<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR automation in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-automation/m-p/1249057#M9172</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/262549"&gt;@RajeshPremSingh&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="343" data-start="83"&gt;In Cortex XDR, the priority of an automation rule is determined by its position in the rules list. Because the system follows a &lt;STRONG data-end="233" data-start="211"&gt;“First Match Wins”&lt;/STRONG&gt; logic, the rules are evaluated sequentially from top to bottom, and only the first matching rule is executed.&lt;/P&gt;
&lt;P data-end="343" data-start="83"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="475" data-start="345"&gt;If you only have one automation rule, it is effectively &lt;STRONG data-end="415" data-start="401"&gt;Priority 1&lt;/STRONG&gt; because it is the first and only rule the engine evaluates.&lt;/P&gt;
&lt;P data-end="475" data-start="345"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="527" data-start="482"&gt;How to Manage Rule Priority and Activation:&lt;/H4&gt;
&lt;P data-end="604" data-start="529"&gt;To ensure your rule is properly prioritized and active, follow these steps:&lt;/P&gt;
&lt;H5 data-end="628" data-start="606"&gt;1. Set the Order&lt;/H5&gt;
&lt;P data-end="775" data-start="629"&gt;In the &lt;STRONG data-end="656" data-start="636"&gt;Automation Rules&lt;/STRONG&gt; table&lt;BR data-end="665" data-start="662" /&gt;(&lt;STRONG data-end="711" data-start="666"&gt;Incident Response &amp;gt; Response &amp;gt; Automation&lt;/STRONG&gt;), the numbers in the left column represent the execution order.&lt;/P&gt;
&lt;P data-end="870" data-start="777"&gt;If you have multiple rules, you can click and drag a rule to change its position in the list.&lt;/P&gt;
&lt;H5 data-end="901" data-start="877"&gt;&amp;nbsp;&lt;/H5&gt;
&lt;H5 data-end="901" data-start="877"&gt;2. Enable the Rule&lt;/H5&gt;
&lt;P data-end="1029" data-start="902"&gt;Newly created rules are often in a disabled (grayed out) state by default. You must manually enable the rule for it to trigger.&lt;/P&gt;
&lt;P data-end="1029" data-start="902"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5 data-end="1057" data-start="1036"&gt;3. Save Changes:&lt;/H5&gt;
&lt;P data-end="1198" data-start="1058"&gt;Any changes to the rule’s status or its order in the list require you to click &lt;STRONG data-end="1145" data-start="1137"&gt;Save&lt;/STRONG&gt; in the top-right corner of the configuration screen.&lt;/P&gt;
&lt;H5 data-end="1244" data-start="1205"&gt;&amp;nbsp;&lt;/H5&gt;
&lt;H5 data-end="1244" data-start="1205"&gt;4. Verify Triggering Requirements:&lt;/H5&gt;
&lt;UL data-end="1648" data-start="1246"&gt;
&lt;LI data-end="1387" data-start="1246"&gt;
&lt;P data-end="1387" data-start="1248"&gt;&lt;STRONG data-end="1268" data-start="1248"&gt;New Alerts Only:&lt;/STRONG&gt;&lt;BR data-end="1271" data-start="1268" /&gt;Automation rules are not retroactive. They apply only to new alerts generated after the rule is saved and enabled.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="1648" data-start="1389"&gt;
&lt;P data-end="1648" data-start="1391"&gt;&lt;STRONG data-end="1416" data-start="1391"&gt;Incident Association:&lt;/STRONG&gt;&lt;BR data-end="1419" data-start="1416" /&gt;Automation rules generally trigger only after an alert is attached to an incident. If an alert is not grouped into an incident (which is common for “Low” or “Informational” severity alerts), the automation rule may not execute.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="1693" data-start="1655"&gt;Important Note on Platform Versions:&lt;/H4&gt;
&lt;P data-end="1865" data-start="1695"&gt;If you are using Cortex XDR version 4.x or have migrated to the unified XSIAM platform, legacy &lt;STRONG data-end="1817" data-start="1790"&gt;Simple Automation Rules&lt;/STRONG&gt; are deprecated and kept in a read-only state.&lt;/P&gt;
&lt;P data-is-only-node="" data-is-last-node="" data-end="1986" data-start="1867"&gt;In these versions, new automations and their associated priorities are managed through the &lt;STRONG data-end="1977" data-start="1958"&gt;Playbook engine&lt;/STRONG&gt; instead.&lt;/P&gt;
&lt;P data-is-only-node="" data-is-last-node="" data-end="1986" data-start="1867"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
    <pubDate>Thu, 26 Feb 2026 13:37:01 GMT</pubDate>
    <dc:creator>susekar</dc:creator>
    <dc:date>2026-02-26T13:37:01Z</dc:date>
    <item>
      <title>Cortex XDR automation</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-automation/m-p/1242010#M8869</link>
      <description>&lt;P&gt;is there any way to make the automation rule priority&amp;nbsp;one? i don't have any other&amp;nbsp; rule&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RajeshPremSingh_0-1763392560357.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69864iF3B2546A6C56D628/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RajeshPremSingh_0-1763392560357.png" alt="RajeshPremSingh_0-1763392560357.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Nov 2025 15:17:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-automation/m-p/1242010#M8869</guid>
