<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XDR Automation Rules not triggering Playbook execution in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-automation-rules-not-triggering-playbook-execution/m-p/1252607#M9266</link>
    <description>&lt;P data-end="178" data-start="85"&gt;I am experiencing an issue with &lt;STRONG data-end="141" data-start="117"&gt;XDR Automation Rules&lt;/STRONG&gt; when attempting to execute a script.&lt;/P&gt;
&lt;P data-end="433" data-start="180"&gt;I have configured an automation rule to trigger a &lt;STRONG data-end="242" data-start="230"&gt;Playbooks&lt;/STRONG&gt;&amp;nbsp;when a specific event occurs. The Playbook is designed to run the built-in &lt;STRONG data-end="357" data-start="318"&gt;Quick Action: “Run Endpoint Script”&lt;/STRONG&gt;, which executes a script registered in &lt;STRONG data-end="432" data-start="397"&gt;Action Center &amp;gt; Scripts Library&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P data-end="522" data-start="435"&gt;However, the automation rule does not execute the Playbook when the event is triggered.&lt;/P&gt;
&lt;P data-end="693" data-start="524"&gt;In contrast, when I go to the &lt;STRONG data-end="564" data-start="554"&gt;Issues&lt;/STRONG&gt; menu, right-click a detected event, and select &lt;STRONG data-end="632" data-start="612"&gt;“Run Automation”&lt;/STRONG&gt;, the same Playbooks executes successfully without any issues.&lt;/P&gt;
&lt;P data-end="786" data-start="695"&gt;Could you please advise why the Automation Rules are not triggering the Playbook execution?&lt;/P&gt;
&lt;P data-end="880" data-start="788"&gt;I am using the &lt;STRONG data-end="822" data-start="803"&gt;XDR Pro version&lt;/STRONG&gt;, and I understand this functionality should be supported.&lt;/P&gt;
&lt;P data-end="986" data-start="882"&gt;Additionally, are there any restrictions on the types of events that Automation Rules can be applied to?&lt;/P&gt;</description>
    <pubDate>Tue, 21 Apr 2026 04:41:56 GMT</pubDate>
    <dc:creator>.522643</dc:creator>
    <dc:date>2026-04-21T04:41:56Z</dc:date>
    <item>
      <title>XDR Automation Rules not triggering Playbook execution</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-automation-rules-not-triggering-playbook-execution/m-p/1252607#M9266</link>
      <description>&lt;P data-end="178" data-start="85"&gt;I am experiencing an issue with &lt;STRONG data-end="141" data-start="117"&gt;XDR Automation Rules&lt;/STRONG&gt; when attempting to execute a script.&lt;/P&gt;
&lt;P data-end="433" data-start="180"&gt;I have configured an automation rule to trigger a &lt;STRONG data-end="242" data-start="230"&gt;Playbooks&lt;/STRONG&gt;&amp;nbsp;when a specific event occurs. The Playbook is designed to run the built-in &lt;STRONG data-end="357" data-start="318"&gt;Quick Action: “Run Endpoint Script”&lt;/STRONG&gt;, which executes a script registered in &lt;STRONG data-end="432" data-start="397"&gt;Action Center &amp;gt; Scripts Library&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P data-end="522" data-start="435"&gt;However, the automation rule does not execute the Playbook when the event is triggered.&lt;/P&gt;
&lt;P data-end="693" data-start="524"&gt;In contrast, when I go to the &lt;STRONG data-end="564" data-start="554"&gt;Issues&lt;/STRONG&gt; menu, right-click a detected event, and select &lt;STRONG data-end="632" data-start="612"&gt;“Run Automation”&lt;/STRONG&gt;, the same Playbooks executes successfully without any issues.&lt;/P&gt;
&lt;P data-end="786" data-start="695"&gt;Could you please advise why the Automation Rules are not triggering the Playbook execution?&lt;/P&gt;
&lt;P data-end="880" data-start="788"&gt;I am using the &lt;STRONG data-end="822" data-start="803"&gt;XDR Pro version&lt;/STRONG&gt;, and I understand this functionality should be supported.&lt;/P&gt;
&lt;P data-end="986" data-start="882"&gt;Additionally, are there any restrictions on the types of events that Automation Rules can be applied to?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 04:41:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-automation-rules-not-triggering-playbook-execution/m-p/1252607#M9266</guid>
