<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Fetched Integrations Objects in XSIAM 3.4 in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/fetched-integrations-objects-in-xsiam-3-4/m-p/1248898#M362</link>
    <description>&lt;P&gt;Good morning Live Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Recently upgraded from XDR to XSIAM.&amp;nbsp; Have never had XSOAR in the past, but worked through POCs at two different orgs, so somewhat familiar, nowhere near proficient.&amp;nbsp; Built some simple automations largely dependent on Marketplace content packs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Working through the Beacon course material slowly but also am starting to tinker.&lt;BR /&gt;&lt;BR /&gt;Looking to ingest incidents from ServiceNow into XSIAM.&amp;nbsp; I have the content pack V2, it's enabled and I can run commands to pull incidents manually in the playground.&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;I crafted my query and updated the instance to only pull down the specific incidents I want from the ServiceNow.&amp;nbsp; I confirmed that I can see in the instance run history that they are being fetched, however, I can't seem to find them anywhere.&lt;BR /&gt;&lt;BR /&gt;In trying to create a playbook automation to turn these objects into cases and configure case mirroring I find that I am unable to figure out how to access these objects from the playbook start as a trigger when they are ingested.&lt;BR /&gt;&lt;BR /&gt;Any ideas how I would manually query these fetched integrations objects to validate that they're there?&amp;nbsp; Once I can confirm they exist in XSIAM, and know how to access them, I can work out how to make them cases.&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;We are under the "Cases and Issues" model.&amp;nbsp; &lt;/P&gt;</description>
    <pubDate>Tue, 24 Feb 2026 15:41:00 GMT</pubDate>
    <dc:creator>mhalbeisen</dc:creator>
    <dc:date>2026-02-24T15:41:00Z</dc:date>
    <item>
      <title>Fetched Integrations Objects in XSIAM 3.4</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/fetched-integrations-objects-in-xsiam-3-4/m-p/1248898#M362</link>
      <description>&lt;P&gt;Good morning Live Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Recently upgraded from XDR to XSIAM.&amp;nbsp; Have never had XSOAR in the past, but worked through POCs at two different orgs, so somewhat familiar, nowhere near proficient.&amp;nbsp; Built some simple automations largely dependent on Marketplace content packs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Working through the Beacon course material slowly but also am starting to tinker.&lt;BR /&gt;&lt;BR /&gt;Looking to ingest incidents from ServiceNow into XSIAM.&amp;nbsp; I have the content pack V2, it's enabled and I can run commands to pull incidents manually in the playground.&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;I crafted my query and updated the instance to only pull down the specific incidents I want from the ServiceNow.&amp;nbsp; I confirmed that I can see in the instance run history that they are being fetched, however, I can't seem to find them anywhere.&lt;BR /&gt;&lt;BR /&gt;In trying to create a playbook automation to turn these objects into cases and configure case mirroring I find that I am unable to figure out how to access these objects from the playbook start as a trigger when they are ingested.&lt;BR /&gt;&lt;BR /&gt;Any ideas how I would manually query these fetched integrations objects to validate that they're there?&amp;nbsp; Once I can confirm they exist in XSIAM, and know how to access them, I can work out how to make them cases.&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;We are under the "Cases and Issues" model.&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 15:41:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/fetched-integrations-objects-in-xsiam-3-4/m-p/1248898#M362</guid>
      <dc:creator>mhalbeisen</dc:creator>
      <dc:date>2026-02-24T15:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: Fetched Integrations Objects in XSIAM 3.4</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/fetched-integrations-objects-in-xsiam-3-4/m-p/1248986#M363</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/194455"&gt;@mhalbeisen&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="348" data-start="0"&gt;In Cortex XSIAM, incidents fetched from ServiceNow are processed through the internal automation engine (XSOAR) and, if successfully mapped, appear as Issues. If you can see that incidents are being fetched in the instance run history but cannot find them in the UI, follow these steps to validate their existence and configure them for automation.&lt;/P&gt;
&lt;P data-end="348" data-start="0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="401" data-start="355"&gt;1. Manually Query Ingested Objects via XQL:&lt;/H4&gt;
&lt;P data-end="658" data-start="403"&gt;To confirm that the ServiceNow incidents have successfully reached XSIAM's raw database, query the dedicated raw dataset using Cortex Query Language (XQL). For the ServiceNow V2 integration, fetched incidents are typically stored in the following dataset:&lt;/P&gt;
&lt;P data-end="658" data-start="403"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="734" data-start="660"&gt;Navigate to &lt;STRONG data-end="725" data-start="672"&gt;Investigation &amp;amp; Response &amp;gt; Search &amp;gt; Query Builder&lt;/STRONG&gt; and run:&lt;/P&gt;
&lt;DIV class="relative w-full my-4"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border corner-superellipse/1.1 border-token-border-light bg-token-bg-elevated-secondary rounded-3xl"&gt;
