<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Email Notifications Setup in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/email-notifications-setup/m-p/1248789#M9161</link>
    <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/241098"&gt;@susekar&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;we did try the above solution but nothing concrete. Is there a way to get the alerts on the notifications tabs aside from the UI (without logging in)?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;BR&lt;BR /&gt;Kingsley&lt;/P&gt;</description>
    <pubDate>Mon, 23 Feb 2026 15:25:01 GMT</pubDate>
    <dc:creator>K.Mgbachi</dc:creator>
    <dc:date>2026-02-23T15:25:01Z</dc:date>
    <item>
      <title>Email Notifications Setup</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/email-notifications-setup/m-p/1246232#M9028</link>
      <description>&lt;P&gt;Good day,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please does anyone know how to setup email alerts for cloud agents warning (like the notifications on the notification tab on the UI) and outdated agents (which are not the latest release/version). thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jan 2026 12:53:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/email-notifications-setup/m-p/1246232#M9028</guid>
      <dc:creator>K.Mgbachi</dc:creator>
      <dc:date>2026-01-22T12:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: Email Notifications Setup</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/email-notifications-setup/m-p/1246255#M9029</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/363069343"&gt;@K.Mgbachi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Setting up email alerts for agent-related notifications in Cortex XDR/XSIAM is handled through three distinct mechanisms depending on the type of information you wish to receive.&lt;/P&gt;
&lt;H4&gt;1. Notifications for New Agent Releases and End-of-Life (EOL)&lt;/H4&gt;
&lt;P&gt;To stay informed about new agent versions (outdated agents) and EOL warnings, you must configure administrative subscriptions. These notifications are sent globally and are not triggered per individual endpoint.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Palo Alto Networks Customer Support Portal (CSP):&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Log into the Customer Support Portal.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Navigate to your user profile (click your name) and select &lt;STRONG&gt;Preferences&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Under &lt;STRONG&gt;My Support Notifications&lt;/STRONG&gt;, enable:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Subscribe to Cortex XDR/XSIAM Software Update Emails&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Subscribe to Cortex XDR/XSIAM Content Update Emails&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Cortex XDR Server Settings:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Navigate to &lt;STRONG&gt;Settings → Configurations → General → Server Settings&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;In the &lt;STRONG&gt;Email Contacts&lt;/STRONG&gt; field, add the email addresses or distribution lists that should receive product maintenance, updates, and new version notifications.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;2. Operational Alerts for Agent Upgrade Failures&lt;/H4&gt;
&lt;P&gt;If you specifically want to be notified when an agent fails to move to the latest version (remaining “outdated” due to failure), you can configure a Notification Forwarding rule:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;Navigate to &lt;STRONG&gt;Settings → Configurations → General → Notifications&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Click &lt;STRONG&gt;+ Add Forwarding Configuration&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Select &lt;STRONG&gt;Agent Audit Logs&lt;/STRONG&gt; as the Log Type and click &lt;STRONG&gt;Next&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;In the &lt;STRONG&gt;Scope&lt;/STRONG&gt; section, apply the following filters:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Type:&lt;/STRONG&gt; Installation&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Sub-Type:&lt;/STRONG&gt; Upgrade&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Result:&lt;/STRONG&gt; Fail&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Add your email to the &lt;STRONG&gt;Distribution List&lt;/STRONG&gt; and set the &lt;STRONG&gt;Grouping Time Frame&lt;/STRONG&gt; to &lt;STRONG&gt;0&lt;/STRONG&gt; for immediate alerts.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;H4&gt;3. UI Notification Center Limitations&lt;/H4&gt;