      <dc:creator>.522643</dc:creator>
      <dc:date>2026-04-21T04:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Automation Rules not triggering Playbook execution</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-automation-rules-not-triggering-playbook-execution/m-p/1252673#M9267</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/645079201"&gt;@.522643&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Greetings for the day.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 data-end="149" data-start="99" data-section-id="9z2zmo"&gt;(Why Cortex XDR Automation Rules May Not Trigger)&lt;/H4&gt;
&lt;P data-end="338" data-start="151"&gt;There are several design behaviors and platform restrictions that explain why an automation rule may fail to trigger, even though manual execution of the same playbook works successfully.&lt;/P&gt;
&lt;P data-end="338" data-start="151"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="380" data-start="345" data-section-id="m6x2oa"&gt;Core Reasons for Trigger Failure:&lt;/H4&gt;
&lt;H4 data-end="415" data-start="382" data-section-id="klcmts"&gt;1. Alert Severity Restriction&lt;/H4&gt;
&lt;P data-end="516" data-start="416"&gt;Automation rules generally trigger only for alerts with a severity of &lt;STRONG data-end="515" data-start="486"&gt;Medium, High, or Critical&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P data-end="685" data-start="518"&gt;Alerts with &lt;STRONG data-end="537" data-start="530"&gt;Low&lt;/STRONG&gt; or &lt;STRONG data-end="558" data-start="541"&gt;Informational&lt;/STRONG&gt; severity typically do not support automatic execution. However, manual execution via the Issues menu bypasses this limitation.&lt;/P&gt;
&lt;H4 data-end="734" data-start="692" data-section-id="1wr8qfo"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 data-end="734" data-start="692" data-section-id="1wr8qfo"&gt;2. Action Limit Thresholds (Failsafes):&lt;/H4&gt;
&lt;P data-end="833" data-start="735"&gt;To prevent unintended large-scale impact, Cortex XDR enforces limits on sensitive actions such as:&lt;/P&gt;
&lt;UL data-end="883" data-start="835"&gt;
&lt;LI data-end="860" data-start="835" data-section-id="yfcyx9"&gt;&lt;STRONG data-end="860" data-start="837"&gt;Run Endpoint Script&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI data-end="883" data-start="861" data-section-id="hqayea"&gt;&lt;STRONG data-end="883" data-start="863"&gt;Isolate Endpoint&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="908" data-start="885"&gt;&lt;STRONG data-end="908" data-start="885"&gt;Threshold Behavior:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-end="1087" data-start="909"&gt;
&lt;LI data-end="1087" data-start="909" data-section-id="b93fyu"&gt;If a single rule triggers more than &lt;STRONG data-end="1008" data-start="947"&gt;5 actions across 5 distinct hosts within a 24-hour period&lt;/STRONG&gt;, the system will automatically &lt;STRONG data-end="1058" data-start="1040"&gt;pause the rule&lt;/STRONG&gt; and stop further executions.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1107" data-start="1089"&gt;&lt;STRONG data-end="1107" data-start="1089"&gt;What to Check:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-end="1238" data-start="1108"&gt;
&lt;LI data-end="1238" data-start="1108" data-section-id="cumbmm"&gt;Review the &lt;STRONG data-end="1145" data-start="1121"&gt;Automation Audit Log&lt;/STRONG&gt; for entries showing a &lt;STRONG data-end="1178" data-start="1168"&gt;Paused&lt;/STRONG&gt; status to confirm whether this threshold has been exceeded.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-end="1273" data-start="1245" data-section-id="6ec64w"&gt;3. Rule Processing Order:&lt;/H4&gt;
&lt;P&gt;Legacy XDR&lt;/P&gt;
&lt;UL data-end="1469" data-start="1291"&gt;
&lt;LI data-end="1338" data-start="1291" data-section-id="6bnchs"&gt;Rules are processed in the order they appear.&lt;/LI&gt;
&lt;LI data-end="1469" data-start="1339" data-section-id="7wyxus"&gt;If a higher-priority rule matches and has &lt;STRONG data-end="1420" data-start="1383"&gt;“Stop processing after this rule”&lt;/STRONG&gt; enabled, subsequent rules will not be evaluated.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Unified Platform&lt;/P&gt;
