<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Severity in correlations in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/severity-in-correlations/m-p/1231738#M209</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/618763197"&gt;@LeandroKopke&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm assuming that you're already having a dedicated field for severity in your query&lt;/P&gt;
&lt;P&gt;such as&amp;nbsp;&lt;/P&gt;
&lt;P&gt;| alter alert_severity = json_extract_scalar(_alert_data, "$.severity")&lt;/P&gt;
&lt;P&gt;You've already selected user defined and chose the right field&amp;nbsp;to match an item within the dropdown list, other wise, it's gonna set to Medium by default&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would you please share a sample of your query?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AElzedy_1-1749841182151.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68036i0F8913E825067ECD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AElzedy_1-1749841182151.png" alt="AElzedy_1-1749841182151.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Jun 2025 19:09:22 GMT</pubDate>
    <dc:creator>A.Elzedy</dc:creator>
    <dc:date>2025-06-13T19:09:22Z</dc:date>
    <item>
      <title>Severity in correlations</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/severity-in-correlations/m-p/1219356#M150</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;
&lt;P&gt;Could you help me with the severity field of the correlation?&lt;/P&gt;
&lt;P&gt;I need to customize the severity of the alert based on the user who triggers the query. &lt;BR /&gt;The query is already made. When I configure the correlation to get this severity, it ignores it and sets any alert as "Medium" whereas the severities were supposed to be "high" or "informational" (this one to open an incident)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Do you know what could be happening and where the incident is inheriting this severity from?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 16:27:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/severity-in-correlations/m-p/1219356#M150</guid>
      <dc:creator>LeandroKopke</dc:creator>
      <dc:date>2025-02-04T16:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: Severity in correlations</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/severity-in-correlations/m-p/1231738#M209</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/618763197"&gt;@LeandroKopke&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm assuming that you're already having a dedicated field for severity in your query&lt;/P&gt;
&lt;P&gt;such as&amp;nbsp;&lt;/P&gt;
&lt;P&gt;| alter alert_severity = json_extract_scalar(_alert_data, "$.severity")&lt;/P&gt;
&lt;P&gt;You've already selected user defined and chose the right field&amp;nbsp;to match an item within the dropdown list, other wise, it's gonna set to Medium by default&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would you please share a sample of your query?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AElzedy_1-1749841182151.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68036i0F8913E825067ECD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AElzedy_1-1749841182151.png" alt="AElzedy_1-1749841182151.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jun 2025 19:09:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/severity-in-correlations/m-p/1231738#M209</guid>
      <dc:creator>A.Elzedy</dc:creator>
      <dc:date>2025-06-13T19:09:22Z</dc:date>
    </item>
  </channel>
</rss>