&lt;P&gt;It is important to note that notifications appearing directly in the console’s Notification Center (the bell icon in the UI), such as specific system warnings or Broker VM connectivity events, cannot be forwarded via email by design.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;To monitor general “outdated” status for a fleet, it is recommended to use the &lt;STRONG&gt;All Endpoints&lt;/STRONG&gt; table and filter by the &lt;STRONG&gt;Operational Status&lt;/STRONG&gt; or &lt;STRONG&gt;Agent Version&lt;/STRONG&gt; columns periodically, as there is currently no direct “outdated agent” alert trigger in the notification forwarding settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Happy New year!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jan 2026 13:33:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/email-notifications-setup/m-p/1246255#M9029</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-01-22T13:33:33Z</dc:date>
    </item>
    <item>
      <title>Re: Email Notifications Setup</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/email-notifications-setup/m-p/1246271#M9030</link>
      <description>&lt;P&gt;thanks for the response&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/241098"&gt;@susekar&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;However, I am already familiar with the notification types you listed above. Is there no other way to get this info on warnings (for connected datasources) and agents that are outdated (perhaps via api or another way)?&lt;BR /&gt;because there is not much from the agents endpoint in the api documentation&lt;BR /&gt;&lt;BR /&gt;BR&lt;BR /&gt;Kingsley&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jan 2026 14:05:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/email-notifications-setup/m-p/1246271#M9030</guid>
      <dc:creator>K.Mgbachi</dc:creator>
      <dc:date>2026-01-22T14:05:11Z</dc:date>
    </item>
    <item>
      <title>Re: Email Notifications Setup</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/email-notifications-setup/m-p/1246282#M9031</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/363069343"&gt;@K.Mgbachi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="135" data-end="389"&gt;Yes, there are alternative methods to receive notifications for outdated agents and data source warnings beyond the standard administrative subscriptions. These involve leveraging Cortex Query Language (XQL), Custom Correlation Rules, and the Public API.&lt;/P&gt;
&lt;P data-start="135" data-end="389"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-start="391" data-end="454"&gt;1. Monitoring Outdated Agents via XQL and Correlation Rules&lt;/H4&gt;
&lt;P data-start="456" data-end="637"&gt;Since there is no default “outdated agent” toggle in notification forwarding, you can create a custom detection logic using XQL to identify endpoints not running a specific version.&lt;/P&gt;
&lt;P data-start="639" data-end="889"&gt;&lt;STRONG data-start="639" data-end="663"&gt;Create an XQL Query:&lt;/STRONG&gt;&lt;BR data-start="663" data-end="666" /&gt;Use the endpoints or agent_auditing datasets to identify agents that are not on your target version. For example, you can query the endpoints table and filter for any agent_version that does not match your required release.&lt;/P&gt;
&lt;P data-start="891" data-end="1132"&gt;&lt;STRONG data-start="891" data-end="924"&gt;Establish a Correlation Rule:&lt;/STRONG&gt;&lt;BR data-start="924" data-end="927" /&gt;Navigate to &lt;STRONG data-start="939" data-end="985"&gt;Detection → Detection Rules → Correlations&lt;/STRONG&gt;. Create a new rule using your XQL query. This rule will trigger a security alert whenever an endpoint reports a version that violates your policy.&lt;/P&gt;
&lt;P data-start="1134" data-end="1351"&gt;&lt;STRONG data-start="1134" data-end="1156"&gt;Forward the Alert:&lt;/STRONG&gt;&lt;BR data-start="1156" data-end="1159" /&gt;Once the correlation rule generates an alert, you can use standard Notification Forwarding (&lt;STRONG data-start="1251" data-end="1296"&gt;Settings → Configurations → Notifications&lt;/STRONG&gt;) to send these specific alerts to your email or Slack.&lt;/P&gt;
&lt;H4 data-start="1358" data-end="1406"&gt;2. Alerts for Connected Data Source Warnings&lt;/H4&gt;
&lt;P data-start="1408" data-end="1642"&gt;Warnings appearing in the UI Notification Center (bell icon) often relate to Broker VM connectivity or integration health. While these specific UI pop-ups cannot be forwarded directly, the underlying events are often logged elsewhere.&lt;/P&gt;
