<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AI Prompt Feature | XSIAM Version  3.4 in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/ai-prompt-feature-xsiam-version-3-4/m-p/1249651#M368</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;Does anyone tested the AI prompt feature in XSIAM version 3.4?&lt;/P&gt;
&lt;P&gt;From our experience, only generic prompts seem to be working. When we try to use specific real-time case or issue data, it doesn't respond as expected.&lt;/P&gt;
&lt;P&gt;We haven't been able to test out-of-the-box or custom prompts using input data like Issue ID or Issue Name, as the AI prompt can't access real-time data for analysis.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone else encountered this issue?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 08 Mar 2026 14:15:30 GMT</pubDate>
    <dc:creator>A.Velusamy</dc:creator>
    <dc:date>2026-03-08T14:15:30Z</dc:date>
    <item>
      <title>AI Prompt Feature | XSIAM Version  3.4</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/ai-prompt-feature-xsiam-version-3-4/m-p/1249651#M368</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;Does anyone tested the AI prompt feature in XSIAM version 3.4?&lt;/P&gt;
&lt;P&gt;From our experience, only generic prompts seem to be working. When we try to use specific real-time case or issue data, it doesn't respond as expected.&lt;/P&gt;
&lt;P&gt;We haven't been able to test out-of-the-box or custom prompts using input data like Issue ID or Issue Name, as the AI prompt can't access real-time data for analysis.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone else encountered this issue?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2026 14:15:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/ai-prompt-feature-xsiam-version-3-4/m-p/1249651#M368</guid>
      <dc:creator>A.Velusamy</dc:creator>
      <dc:date>2026-03-08T14:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: AI Prompt Feature | XSIAM Version  3.4</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/ai-prompt-feature-xsiam-version-3-4/m-p/1249849#M369</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1401872841"&gt;@A.Velusamy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="flex flex-col text-sm"&gt;
&lt;ARTICLE class="text-token-text-primary w-full focus:outline-none [--shadow-height:45px] has-data-writing-block:pointer-events-none has-data-writing-block:-mt-(--shadow-height) has-data-writing-block:pt-(--shadow-height) [&amp;amp;:has([data-writing-block])&amp;gt;*]:pointer-events-auto scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" tabindex="-1" data-turn="assistant" data-scroll-anchor="true" data-testid="conversation-turn-6" data-turn-id="request-WEB:c1365fa0-747e-4dd5-be11-3b1d10131385-2"&gt;
&lt;DIV class="text-base my-auto mx-auto pb-10 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)"&gt;
&lt;DIV class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn" tabindex="-1"&gt;
&lt;DIV class="flex max-w-full flex-col gap-4 grow"&gt;
&lt;DIV class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal [.text-message+&amp;amp;]:mt-1" dir="auto" data-message-model-slug="gpt-5-3" data-message-id="011709ec-ce27-4c16-b109-86912fb5e852" data-message-author-role="assistant"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden"&gt;
&lt;DIV class="markdown prose dark:prose-invert w-full wrap-break-word light markdown-new-styling"&gt;
&lt;P data-end="400" data-start="0"&gt;In Cortex XSIAM version 3.4, the AI prompt feature (often associated with the Agentic Assistant or AgentiX) requires specific variable mapping and syntax to access real-time case or issue data. Based on internal investigations and engineering guidance, simply inputting a static Issue ID or Name is insufficient because the AI model needs a reference to the actual context object to perform analysis.&lt;/P&gt;
&lt;H4 data-end="450" data-start="402" data-section-id="1ytugmr"&gt;Key Requirements for Accessing Real-Time Data:&lt;/H4&gt;
&lt;H4 data-end="483" data-start="452" data-section-id="co6zlg"&gt;Use Correct Variable Syntax&lt;/H4&gt;
&lt;P data-end="695" data-start="484"&gt;When executing prompts like &lt;STRONG data-end="542" data-start="512"&gt;IssueSummaryAndRemediation&lt;/STRONG&gt;, you must provide the path to the issue object in the context rather than a manual ID string. The required syntax (based on the AI Prompts playbook) is:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼ5 ͼj" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;!IssueSummaryAndRemediation issue=${issue}&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;H4&gt;&lt;SPAN&gt;Execution Environment:&lt;/SPAN&gt;&lt;/H4&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="872" data-start="775"&gt;These prompts must be run from a location where the issue context is natively available, such as:&lt;/P&gt;
&lt;UL data-end="944" data-start="874"&gt;
