaged to identify potential threats, you can use the Security Operations Palo Alto Networks - Check and Block Value workflow to automatically check and update IP addresses, URLs, and domains using External Dynamic Lists defined in Palo Alto Networks - Firewall.") * [Get AutoFocus Session Info Enrichment Flow](https://www.servicenow.com/docs/2cksRej6Pgml2aYPxMmSyg#search-for-malicious-content "When the Security Operations Palo Alto Networks- Get AutoFocus Session Info Enrichment flow is executed, it queues a search query with AutoFocus for gathering information about a specified source IP. If AutoFocus has knowledge about previous sessions originating from that IP address, a JSON-formatted report is returned.") {#palo-alto-autofocus-landing-page__ul_qkh_cpj_dx} | Develop * [ServiceNow Security Operations integration development guidelines](https://www.servicenow.com/docs/I4hL2~J4aP4Tot3tMdsdHQ "The ServiceNow platform provides several mechanisms for developing integrations with external systems. The ServiceNow Security Operations product suite adds integration capabilities intended to streamline the process of integrating with security-focused external systems.") * [Tips for writing integrations](https://www.servicenow.com/docs/2HBiCmUz7RXqjhSpuXC4sw "Avoid some of the pitfalls you can encounter when writing your own integrations by following these guidelines.") * [Developer training](https://developer.servicenow.com/app.do#!/training/landing) * [Developer documentation](https://developer.servicenow.com/app.do#!/documentation) * [Find components installed with an application](https://www.servicenow.com/docs/access?context=find-components&version=yokohama&pubname=yokohama-platform-administration&ft:locale=en-US) {#palo-alto-autofocus-landing-page__ul_zsn_wnv_qx} |
| Troubleshoot and get help * [Integration troubleshooting](https://www.servicenow.com/docs/b~EIw0PiIzQ2LD_r7_uRpw "These troubleshooting suggestions can help you resolve common issues you can encounter when setting up or running integrations.") * [Ask or answer questions in the Security Operations community](https://community.servicenow.com/community/security-operations) * [Search the Known Error Portal for known error articles](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0597477) * [Contact Customer Service and Support](https://support.servicenow.com/now?draw=case) {#palo-alto-autofocus-landing-page__ul_zyk_3j4_qx} |   |
[Table 1.]

{#palo-alto-autofocus-landing-page__simpletable_g33_wwg_vt}