&lt;DIV class="corner-superellipse/1.1 rounded-3xl bg-token-bg-elevated-secondary"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼ5 ͼj" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;dataset = servicenow_v2_generic_alert_raw&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;| sort desc _time&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P data-end="971" data-start="805"&gt;If this dataset returns results, it confirms the integration is successfully ingesting the data, but the platform has not yet converted these raw objects into Issues.&lt;/P&gt;
&lt;P data-end="971" data-start="805"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="1029" data-start="978"&gt;2. Locate Fetched Objects in the "Issues" Table:&lt;/H4&gt;
&lt;P data-end="1181" data-start="1031"&gt;Under the "Cases and Issues" model, fetched incidents from third-party integrations appear in the &lt;STRONG data-end="1139" data-start="1129"&gt;Issues&lt;/STRONG&gt; table before they are grouped into Cases.&lt;/P&gt;
&lt;P data-end="1281" data-start="1183"&gt;Navigate to &lt;STRONG data-end="1242" data-start="1195"&gt;Incident Response &amp;gt; Cases &amp;amp; Issues &amp;gt; Issues&lt;/STRONG&gt; and check if the records appear there.&lt;/P&gt;
&lt;P data-end="1373" data-start="1283"&gt;If they do not, it is likely because they failed to pass through the Classifier or Mapper.&lt;/P&gt;
&lt;P data-end="1373" data-start="1283"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="1419" data-start="1380"&gt;3. Troubleshooting Missing "Issues":&lt;/H4&gt;
&lt;P data-end="1502" data-start="1421"&gt;If you see the incidents in XQL but not in the Issues table, check the following:&lt;/P&gt;
&lt;P data-end="1844" data-start="1504"&gt;&lt;STRONG data-end="1529" data-start="1504"&gt;Classifier and Mapper&lt;/STRONG&gt;&lt;BR data-end="1532" data-start="1529" /&gt;Every fetching integration requires a Classifier (to determine the incident type) and an Incoming Mapper (to map ServiceNow fields to XSIAM fields). Ensure these are selected in your ServiceNow V2 instance configuration under:&lt;BR data-end="1761" data-start="1758" /&gt;&lt;STRONG data-end="1841" data-start="1761"&gt;Settings &amp;gt; Configurations &amp;gt; Data Collection &amp;gt; Automation &amp;amp; Feed Integrations&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P data-end="1919" data-start="1846"&gt;If these are missing or failing, the objects will be dropped after fetch.&lt;/P&gt;
&lt;P data-end="2186" data-start="1921"&gt;&lt;STRONG data-end="1944" data-start="1921"&gt;Severity Thresholds&lt;/STRONG&gt;&lt;BR data-end="1947" data-start="1944" /&gt;XSIAM may not automatically generate a Case for low-severity issues by design. Ensure the incoming incidents have a severity level high enough to trigger your case generation logic, or manually promote them from the Issues table to a Case.&lt;/P&gt;
&lt;P data-end="2186" data-start="1921"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="2221" data-start="2193"&gt;4. Triggering a Playbook:&lt;/H4&gt;
&lt;P data-end="2327" data-start="2223"&gt;In XSIAM, playbooks do not trigger directly on raw objects; they trigger on Issues via Automation Rules.&lt;/P&gt;
&lt;P data-end="2402" data-start="2329"&gt;Navigate to &lt;STRONG data-end="2401" data-start="2341"&gt;Investigation &amp;amp; Response &amp;gt; Automation &amp;gt; Automation Rules&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P data-end="2427" data-start="2404"&gt;Create a new rule with:&lt;/P&gt;
&lt;UL data-end="2638" data-start="2428"&gt;
&lt;LI data-end="2455" data-start="2428"&gt;
&lt;P data-end="2455" data-start="2430"&gt;&lt;STRONG data-end="2438" data-start="2430"&gt;WHEN&lt;/STRONG&gt;: Issue Created&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="2580" data-start="2456"&gt;
&lt;P data-end="2580" data-start="2458"&gt;&lt;STRONG data-end="2464" data-start="2458"&gt;IF&lt;/STRONG&gt;: Add a filter to target your ServiceNow objects (for example, &lt;CODE data-end="2546" data-start="2527"&gt;Issue Domain = IT&lt;/CODE&gt; or &lt;CODE data-end="2577" data-start="2550"&gt;alert_source = ServiceNow&lt;/CODE&gt;)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="2638" data-start="2581"&gt;
&lt;P data-end="2638" data-start="2583"&gt;&lt;STRONG data-end="2591" data-start="2583"&gt;THEN&lt;/STRONG&gt;: Run Playbook and select your desired playbook&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-end="2666" data-start="2645"&gt;(Summary Checklist)&lt;/H4&gt;
&lt;UL data-is-only-node="" data-is-last-node="" data-end="3029" data-start="2668"&gt;
&lt;LI data-end="2759" data-start="2668"&gt;
&lt;P data-end="2759" data-start="2670"&gt;&lt;STRONG data-end="2690" data-start="2670"&gt;Query validation&lt;/STRONG&gt;: Use &lt;CODE data-end="2739" data-start="2696"&gt;dataset = servicenow_v2_generic_alert_raw&lt;/CODE&gt; in Query Builder.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="2820" data-start="2760"&gt;
&lt;P data-end="2820" data-start="2762"&gt;&lt;STRONG data-end="2782" data-start="2762"&gt;Issue visibility&lt;/STRONG&gt;: Check &lt;STRONG data-end="2817" data-start="2790"&gt;Cases &amp;amp; Issues &amp;gt; Issues&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="2940" data-start="2821"&gt;
&lt;P data-end="2940" data-start="2823"&gt;&lt;STRONG data-end="2840" data-start="2823"&gt;Mapping check&lt;/STRONG&gt;: Ensure the ServiceNow V2 Classifier and Incoming Mapper are enabled in the integration settings.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-is-last-node="" data-end="3029" data-start="2941"&gt;
&lt;P data-is-last-node="" data-end="3029" data-start="2943"&gt;&lt;STRONG data-end="2962" data-start="2943"&gt;Playbook access&lt;/STRONG&gt;: Use Automation Rules to link the ingested Issue to your playbook.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and &lt;STRONG&gt;"marking this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Wed, 25 Feb 2026 14:32:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/fetched-integrations-objects-in-xsiam-3-4/m-p/1248986#M363</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-02-25T14:32:29Z</dc:date>
    </item>
  </channel>
</rss>