&lt;P data-start="1408" data-end="1642"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="1644" data-end="1851"&gt;&lt;STRONG data-start="1644" data-end="1670"&gt;Management Audit Logs:&lt;/STRONG&gt;&lt;BR data-start="1670" data-end="1673" /&gt;You can configure a Notification Forwarding rule for the &lt;STRONG data-start="1730" data-end="1755"&gt;Management Audit Logs&lt;/STRONG&gt; type. Filter for events related to “Broker VM” to track connectivity issues and cluster events.&lt;/P&gt;
&lt;P data-start="1644" data-end="1851"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="1853" data-end="2096"&gt;&lt;STRONG data-start="1853" data-end="1904"&gt;Cloud Health Auditing (XSIAM/Unified Platform):&lt;/STRONG&gt;&lt;BR data-start="1904" data-end="1907" /&gt;For data source integration warnings, you can run XQL queries on the cloud_health_auditing dataset. This dataset tracks connector issues, such as missing permissions or connectivity errors.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P data-start="2098" data-end="2253"&gt;&lt;STRONG data-start="2098" data-end="2119"&gt;Automation Rules:&lt;/STRONG&gt;&lt;BR data-start="2119" data-end="2122" /&gt;You can create an automation rule that triggers a “Send Email” action when a specific health alert or audit log entry is generated.&lt;/P&gt;
&lt;HR data-start="2255" data-end="2258" /&gt;
&lt;H4 data-start="2260" data-end="2292"&gt;3. Leveraging the Public API&lt;/H4&gt;
&lt;P data-start="2294" data-end="2418"&gt;If you prefer an external monitoring solution, you can use the Cortex REST API to pull health and version data periodically.&lt;/P&gt;
&lt;P data-start="2294" data-end="2418"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="2420" data-end="2712"&gt;&lt;STRONG data-start="2420" data-end="2439"&gt;Endpoints Data:&lt;/STRONG&gt;&lt;BR data-start="2439" data-end="2442" /&gt;Use the get_endpoints API to retrieve a list of all endpoints, including their agent_version, operational_status, and last_seen timestamps. You can then process this JSON output with an external script to identify agents that are outdated compared to the latest release./&lt;/P&gt;
&lt;P data-start="2420" data-end="2712"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="2714" data-end="2930"&gt;&lt;STRONG data-start="2714" data-end="2726"&gt;XQL API:&lt;/STRONG&gt;&lt;BR data-start="2726" data-end="2729" /&gt;You can programmatically run XQL queries against the agent_auditing, management_audit_logs, or cloud_health_auditing datasets using the API to feed into your own alerting dashboard or ticketing system.&lt;/P&gt;
&lt;P data-start="2714" data-end="2930"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="2932" data-end="3100"&gt;&lt;STRONG data-start="2932" data-end="2950"&gt;Distributions:&lt;/STRONG&gt;&lt;BR data-start="2950" data-end="2953" /&gt;To manage outdated agents, you can also use APIs like Get-Distribution-URL to automate the creation and downloading of the latest agent installers.&lt;/P&gt;
&lt;P data-start="2932" data-end="3100"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jan 2026 15:01:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/email-notifications-setup/m-p/1246282#M9031</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-01-22T15:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: Email Notifications Setup</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/email-notifications-setup/m-p/1248789#M9161</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/241098"&gt;@susekar&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;we did try the above solution but nothing concrete. Is there a way to get the alerts on the notifications tabs aside from the UI (without logging in)?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;BR&lt;BR /&gt;Kingsley&lt;/P&gt;</description>
      <pubDate>Mon, 23 Feb 2026 15:25:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/email-notifications-setup/m-p/1248789#M9161</guid>
      <dc:creator>K.Mgbachi</dc:creator>
      <dc:date>2026-02-23T15:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: Email Notifications Setup</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/email-notifications-setup/m-p/1248793#M9162</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/363069343"&gt;@K.Mgbachi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The above are the options.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Feb 2026 15:58:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/email-notifications-setup/m-p/1248793#M9162</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-02-23T15:58:28Z</dc:date>
    </item>
  </channel>
</rss>

