<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sending case to a third party tickiting system in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/sending-case-to-a-third-party-tickiting-system/m-p/1261695#M9498</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i hope you re doing well i want to know the steps to send cases when there generated to our third party tickiting system , how to do it via API or weebhook.&lt;/P&gt;
&lt;P&gt;can someone already worked on a similare case share with me all the steps and configuration required.&lt;/P&gt;
&lt;P&gt;thanks in advance&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Aug 2026 08:11:46 GMT</pubDate>
    <dc:creator>A.BELKAHLA</dc:creator>
    <dc:date>2026-08-13T08:11:46Z</dc:date>
    <item>
      <title>Sending case to a third party tickiting system</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/sending-case-to-a-third-party-tickiting-system/m-p/1261695#M9498</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i hope you re doing well i want to know the steps to send cases when there generated to our third party tickiting system , how to do it via API or weebhook.&lt;/P&gt;
&lt;P&gt;can someone already worked on a similare case share with me all the steps and configuration required.&lt;/P&gt;
&lt;P&gt;thanks in advance&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2026 08:11:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/sending-case-to-a-third-party-tickiting-system/m-p/1261695#M9498</guid>
      <dc:creator>A.BELKAHLA</dc:creator>
      <dc:date>2026-08-13T08:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: Sending case to a third party tickiting system</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/sending-case-to-a-third-party-tickiting-system/m-p/1261723#M9499</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/731754273"&gt;@A.BELKAHLA&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P class="p8i6j01 paragraph"&gt;To send Cortex XDR incidents (cases) to a third-party ticketing system, you should use the &lt;STRONG&gt;Forwarding&lt;/STRONG&gt; feature in combination with a &lt;STRONG&gt;Webhook&lt;/STRONG&gt; or the &lt;STRONG&gt;Public API&lt;/STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P class="p8i6j01 paragraph"&gt;I have outlined the specific steps and configurations below.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H4 class="wnfdnti _1ibi0s33y _1ibi0s34u" dir="auto" data-pm-slice="1 1 []"&gt;Step 1: Create a Webhook Integration Profile&lt;/H4&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;First, you must define the connection details for your ticketing system.&lt;/P&gt;
&lt;OL class="wnfdntg" dir="auto"&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;Log in to the &lt;STRONG&gt;Cortex XDR console&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;Navigate to &lt;STRONG&gt;Settings &amp;gt; Configurations &amp;gt; Integrations &amp;gt; External Services&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;Click &lt;STRONG&gt;+ Add Webhook&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;Configure the following fields:&lt;/P&gt;
&lt;UL class="wnfdntf" dir="auto"&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;&lt;STRONG&gt;Name&lt;/STRONG&gt;: A descriptive name (e.g., &lt;CODE&gt;Corporate_Jira_Service_Desk&lt;/CODE&gt;).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;&lt;STRONG&gt;URL&lt;/STRONG&gt;: The API endpoint of your ticketing system (e.g., &lt;CODE&gt;&lt;A href="https://api.yourticketing.com/v1/tickets" target="_blank"&gt;https://api.yourticketing.com/v1/tickets&lt;/A&gt;&lt;/CODE&gt;).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;&lt;STRONG&gt;Method&lt;/STRONG&gt;: Select &lt;CODE&gt;POST&lt;/CODE&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;&lt;STRONG&gt;Headers&lt;/STRONG&gt;: Add any required headers for authentication (e.g., &lt;CODE&gt;Authorization: Bearer &amp;lt;token&amp;gt;&lt;/CODE&gt; and &lt;CODE&gt;Content-Type: application/json&lt;/CODE&gt;).&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;&lt;STRONG&gt;Payload Configuration&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL class="wnfdntf" dir="auto"&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;Select &lt;STRONG&gt;Custom Payload&lt;/STRONG&gt; to match the JSON schema required by your ticketing system.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;Use dynamic placeholders to map Cortex data to your ticket fields. Common placeholders include:&lt;/P&gt;