&lt;LI data-end="898" data-start="874" data-section-id="1npq0fn"&gt;
&lt;P data-end="898" data-start="876"&gt;The &lt;STRONG data-end="898" data-start="880"&gt;Issue War Room&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="944" data-start="899" data-section-id="147sh3"&gt;
&lt;P data-end="944" data-start="901"&gt;A &lt;STRONG data-end="915" data-start="903"&gt;Playbook&lt;/STRONG&gt; within the issue's work plan&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1063" data-start="946"&gt;Running them from a &lt;STRONG data-end="980" data-start="966"&gt;Playground&lt;/STRONG&gt; environment without a loaded context will result in failures or generic responses.&lt;/P&gt;
&lt;H4 data-end="1096" data-start="1065" data-section-id="7brzgs"&gt;Core Integration Dependency&lt;/H4&gt;
&lt;P data-end="1197" data-start="1097"&gt;The AI Agent relies on the &lt;STRONG data-end="1150" data-start="1124"&gt;Cortex Platform - Core&lt;/STRONG&gt; integration to interact with cases and issues.&lt;/P&gt;
&lt;P data-end="1211" data-start="1199"&gt;Ensure that:&lt;/P&gt;
&lt;UL data-is-only-node="" data-is-last-node="" data-end="1398" data-start="1212"&gt;
&lt;LI data-end="1296" data-start="1212" data-section-id="uutvx7"&gt;
&lt;P data-end="1296" data-start="1214"&gt;The &lt;STRONG data-end="1244" data-start="1218"&gt;Cortex Platform - Core&lt;/STRONG&gt; content pack is installed from the &lt;STRONG data-end="1295" data-start="1280"&gt;Marketplace&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-is-last-node="" data-end="1398" data-start="1297" data-section-id="knmddk"&gt;
&lt;P data-is-last-node="" data-end="1398" data-start="1299"&gt;An integration instance is configured and enabled under &lt;STRONG data-end="1397" data-start="1355"&gt;Settings &amp;gt; Data Sources &amp;gt; Integrations&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="z-0 flex min-h-[46px] justify-start"&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/ARTICLE&gt;
&lt;/DIV&gt;
&lt;DIV class="pointer-events-none h-px w-px absolute bottom-0" data-edge="true" aria-hidden="true"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 10 Mar 2026 14:17:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/ai-prompt-feature-xsiam-version-3-4/m-p/1249849#M369</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-03-10T14:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: AI Prompt Feature | XSIAM Version  3.4</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/ai-prompt-feature-xsiam-version-3-4/m-p/1249884#M370</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/241098"&gt;@susekar&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;DIV class="flex flex-col text-sm"&gt;
&lt;ARTICLE class="text-token-text-primary w-full focus:outline-none [--shadow-height:45px] has-data-writing-block:pointer-events-none has-data-writing-block:-mt-(--shadow-height) has-data-writing-block:pt-(--shadow-height) [&amp;amp;:has([data-writing-block])&amp;gt;*]:pointer-events-auto scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" tabindex="-1" data-turn="assistant" data-scroll-anchor="true" data-testid="conversation-turn-6" data-turn-id="request-WEB:c1365fa0-747e-4dd5-be11-3b1d10131385-2"&gt;
&lt;DIV class="text-base my-auto mx-auto pb-10 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)"&gt;
&lt;DIV class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn" tabindex="-1"&gt;
&lt;DIV class="flex max-w-full flex-col gap-4 grow"&gt;
&lt;DIV class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal [.text-message+&amp;amp;]:mt-1" dir="auto" data-message-model-slug="gpt-5-3" data-message-id="011709ec-ce27-4c16-b109-86912fb5e852" data-message-author-role="assistant"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden"&gt;
&lt;DIV class="markdown prose dark:prose-invert w-full wrap-break-word light markdown-new-styling"&gt;
&lt;P data-end="872" data-start="775"&gt;These prompts must be run from a location where the issue context is natively available, such as:&lt;/P&gt;
&lt;UL data-end="944" data-start="874"&gt;
&lt;LI data-end="898" data-start="874" data-section-id="1npq0fn"&gt;
&lt;P data-end="898" data-start="876"&gt;The &lt;STRONG data-end="898" data-start="880"&gt;Issue War Room&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="944" data-start="899" data-section-id="147sh3"&gt;
&lt;P data-end="944" data-start="901"&gt;A &lt;STRONG data-end="915" data-start="903"&gt;Playbook&lt;/STRONG&gt; within the issue's work plan&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/ARTICLE&gt;
&lt;/DIV&gt;
