<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sending Cortex XDR incidents to MS Teams in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/sending-cortex-xdr-incidents-to-ms-teams/m-p/594790#M7065</link>
    <description>&lt;P&gt;Isn't there any plattform where you can vote for changes? This is insane, when we have to buy another expensive product only to get a better communication to our SOC.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Actually also the mail notification is not satisfying. There is no adjustment.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 13 Aug 2024 17:03:22 GMT</pubDate>
    <dc:creator>RFeyertag</dc:creator>
    <dc:date>2024-08-13T17:03:22Z</dc:date>
    <item>
      <title>Sending Cortex XDR incidents to MS Teams</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/sending-cortex-xdr-incidents-to-ms-teams/m-p/594707#M7063</link>
      <description>&lt;P&gt;So, since XDR has only 3 options of forwarding alerts - email, syslog server and slack. There is no straight method to push alerts to MS Teams. We've found a bypass which is to create an email address for a teams channel and then provide that email address when configuring the alert forwarding on XDR. The problem is that there are tons of alerts, so it wouldn't be very smart to let XDR spam the teams channel whenever new alert is created. Unfortunately, we haven't come up with a solution of forwarding &lt;STRONG&gt;incidents&lt;/STRONG&gt; and &lt;STRIKE&gt;not alerts&lt;/STRIKE&gt;. Is there any way to do that? Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 11:19:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/sending-cortex-xdr-incidents-to-ms-teams/m-p/594707#M7063</guid>
      <dc:creator>paIoaItonetworks</dc:creator>
      <dc:date>2024-08-13T11:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: Sending Cortex XDR incidents to MS Teams</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/sending-cortex-xdr-incidents-to-ms-teams/m-p/594766#M7064</link>
      <description>&lt;P&gt;How you manage to buy XDR without support of your primary chat solution. Overall I don't understand how PA continuously ignoring MS teams support for years. Most likely , based on PA approach you need to buy SOAR platform to work with MS Teams.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 15:18:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/sending-cortex-xdr-incidents-to-ms-teams/m-p/594766#M7064</guid>
      <dc:creator>eronko</dc:creator>
      <dc:date>2024-08-13T15:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: Sending Cortex XDR incidents to MS Teams</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/sending-cortex-xdr-incidents-to-ms-teams/m-p/594790#M7065</link>
      <description>&lt;P&gt;Isn't there any plattform where you can vote for changes? This is insane, when we have to buy another expensive product only to get a better communication to our SOC.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Actually also the mail notification is not satisfying. There is no adjustment.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 17:03:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/sending-cortex-xdr-incidents-to-ms-teams/m-p/594790#M7065</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2024-08-13T17:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: Sending Cortex XDR incidents to MS Teams</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/sending-cortex-xdr-incidents-to-ms-teams/m-p/594919#M7073</link>
      <description>&lt;P&gt;Check automation rules (if you have Cortex XDR Pro). Those should trigger only on alerts within an incident and it's possible to send an email as the automation task. You will still get a message for every alert within an incident but at least no more messages for alerts which aren't in an incident&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 14:05:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/sending-cortex-xdr-incidents-to-ms-teams/m-p/594919#M7073</guid>
      <dc:creator>micomi</dc:creator>
      <dc:date>2024-08-14T14:05:44Z</dc:date>
    </item>
  </channel>
</rss>