&lt;UL class="wnfdntf" dir="auto"&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;&lt;CODE&gt;${incident_id}&lt;/CODE&gt;: The unique XDR incident ID.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;&lt;CODE&gt;${description}&lt;/CODE&gt;: Summary of the threat.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;&lt;CODE&gt;${severity}&lt;/CODE&gt;: Critical, High, Medium, or Low.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;&lt;CODE&gt;${incident_sources}&lt;/CODE&gt;: The originating security modules.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;H2 class="wnfdnti _1ibi0s33y _1ibi0s34u" dir="auto"&gt;Step 2: Configure Incident Forwarding Rules&lt;/H2&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;Once the webhook is defined, you must tell Cortex XDR which incidents to send.&lt;/P&gt;
&lt;OL class="wnfdntg" dir="auto"&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;Navigate to &lt;STRONG&gt;Settings &amp;gt; Configurations &amp;gt; General &amp;gt; Forwarding&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;Click &lt;STRONG&gt;+ New Rule&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;Set the following parameters:&lt;/P&gt;
&lt;UL class="wnfdntf" dir="auto"&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;&lt;STRONG&gt;Status&lt;/STRONG&gt;: &lt;CODE&gt;Enabled&lt;/CODE&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;&lt;STRONG&gt;Log Type&lt;/STRONG&gt;: Select &lt;CODE&gt;Incident&lt;/CODE&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;&lt;STRONG&gt;Filters&lt;/STRONG&gt;: Define which incidents trigger a ticket. (e.g., &lt;CODE&gt;Severity = High&lt;/CODE&gt; OR &lt;CODE&gt;Severity = Critical&lt;/CODE&gt;).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;&lt;STRONG&gt;Target&lt;/STRONG&gt;: Select the Webhook profile you created in Step 1.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;Click &lt;STRONG&gt;Save&lt;/STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;H2 class="wnfdnti _1ibi0s33y _1ibi0s34u" dir="auto"&gt;Step 3: Verification&lt;/H2&gt;
&lt;OL class="wnfdntg" dir="auto"&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;Within the Webhook configuration screen, use the &lt;STRONG&gt;Test&lt;/STRONG&gt; button to send a sample payload to your ticketing system.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;Verify that a "test" ticket is successfully created in your third-party system.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;Check the &lt;STRONG&gt;Jobs&lt;/STRONG&gt; or &lt;STRONG&gt;System Logs&lt;/STRONG&gt; in Cortex XDR if the test fails to troubleshoot connectivity or authentication errors.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;H4 class="wnfdnti _1ibi0s33y _1ibi0s34u" dir="auto"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 class="wnfdnti _1ibi0s33y _1ibi0s34u" dir="auto"&gt;Alternative: Pulling via Public API&lt;/H4&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;If your system prefers to "pull" data rather than receive "pushes," use the following:&lt;/P&gt;
&lt;OL class="wnfdntg" dir="auto"&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;&lt;STRONG&gt;Generate API Key&lt;/STRONG&gt;: Go to &lt;STRONG&gt;Settings &amp;gt; Configurations &amp;gt; Integrations &amp;gt; API Keys&lt;/STRONG&gt; and create a key with &lt;CODE&gt;Security Admin&lt;/CODE&gt; or &lt;CODE&gt;Instance Administrator&lt;/CODE&gt; permissions.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;&lt;STRONG&gt;API Endpoint&lt;/STRONG&gt;: Use &lt;CODE&gt;POST /incidents/get_incidents/&lt;/CODE&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="wnfdnte _1ibi0s33w" dir="auto"&gt;
&lt;P class="wnfdntu _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea"&gt;&lt;STRONG&gt;Logic&lt;/STRONG&gt;: Configure your internal system to query this endpoint every 5–10 minutes, filtering for incidents with a &lt;CODE&gt;creation_time&lt;/CODE&gt; newer than the last successful pull.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2026 13:07:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/sending-case-to-a-third-party-tickiting-system/m-p/1261723#M9499</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-08-13T13:07:08Z</dc:date>
    </item>
  </channel>
</rss>

