← Back to connectors

Panther connector for Okou

Connect Panther to investigate security alerts, inspect detections and log sources, query security data, and manage security operations through its REST API.

Data & infrastructure · Panther API Token

Use Panther in Okou

Panther REST API for security alerts, alert events and comments, detections, policies, log sources, saved queries, cloud security sources, and Panther administration.

Once connected, supported Panther actions can become steps in a reusable workflow alongside the other services your team uses. Run the workflow once, on a schedule, or when an event starts it.

What you can do with Panther

  • Read Panther alerts, alert details, and alert event history (Panther AlertRead); provider permission: AlertRead.
  • Read Panther API token metadata without exposing token values (Panther OrganizationAPITokenRead); provider permission: OrganizationAPITokenRead.
  • Read Panther AWS cloud security account integrations (Panther CloudsecSourceRead); provider permission: CloudsecSourceRead.
  • Read Panther data models (Panther LogSourceRead); provider permission: LogSourceRead.
  • Read Panther saved queries and query data (Panther DataAnalyticsRead / Query Data Lake); provider permission: DataAnalyticsRead / Query Data Lake.
  • Read Panther global detection and policy configuration (Panther View Rules or View Policies); provider permission: View Rules or View Policies.
  • Read Panther correlation rules (Panther RuleRead); provider permission: RuleRead.
  • Change Panther alert state, assignments, quality, or context (Panther AlertModify); provider permission: AlertModify.

How the Panther connector works

A connected service becomes one permissioned step in the work you hand off.

  1. 1

    Connect Panther

    Choose Panther API Token.

  2. 2

    Choose the work

    Use only the supported actions your workflow needs.

  3. 3

    Run it your way

    Start it once, schedule it, or attach an event trigger.

Connect Panther securely

Use the connection method that fits your account and grant only the access the workflow needs.

  • Panther API Token

Connector access is controlled per service and per action, so a workflow does not need broader access than the work you ask it to do.

Panther connector questions

What can Okou do with Panther?
Connect Panther to investigate security alerts, inspect detections and log sources, query security data, and manage security operations through its REST API. Documented actions include: Read Panther alerts, alert details, and alert event history (Panther AlertRead); provider permission: AlertRead. Read Panther API token metadata without exposing token values (Panther OrganizationAPITokenRead); provider permission: OrganizationAPITokenRead.
How do I connect Panther to Okou?
Connect Panther using Panther API Token. The connection controls which supported actions a workflow can use.
Can Panther run in an automated workflow?
Yes. After it is connected, supported Panther actions can run in reusable Okou workflows on demand, on a schedule, or from an event trigger.

More data & infrastructure connectors

Explore other connectors in the same product category.