&lt;DIV class="pointer-events-none h-px w-px absolute bottom-0" data-edge="true" aria-hidden="true"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;this is not true. I tested this just now in an arbitrary XQL tab in our environment (no issue context), and was able to access arbitrary issues, see screenshot. The !IssueSummaryAndRemediation issue=12345 was working for me, although the assistant did not recognize the command (no autocomplete). I'm not sure if the agentic assistants support the old !command syntax at all.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1401872841"&gt;@A.Velusamy&lt;/a&gt;&amp;nbsp;There might be some setup steps still missing in your environment as mentioned by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/241098"&gt;@susekar&lt;/a&gt;&amp;nbsp;, we also needed to activate an additional integation for the Agentic Assistant to work. Would be nice if this information ("this option is not supported because the integartion xx is not enabled") would be a output from the assistant instead of "I can't do that", but hey.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are not really impressed by the Agentic Assistants so far. There are a couple of examples where the functionalities are really impressive, like the following prompt (which was also shown in a webcast):&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;EM&gt;Please extract all IP addresses listed as IOC in this report &lt;A href="https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/" target="_blank" rel="noopener"&gt;https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/&lt;/A&gt; and check if any connection from our environment has been made to any of these addresses of the last 24 hours. You might need to defang the IPs.&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This completed successfully including a completed XQL search (although the assistant did extract the links to other unit42 blocks as IOCs).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the other side, assistants currently fail to generate even the most basic xql queries that don't contain hallucinated commands, we have a support case open for this.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edit: "Fun" fact: if you use a different prompt for basically the same request, you get much more detailed summary, see second screenshot.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2026 20:18:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/ai-prompt-feature-xsiam-version-3-4/m-p/1249884#M370</guid>
      <dc:creator>TobiasHahn</dc:creator>
      <dc:date>2026-03-10T20:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: AI Prompt Feature | XSIAM Version  3.4</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/ai-prompt-feature-xsiam-version-3-4/m-p/1250125#M374</link>
      <description>&lt;P&gt;Yes, AI prompt is not working in the issue war room as well as&amp;nbsp; in the playbook but if we use this command -!IssueSummaryAndRemediation issue=1234 in Agentic Assistant it provides the summary. See the screenshot attached.&amp;nbsp; It won't be helpful if palo alto provides some proper information about this.&lt;/P&gt;
&lt;P&gt;I have enabled and tested -&amp;nbsp;&lt;STRONG data-start="1218" data-end="1244"&gt;Cortex Platform - Core.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2026 05:32:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/ai-prompt-feature-xsiam-version-3-4/m-p/1250125#M374</guid>
      <dc:creator>A.Velusamy</dc:creator>
      <dc:date>2026-03-13T05:32:02Z</dc:date>
    </item>
    <item>
      <title>Re: AI Prompt Feature | XSIAM Version  3.4</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/ai-prompt-feature-xsiam-version-3-4/m-p/1250638#M382</link>
      <description>&lt;P data-end="206" data-start="0"&gt;I don’t think running the command inside an Agentic Assistant chat is how AI Prompts it’s intended to be used. Agentic interprets the command as the task it needs to perform, rather than actually executing the prompt.&lt;/P&gt;
&lt;P data-end="206" data-start="0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="421" data-start="208"&gt;I had the same problem, and what &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/241098"&gt;@susekar&lt;/a&gt;&amp;nbsp;recommended worked for me. I put the prompt into a playbook, and in the input I directly used ${issue}—I didn’t reference specific variables, I just passed the entire alert&lt;/P&gt;
&lt;P data-is-only-node="" data-is-last-node="" data-end="524" data-start="423"&gt;So far it worked, whereas before it didn’t (I was getting the same issue as the creator of this topic.)&lt;/P&gt;</description>
      <pubDate>Sat, 21 Mar 2026 13:29:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/ai-prompt-feature-xsiam-version-3-4/m-p/1250638#M382</guid>
      <dc:creator>Gino</dc:creator>
      <dc:date>2026-03-21T13:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: AI Prompt Feature | XSIAM Version  3.4</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/ai-prompt-feature-xsiam-version-3-4/m-p/1250737#M383</link>
      <description>&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2026 17:34:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/ai-prompt-feature-xsiam-version-3-4/m-p/1250737#M383</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-03-23T17:34:32Z</dc:date>
    </item>
  </channel>
</rss>