&lt;UL data-end="1602" data-start="1493"&gt;
&lt;LI data-end="1534" data-start="1493" data-section-id="1576jdn"&gt;Rules are evaluated from top to bottom.&lt;/LI&gt;
&lt;LI data-end="1602" data-start="1535" data-section-id="17sz2jt"&gt;Processing stops as soon as the &lt;STRONG data-end="1592" data-start="1569"&gt;first matching rule&lt;/STRONG&gt; is found.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-end="1645" data-start="1609" data-section-id="lgawju"&gt;4. Incident Grouping Requirement&lt;/H4&gt;
&lt;P data-end="1729" data-start="1646"&gt;Automation rules apply only to alerts that are successfully grouped into incidents.&lt;/P&gt;
&lt;UL data-end="1803" data-start="1731"&gt;
&lt;LI data-end="1803" data-start="1731" data-section-id="eg2zfx"&gt;If an alert is not assigned to an incident, the rule will not trigger.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-end="1838" data-start="1810" data-section-id="14aq88a"&gt;5. Missing Endpoint Data&lt;/H4&gt;
&lt;P data-end="1976" data-start="1839"&gt;If the triggering alert (often from a custom Correlation Rule) does not include required fields such as &lt;STRONG data-end="1955" data-start="1943"&gt;agent_id&lt;/STRONG&gt; or endpoint context:&lt;/P&gt;
&lt;UL data-end="2083" data-start="1978"&gt;
&lt;LI data-end="2083" data-start="1978" data-section-id="1byagos"&gt;Actions like &lt;STRONG data-end="2016" data-start="1993"&gt;Run Endpoint Script&lt;/STRONG&gt; will fail because the system cannot determine the target endpoint.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-end="2120" data-start="2090" data-section-id="1lao2as"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 data-end="2120" data-start="2090" data-section-id="1lao2as"&gt;(Restrictions on Event Types)&lt;/H4&gt;
&lt;H5 data-end="2120" data-start="2090" data-section-id="1lao2as"&gt;New Alerts Only&lt;/H5&gt;
&lt;UL data-end="2298" data-start="2142"&gt;
&lt;LI data-end="2202" data-start="2142" data-section-id="1dxjrd0"&gt;Automation rules apply only to &lt;STRONG data-end="2201" data-start="2175"&gt;newly generated alerts&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI data-end="2298" data-start="2203" data-section-id="ib28pn"&gt;They do not run retroactively on past alerts, even if those alerts match the rule conditions.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H5 data-end="2338" data-start="2305" data-section-id="1nlgups"&gt;Incident Association Required&lt;/H5&gt;
&lt;UL data-end="2422" data-start="2339"&gt;
&lt;LI data-end="2422" data-start="2339" data-section-id="x2ss7p"&gt;The alert must be associated with an incident for the automation rule to execute.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H5 data-end="2461" data-start="2429" data-section-id="1mh7j30"&gt;Minimum Severity Requirement&lt;/H5&gt;
&lt;UL data-end="2555" data-start="2462"&gt;
&lt;LI data-end="2555" data-start="2462" data-section-id="nkqqej"&gt;Most automated actions require alerts to have a severity higher than &lt;STRONG data-end="2554" data-start="2533"&gt;Low/Informational&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H5 data-end="2586" data-start="2562" data-section-id="gp7tz2"&gt;Scoped Access (SBAC)&lt;/H5&gt;
&lt;UL data-end="2748" data-start="2587"&gt;
&lt;LI data-end="2748" data-start="2587" data-section-id="g9ryy1"&gt;If &lt;STRONG data-end="2631" data-start="2592"&gt;Scoped Server Access Control (SBAC)&lt;/STRONG&gt; is enabled:
&lt;UL data-end="2748" data-start="2646"&gt;
&lt;LI data-end="2748" data-start="2646" data-section-id="1aa8r9a"&gt;Automation rules will only trigger for endpoints that fall within the user’s defined &lt;STRONG data-end="2747" data-start="2733"&gt;scope tags&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 17:23:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-automation-rules-not-triggering-playbook-execution/m-p/1252673#M9267</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-04-21T17:23:49Z</dc:date>
    </item>
  </channel>
</rss>

