<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Get notified when a case is assigned in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/get-notified-when-a-case-is-assigned/m-p/1260284#M9469</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184443"&gt;@SeanDeHarris&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="qMYqUG_convSearchResultHighlightRoot"&gt;
&lt;DIV class="" data-is-intersecting="true" data-turn-id-container="request-WEB:7f416fa9-e5bf-40e3-be29-fa80fef2d4b6-0"&gt;
&lt;SECTION class="text-token-text-primary w-full focus:outline-none has-data-writing-block:pointer-events-none [&amp;amp;:has([data-writing-block])&amp;gt;*]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(--scroll-root-safe-area-inset-bottom,0px)+var(--thread-response-height))] scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" data-turn="assistant" data-testid="conversation-turn-2" data-turn-id-container="request-WEB:7f416fa9-e5bf-40e3-be29-fa80fef2d4b6-0" data-turn-id="request-WEB:7f416fa9-e5bf-40e3-be29-fa80fef2d4b6-0"&gt;
&lt;DIV class="text-base my-auto mx-auto pb-15 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)"&gt;
&lt;DIV class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn" data-conversation-screenshot-content=""&gt;
&lt;DIV class="flex max-w-full flex-col gap-4 grow"&gt;
&lt;DIV class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal outline-none keyboard-focused:focus-ring [.text-message+&amp;amp;]:mt-1" dir="auto" tabindex="0" data-turn-start-message="true" data-message-model-slug="gpt-5-5" data-message-id="e880cfa3-6bb6-402e-9f3a-e83173d5f684" data-message-author-role="assistant"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden"&gt;
&lt;DIV class="markdown prose dark:prose-invert wrap-break-word w-full dark markdown-new-styling"&gt;
&lt;P class="PDq2pG_selectionAnchorContainer" data-end="455" data-start="99"&gt;Direct, immediate email notification to a specific individual based solely on incident assignment is currently a product limitation in standalone Cortex XDR. While you can configure notifications for when an incident is assigned, these typically go to a predefined distribution list rather than dynamically routing to the specific assignee's email address.&lt;/P&gt;
&lt;P class="PDq2pG_selectionAnchorContainer" data-end="455" data-start="99"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="575" data-start="457"&gt;However, there are ways to manage and configure incident/case notifications depending on your version and environment:&lt;/P&gt;
&lt;H3 data-end="643" data-start="577" data-section-id="1vbt732"&gt;1. General Assigned Incident Notifications (Distribution List)&lt;/H3&gt;
&lt;P data-end="767" data-start="645"&gt;You can configure Cortex XDR to send an email to a team distribution list whenever any incident is marked as &lt;STRONG data-end="766" data-start="754"&gt;Assigned&lt;/STRONG&gt;.&lt;/P&gt;
&lt;OL data-end="1147" data-start="769"&gt;
&lt;LI data-end="840" data-start="769" data-section-id="29jv90"&gt;Navigate to &lt;STRONG data-end="839" data-start="784"&gt;Settings → Configurations → General → Notifications&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI data-end="885" data-start="841" data-section-id="1jezfvc"&gt;Click &lt;STRONG data-end="884" data-start="850"&gt;+ Add Forwarding Configuration&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI data-end="969" data-start="886" data-section-id="1l0r2e2"&gt;Set the &lt;STRONG data-end="909" data-start="897"&gt;Log Type&lt;/STRONG&gt; to &lt;STRONG data-end="923" data-start="913"&gt;Alerts&lt;/STRONG&gt; or &lt;STRONG data-end="940" data-start="927"&gt;Incidents&lt;/STRONG&gt; (depending on your version).&lt;/LI&gt;
&lt;LI data-end="1036" data-start="970" data-section-id="1q0hvta"&gt;Filter the &lt;STRONG data-end="996" data-start="984"&gt;Sub-type&lt;/STRONG&gt; field and select &lt;STRONG data-end="1035" data-start="1014"&gt;Assigned Incident&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI data-end="1147" data-start="1037" data-section-id="1mmbdf0"&gt;Under &lt;STRONG data-end="1067" data-start="1046"&gt;Distribution List&lt;/STRONG&gt;, enter the email address or group address that should receive the notification.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H3 data-end="1199" data-start="1149" data-section-id="7y3azq"&gt;2. User Notifications (Cortex XDR 4.0 / XSIAM)&lt;/H3&gt;
&lt;P data-end="1334" data-start="1201"&gt;In newer platform versions, notifications are triggered when a case is resolved or assigned, and these are sent to the assigned user.&lt;/P&gt;
&lt;UL data-is-only-node="" data-is-last-node="" data-end="1449" data-start="1336"&gt;
&lt;LI data-is-last-node="" data-end="1449" data-start="1336" data-section-id="cd0uvo"&gt;Users can manage these personal notifications through &lt;STRONG data-end="1422" data-start="1392"&gt;Default User Notifications&lt;/STRONG&gt; in their profile settings.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jul 2026 04:59:00 GMT</pubDate>
    <dc:creator>susekar</dc:creator>
    <dc:date>2026-07-29T04:59:00Z</dc:date>
    <item>
      <title>Get notified when a case is assigned</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/get-notified-when-a-case-is-assigned/m-p/1260217#M9465</link>
      <description>&lt;P&gt;Hello XDR experts,&lt;/P&gt;
&lt;P&gt;Is there a way to configure sending an notification by email to whom the case/incident was assigned?&lt;/P&gt;
