<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Guidance on Automating Alert Notifications in Cortex XSIAM Using Playbooks (Future SNOW Integration) in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/guidance-on-automating-alert-notifications-in-cortex-xsiam-using/m-p/1234555#M234</link>
    <description>&lt;P data-start="328" data-end="343"&gt;Hello everyone,&lt;/P&gt;
&lt;P data-start="345" data-end="691"&gt;I'm currently exploring Cortex XSIAM as part of my day-to-day responsibilities, and I’m working on automating alert notifications using native playbooks particularly for &lt;STRONG&gt;mail notifications triggered by specific alerts&lt;/STRONG&gt;&lt;SPAN&gt;, like "port scan"&lt;/SPAN&gt;. The end goal is to reduce manual handling, potentially via email.&lt;/P&gt;
&lt;P data-start="693" data-end="1024"&gt;As a first step, I’d like to create a basic playbook that sends automatic email alerts when certain conditions are met (ex. specific alert names ). Once that’s in place, my plan is to integrate this workflow with &lt;STRONG data-start="921" data-end="935"&gt;ServiceNow&lt;/STRONG&gt;&amp;nbsp; to generate and manage tickets from Cortex XSIAM incidents.&lt;/P&gt;
&lt;P data-start="1026" data-end="1067"&gt;I'm reaching out&amp;nbsp; to ask:&lt;/P&gt;
&lt;UL data-start="1068" data-end="1343"&gt;
&lt;LI data-start="1068" data-end="1125"&gt;
&lt;P data-start="1070" data-end="1125"&gt;Has anyone here implemented similar use cases in XSIAM?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1126" data-end="1260"&gt;
&lt;P data-start="1128" data-end="1260"&gt;Are there any best practices or documentation you'd recommend, particularly around designing efficient playbooks for alert handling?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1261" data-end="1343"&gt;
&lt;P data-start="1263" data-end="1343"&gt;Any advice for a beginner in automating operational security tasks inside XSIAM?&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="1345" data-end="1440"&gt;Thanks in advance!&lt;/P&gt;
&lt;P data-start="1442" data-end="1481"&gt;Best regards,&lt;/P&gt;</description>
    <pubDate>Wed, 23 Jul 2025 16:22:09 GMT</pubDate>
    <dc:creator>I.JuvillaGonzalez</dc:creator>
    <dc:date>2025-07-23T16:22:09Z</dc:date>
    <item>
      <title>Guidance on Automating Alert Notifications in Cortex XSIAM Using Playbooks (Future SNOW Integration)</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/guidance-on-automating-alert-notifications-in-cortex-xsiam-using/m-p/1234555#M234</link>
      <description>&lt;P data-start="328" data-end="343"&gt;Hello everyone,&lt;/P&gt;
&lt;P data-start="345" data-end="691"&gt;I'm currently exploring Cortex XSIAM as part of my day-to-day responsibilities, and I’m working on automating alert notifications using native playbooks particularly for &lt;STRONG&gt;mail notifications triggered by specific alerts&lt;/STRONG&gt;&lt;SPAN&gt;, like "port scan"&lt;/SPAN&gt;. The end goal is to reduce manual handling, potentially via email.&lt;/P&gt;
&lt;P data-start="693" data-end="1024"&gt;As a first step, I’d like to create a basic playbook that sends automatic email alerts when certain conditions are met (ex. specific alert names ). Once that’s in place, my plan is to integrate this workflow with &lt;STRONG data-start="921" data-end="935"&gt;ServiceNow&lt;/STRONG&gt;&amp;nbsp; to generate and manage tickets from Cortex XSIAM incidents.&lt;/P&gt;
&lt;P data-start="1026" data-end="1067"&gt;I'm reaching out&amp;nbsp; to ask:&lt;/P&gt;
&lt;UL data-start="1068" data-end="1343"&gt;
&lt;LI data-start="1068" data-end="1125"&gt;
&lt;P data-start="1070" data-end="1125"&gt;Has anyone here implemented similar use cases in XSIAM?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1126" data-end="1260"&gt;
&lt;P data-start="1128" data-end="1260"&gt;Are there any best practices or documentation you'd recommend, particularly around designing efficient playbooks for alert handling?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1261" data-end="1343"&gt;
&lt;P data-start="1263" data-end="1343"&gt;Any advice for a beginner in automating operational security tasks inside XSIAM?&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="1345" data-end="1440"&gt;Thanks in advance!&lt;/P&gt;
&lt;P data-start="1442" data-end="1481"&gt;Best regards,&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 16:22:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/guidance-on-automating-alert-notifications-in-cortex-xsiam-using/m-p/1234555#M234</guid>
      <dc:creator>I.JuvillaGonzalez</dc:creator>
      <dc:date>2025-07-23T16:22:09Z</dc:date>
    </item>
  </channel>
</rss>