      <dc:creator>RajeshPremSingh</dc:creator>
      <dc:date>2025-11-17T15:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR automation</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-automation/m-p/1249057#M9172</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/262549"&gt;@RajeshPremSingh&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="343" data-start="83"&gt;In Cortex XDR, the priority of an automation rule is determined by its position in the rules list. Because the system follows a &lt;STRONG data-end="233" data-start="211"&gt;“First Match Wins”&lt;/STRONG&gt; logic, the rules are evaluated sequentially from top to bottom, and only the first matching rule is executed.&lt;/P&gt;
&lt;P data-end="343" data-start="83"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="475" data-start="345"&gt;If you only have one automation rule, it is effectively &lt;STRONG data-end="415" data-start="401"&gt;Priority 1&lt;/STRONG&gt; because it is the first and only rule the engine evaluates.&lt;/P&gt;
&lt;P data-end="475" data-start="345"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="527" data-start="482"&gt;How to Manage Rule Priority and Activation:&lt;/H4&gt;
&lt;P data-end="604" data-start="529"&gt;To ensure your rule is properly prioritized and active, follow these steps:&lt;/P&gt;
&lt;H5 data-end="628" data-start="606"&gt;1. Set the Order&lt;/H5&gt;
&lt;P data-end="775" data-start="629"&gt;In the &lt;STRONG data-end="656" data-start="636"&gt;Automation Rules&lt;/STRONG&gt; table&lt;BR data-end="665" data-start="662" /&gt;(&lt;STRONG data-end="711" data-start="666"&gt;Incident Response &amp;gt; Response &amp;gt; Automation&lt;/STRONG&gt;), the numbers in the left column represent the execution order.&lt;/P&gt;
&lt;P data-end="870" data-start="777"&gt;If you have multiple rules, you can click and drag a rule to change its position in the list.&lt;/P&gt;
&lt;H5 data-end="901" data-start="877"&gt;&amp;nbsp;&lt;/H5&gt;
&lt;H5 data-end="901" data-start="877"&gt;2. Enable the Rule&lt;/H5&gt;
&lt;P data-end="1029" data-start="902"&gt;Newly created rules are often in a disabled (grayed out) state by default. You must manually enable the rule for it to trigger.&lt;/P&gt;
&lt;P data-end="1029" data-start="902"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5 data-end="1057" data-start="1036"&gt;3. Save Changes:&lt;/H5&gt;
&lt;P data-end="1198" data-start="1058"&gt;Any changes to the rule’s status or its order in the list require you to click &lt;STRONG data-end="1145" data-start="1137"&gt;Save&lt;/STRONG&gt; in the top-right corner of the configuration screen.&lt;/P&gt;
&lt;H5 data-end="1244" data-start="1205"&gt;&amp;nbsp;&lt;/H5&gt;
&lt;H5 data-end="1244" data-start="1205"&gt;4. Verify Triggering Requirements:&lt;/H5&gt;
&lt;UL data-end="1648" data-start="1246"&gt;
&lt;LI data-end="1387" data-start="1246"&gt;
&lt;P data-end="1387" data-start="1248"&gt;&lt;STRONG data-end="1268" data-start="1248"&gt;New Alerts Only:&lt;/STRONG&gt;&lt;BR data-end="1271" data-start="1268" /&gt;Automation rules are not retroactive. They apply only to new alerts generated after the rule is saved and enabled.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="1648" data-start="1389"&gt;
&lt;P data-end="1648" data-start="1391"&gt;&lt;STRONG data-end="1416" data-start="1391"&gt;Incident Association:&lt;/STRONG&gt;&lt;BR data-end="1419" data-start="1416" /&gt;Automation rules generally trigger only after an alert is attached to an incident. If an alert is not grouped into an incident (which is common for “Low” or “Informational” severity alerts), the automation rule may not execute.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="1693" data-start="1655"&gt;Important Note on Platform Versions:&lt;/H4&gt;
&lt;P data-end="1865" data-start="1695"&gt;If you are using Cortex XDR version 4.x or have migrated to the unified XSIAM platform, legacy &lt;STRONG data-end="1817" data-start="1790"&gt;Simple Automation Rules&lt;/STRONG&gt; are deprecated and kept in a read-only state.&lt;/P&gt;
&lt;P data-is-only-node="" data-is-last-node="" data-end="1986" data-start="1867"&gt;In these versions, new automations and their associated priorities are managed through the &lt;STRONG data-end="1977" data-start="1958"&gt;Playbook engine&lt;/STRONG&gt; instead.&lt;/P&gt;
&lt;P data-is-only-node="" data-is-last-node="" data-end="1986" data-start="1867"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Thu, 26 Feb 2026 13:37:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-automation/m-p/1249057#M9172</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-02-26T13:37:01Z</dc:date>
    </item>
  </channel>
</rss>

