<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reports no longer shows the source of an incident in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/reports-no-longer-shows-the-source-of-an-incident/m-p/1255516#M9371</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/318033947"&gt;@C.PAPET&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;The reported change in incident report output after the Cortex v5.0 update is primarily due to a combination of terminology changes, UI reorganization, and architectural performance optimizations.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN&gt;(Key Factors for Missing "Source" Data)&lt;/SPAN&gt;&lt;/H4&gt;
&lt;H4&gt;&lt;SPAN&gt;Performance Decoupling:&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;In v5.0, &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Issues (formerly Alerts)&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; are sent for notification immediately upon detection to ensure near real-time reporting.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;This can occur before the backend completes grouping the issue into a &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Case (formerly Incident)&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, which may result in some metadata fields appearing as blank or null in immediate outputs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN&gt;Widget Relocation:&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;The &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Alert Sources&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; widget was relocated in v5.0 and is now available under the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Alerts&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; widget within the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Incident Overview&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; tab.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN&gt;Predefined Template Limitations:&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Built-in report templates are static. If the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Source&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; field is no longer included in a default report template after the upgrade, a custom report template may be required to ensure the field is displayed.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;STRONG&gt;Steps to Restore the "Source" Field in Reports:&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;To ensure the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Source&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; (or &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Alert Source&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;) field is included in generated reports:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL start="1" data-spread="true"&gt;
&lt;LI&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Navigate to:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Dashboards &amp;amp; Reports → Customize → Report Templates&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Click &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;+ New Template&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; and select &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Blank&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; as the template type.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Drag a &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Table Widget&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; onto the report canvas.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Set the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Data Source&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; to either:&lt;/SPAN&gt;
&lt;UL data-spread="false"&gt;
&lt;LI&gt;&lt;SPAN&gt;Alerts&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Incidents (Cases)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;In the widget's column configuration, manually add the following field:&lt;/SPAN&gt;
&lt;UL data-spread="false"&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN&gt;Source&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN&gt;Alert Source&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;(Optional) For raw data reporting, use a custom XQL query within the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Attach CSV&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; section:&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;PRE dir="ltr"&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;dataset = alerts
| fields _time, alert_id, alert_source, severity&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;OL start="7" data-spread="false"&gt;
&lt;LI&gt;&lt;SPAN&gt;Save the template and configure any required report schedules.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="isSelectedEnd"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Important:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; Changes must be saved directly to the report template to ensure they are reflected in scheduled and recurring reports.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;STRONG&gt;Additional Verification:&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;If the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Source&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; field continues to appear as &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;null&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; after configuring a custom report template:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL data-spread="false"&gt;
&lt;LI&gt;&lt;SPAN&gt;Verify that the underlying alert data actually contains values for the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;alert_source&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; field.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Confirm that the selected report dataset includes the required field.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Review any field visibility settings configured within the console.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Check whether an editable Incident/Case layout configuration affects which fields are exposed to report templates and PDF exports.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;It may also be helpful to verify whether any report template, dashboard widget, or case layout customization introduced after the upgrade is affecting field visibility within exported reports.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jun 2026 15:53:32 GMT</pubDate>
    <dc:creator>susekar</dc:creator>
    <dc:date>2026-06-05T15:53:32Z</dc:date>
    <item>
      <title>Reports no longer shows the source of an incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/reports-no-longer-shows-the-source-of-an-incident/m-p/1255384#M9369</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;One of our customers pointed out that since the 5.0 update of the Cortex console, the report output has changed.&lt;BR /&gt;Before the update, the reports always displayed the source of the incident (as highlighted in the “Before.png” file). &lt;BR /&gt;Since the 5.0 update, as you can see in the “Now.png” file, the source of the incident is not always displayed in the report.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;The customer would like to know if there is a way to make the source appear again when the reports are generated.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thank you in advance for your response.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2026 06:24:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/reports-no-longer-shows-the-source-of-an-incident/m-p/1255384#M9369</guid>
      <dc:creator>C.PAPET</dc:creator>
      <dc:date>2026-06-04T06:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: Reports no longer shows the source of an incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/reports-no-longer-shows-the-source-of-an-incident/m-p/1255516#M9371</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/318033947"&gt;@C.PAPET&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;The reported change in incident report output after the Cortex v5.0 update is primarily due to a combination of terminology changes, UI reorganization, and architectural performance optimizations.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN&gt;(Key Factors for Missing "Source" Data)&lt;/SPAN&gt;&lt;/H4&gt;
&lt;H4&gt;&lt;SPAN&gt;Performance Decoupling:&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;In v5.0, &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Issues (formerly Alerts)&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; are sent for notification immediately upon detection to ensure near real-time reporting.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;This can occur before the backend completes grouping the issue into a &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Case (formerly Incident)&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, which may result in some metadata fields appearing as blank or null in immediate outputs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN&gt;Widget Relocation:&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;The &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Alert Sources&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; widget was relocated in v5.0 and is now available under the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Alerts&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; widget within the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Incident Overview&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; tab.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN&gt;Predefined Template Limitations:&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Built-in report templates are static. If the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Source&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; field is no longer included in a default report template after the upgrade, a custom report template may be required to ensure the field is displayed.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;STRONG&gt;Steps to Restore the "Source" Field in Reports:&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;To ensure the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Source&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; (or &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Alert Source&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;) field is included in generated reports:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL start="1" data-spread="true"&gt;
&lt;LI&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Navigate to:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Dashboards &amp;amp; Reports → Customize → Report Templates&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Click &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;+ New Template&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; and select &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Blank&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; as the template type.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Drag a &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Table Widget&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; onto the report canvas.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Set the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Data Source&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; to either:&lt;/SPAN&gt;
&lt;UL data-spread="false"&gt;
&lt;LI&gt;&lt;SPAN&gt;Alerts&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Incidents (Cases)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;In the widget's column configuration, manually add the following field:&lt;/SPAN&gt;
&lt;UL data-spread="false"&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN&gt;Source&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN&gt;Alert Source&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;(Optional) For raw data reporting, use a custom XQL query within the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Attach CSV&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; section:&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;PRE dir="ltr"&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;dataset = alerts
| fields _time, alert_id, alert_source, severity&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;OL start="7" data-spread="false"&gt;
&lt;LI&gt;&lt;SPAN&gt;Save the template and configure any required report schedules.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="isSelectedEnd"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Important:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; Changes must be saved directly to the report template to ensure they are reflected in scheduled and recurring reports.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;STRONG&gt;Additional Verification:&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;If the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Source&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; field continues to appear as &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;null&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; after configuring a custom report template:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL data-spread="false"&gt;
&lt;LI&gt;&lt;SPAN&gt;Verify that the underlying alert data actually contains values for the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;alert_source&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; field.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Confirm that the selected report dataset includes the required field.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Review any field visibility settings configured within the console.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Check whether an editable Incident/Case layout configuration affects which fields are exposed to report templates and PDF exports.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;It may also be helpful to verify whether any report template, dashboard widget, or case layout customization introduced after the upgrade is affecting field visibility within exported reports.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2026 15:53:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/reports-no-longer-shows-the-source-of-an-incident/m-p/1255516#M9371</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-06-05T15:53:32Z</dc:date>
    </item>
  </channel>
</rss>