&lt;P&gt;Cannot find any hints&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sdg&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2026 10:22:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/get-notified-when-a-case-is-assigned/m-p/1260217#M9465</guid>
      <dc:creator>SeanDeHarris</dc:creator>
      <dc:date>2026-07-28T10:22:45Z</dc:date>
    </item>
    <item>
      <title>Re: Get notified when a case is assigned</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/get-notified-when-a-case-is-assigned/m-p/1260284#M9469</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184443"&gt;@SeanDeHarris&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="qMYqUG_convSearchResultHighlightRoot"&gt;
&lt;DIV class="" data-is-intersecting="true" data-turn-id-container="request-WEB:7f416fa9-e5bf-40e3-be29-fa80fef2d4b6-0"&gt;
&lt;SECTION class="text-token-text-primary w-full focus:outline-none has-data-writing-block:pointer-events-none [&amp;amp;:has([data-writing-block])&amp;gt;*]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(--scroll-root-safe-area-inset-bottom,0px)+var(--thread-response-height))] scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" data-turn="assistant" data-testid="conversation-turn-2" data-turn-id-container="request-WEB:7f416fa9-e5bf-40e3-be29-fa80fef2d4b6-0" data-turn-id="request-WEB:7f416fa9-e5bf-40e3-be29-fa80fef2d4b6-0"&gt;
&lt;DIV class="text-base my-auto mx-auto pb-15 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)"&gt;
&lt;DIV class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn" data-conversation-screenshot-content=""&gt;
&lt;DIV class="flex max-w-full flex-col gap-4 grow"&gt;
&lt;DIV class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal outline-none keyboard-focused:focus-ring [.text-message+&amp;amp;]:mt-1" dir="auto" tabindex="0" data-turn-start-message="true" data-message-model-slug="gpt-5-5" data-message-id="e880cfa3-6bb6-402e-9f3a-e83173d5f684" data-message-author-role="assistant"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden"&gt;
&lt;DIV class="markdown prose dark:prose-invert wrap-break-word w-full dark markdown-new-styling"&gt;
&lt;P class="PDq2pG_selectionAnchorContainer" data-end="455" data-start="99"&gt;Direct, immediate email notification to a specific individual based solely on incident assignment is currently a product limitation in standalone Cortex XDR. While you can configure notifications for when an incident is assigned, these typically go to a predefined distribution list rather than dynamically routing to the specific assignee's email address.&lt;/P&gt;
&lt;P class="PDq2pG_selectionAnchorContainer" data-end="455" data-start="99"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="575" data-start="457"&gt;However, there are ways to manage and configure incident/case notifications depending on your version and environment:&lt;/P&gt;
&lt;H3 data-end="643" data-start="577" data-section-id="1vbt732"&gt;1. General Assigned Incident Notifications (Distribution List)&lt;/H3&gt;
&lt;P data-end="767" data-start="645"&gt;You can configure Cortex XDR to send an email to a team distribution list whenever any incident is marked as &lt;STRONG data-end="766" data-start="754"&gt;Assigned&lt;/STRONG&gt;.&lt;/P&gt;
&lt;OL data-end="1147" data-start="769"&gt;
&lt;LI data-end="840" data-start="769" data-section-id="29jv90"&gt;Navigate to &lt;STRONG data-end="839" data-start="784"&gt;Settings → Configurations → General → Notifications&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI data-end="885" data-start="841" data-section-id="1jezfvc"&gt;Click &lt;STRONG data-end="884" data-start="850"&gt;+ Add Forwarding Configuration&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI data-end="969" data-start="886" data-section-id="1l0r2e2"&gt;Set the &lt;STRONG data-end="909" data-start="897"&gt;Log Type&lt;/STRONG&gt; to &lt;STRONG data-end="923" data-start="913"&gt;Alerts&lt;/STRONG&gt; or &lt;STRONG data-end="940" data-start="927"&gt;Incidents&lt;/STRONG&gt; (depending on your version).&lt;/LI&gt;
&lt;LI data-end="1036" data-start="970" data-section-id="1q0hvta"&gt;Filter the &lt;STRONG data-end="996" data-start="984"&gt;Sub-type&lt;/STRONG&gt; field and select &lt;STRONG data-end="1035" data-start="1014"&gt;Assigned Incident&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI data-end="1147" data-start="1037" data-section-id="1mmbdf0"&gt;Under &lt;STRONG data-end="1067" data-start="1046"&gt;Distribution List&lt;/STRONG&gt;, enter the email address or group address that should receive the notification.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H3 data-end="1199" data-start="1149" data-section-id="7y3azq"&gt;2. User Notifications (Cortex XDR 4.0 / XSIAM)&lt;/H3&gt;
&lt;P data-end="1334" data-start="1201"&gt;In newer platform versions, notifications are triggered when a case is resolved or assigned, and these are sent to the assigned user.&lt;/P&gt;
&lt;UL data-is-only-node="" data-is-last-node="" data-end="1449" data-start="1336"&gt;
&lt;LI data-is-last-node="" data-end="1449" data-start="1336" data-section-id="cd0uvo"&gt;Users can manage these personal notifications through &lt;STRONG data-end="1422" data-start="1392"&gt;Default User Notifications&lt;/STRONG&gt; in their profile settings.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2026 04:59:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/get-notified-when-a-case-is-assigned/m-p/1260284#M9469</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-07-29T04:59:00Z</dc:date>
    </item>
  </channel>
</rss>

