Overview
This article explains an error encountered when trying to integrate Druva with Palo Alto XSOAR for ransomware response, due to a missing specific license feature in the Druva tenant.
Problem Description
Attempts to integrate Druva with Palo Alto XSOAR using the official integration guide resulted in errors, indicating the Druva instance lacked the necessary "Ransomware License" for the specific API functionality.
Reference - Palo Alto's documentation - https://xsoar.pan.dev/docs/reference/integrations/druva-ransomware-response
Cause
The Druva API endpoints used by the Palo Alto XSOAR integration for ransomware response functionalities require an "Accelerated Ransomware Response (ARR)" license or a specific "Security Add-on" feature within Druva, which was not part of the customer's existing "Elite" license.
Resolution
The Palo Alto XSOAR integration for ransomware response utilizes specific Druva APIs. Access to these APIs is contingent on the Druva tenant having an active "Accelerated Ransomware Response (ARR)" license or an equivalent "Security Add-on."
Contact the Druva support team or your sales representative to enable the license for Advanced Ransomware Protection & Recovery.