<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XSIAM - API Get Correlation Rules - Least Priviledge in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/xsiam-api-get-correlation-rules-least-priviledge/m-p/1251876#M390</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/150470069"&gt;@J.MuozTriguero&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;DIV class="flex flex-col text-sm pb-25"&gt;
&lt;SECTION class="text-token-text-primary w-full focus:outline-none [--shadow-height:45px] has-data-writing-block:pointer-events-none has-data-writing-block:-mt-(--shadow-height) has-data-writing-block:pt-(--shadow-height) [&amp;amp;:has([data-writing-block])&amp;gt;*]:pointer-events-auto scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" data-turn="assistant" data-scroll-anchor="true" data-testid="conversation-turn-4" data-turn-id="request-WEB:017d91c7-dad3-439e-8b53-b1dcd19ec90c-1"&gt;
&lt;DIV class="text-base my-auto mx-auto pb-10 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)"&gt;
&lt;DIV class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn"&gt;
&lt;DIV class="flex max-w-full flex-col gap-4 grow"&gt;
&lt;DIV class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal outline-none keyboard-focused:focus-ring [.text-message+&amp;amp;]:mt-1" dir="auto" tabindex="0" data-turn-start-message="true" data-message-model-slug="gpt-5-3" data-message-id="a4ec2bb3-e4e9-4018-a352-ebf3e1ad344b" data-message-author-role="assistant"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden"&gt;
&lt;DIV class="markdown prose dark:prose-invert w-full wrap-break-word light markdown-new-styling"&gt;
&lt;H3 data-section-id="1irqvfe" data-end="35" data-start="0"&gt;Custom Role for Correlation API&lt;/H3&gt;
&lt;P data-end="304" data-start="37"&gt;No, it is currently not possible to create a custom role with sufficient permissions to execute the &lt;CODE data-end="170" data-start="137"&gt;/public_api/v1/correlations/get&lt;/CODE&gt; endpoint. This function is hard-coded by design to require either the built-in &lt;STRONG data-end="276" data-start="250"&gt;Instance Administrator&lt;/STRONG&gt; or &lt;STRONG data-end="297" data-start="280"&gt;Account Admin&lt;/STRONG&gt; roles.&lt;/P&gt;
&lt;P data-end="304" data-start="37"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="708" data-start="306"&gt;Attempts to use custom roles—even those granted the highest visible permissions (such as "View/Edit" for "Rules" or "Public API")—will result in a &lt;STRONG data-end="470" data-start="453"&gt;403 Forbidden&lt;/STRONG&gt; error with the message &lt;EM data-end="535" data-start="494"&gt;“Insufficient permissions for api key.”&lt;/EM&gt; This is a known product limitation, and feature requests (such as CXDR-I-2505) have been raised to enable more granular RBAC for administrative API endpoints in the future.&lt;/P&gt;
&lt;P data-end="708" data-start="306"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="757" data-start="715" data-section-id="137gkkz"&gt;Alternative Ways to Retrieve the Query&lt;/H4&gt;
&lt;P data-end="904" data-start="759"&gt;If you cannot use the Instance Administrator role for an API key, here are alternative methods to retrieve the XQL query from a correlation rule:&lt;/P&gt;
&lt;H4 data-end="934" data-start="906"&gt;Management Console (UI)&lt;/H4&gt;
&lt;P data-end="1120" data-start="935"&gt;Users with sufficient RBAC permissions (typically &lt;STRONG data-end="1035" data-start="985"&gt;Detections &amp;amp; Threat Intel &amp;gt; Detections &amp;gt; Rules&lt;/STRONG&gt; set to &lt;EM data-end="1049" data-start="1043"&gt;View&lt;/EM&gt; or &lt;EM data-end="1064" data-start="1053"&gt;View/Edit&lt;/EM&gt;) can manually retrieve the query via the web interface:&lt;/P&gt;
&lt;UL data-end="1360" data-start="1122"&gt;
&lt;LI data-end="1198" data-start="1122" data-section-id="1ncew8j"&gt;Navigate to &lt;STRONG data-end="1198" data-start="1136"&gt;Detections &amp;amp; Threat Intel → Detection Rules → Correlations&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI data-end="1308" data-start="1199" data-section-id="ijkhe6"&gt;Right-click the specific rule and select &lt;STRONG data-end="1257" data-start="1242"&gt;Open in XQL&lt;/STRONG&gt; to view the underlying query in the Query Center&lt;/LI&gt;
&lt;LI data-end="1360" data-start="1309" data-section-id="e1sx5c"&gt;Or select &lt;STRONG data-end="1329" data-start="1321"&gt;Edit&lt;/STRONG&gt; to view the rule configuration&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1636" data-start="1362"&gt;&lt;STRONG data-end="1371" data-start="1362"&gt;Note:&lt;/STRONG&gt;&lt;BR data-end="1374" data-start="1371" /&gt;If a rule uses a dataset that does not exist in the tenant (for example, a rule imported from the Marketplace for a source not yet ingested), it will be hidden from non-admin users. Only &lt;STRONG data-end="1588" data-start="1561"&gt;Instance Administrators&lt;/STRONG&gt; can view rules linked to non-existent datasets.&lt;/P&gt;
&lt;H4 data-end="1681" data-start="1643"&gt;&lt;BR /&gt;Scripting with Instance Admin Key&lt;/H4&gt;
&lt;P data-end="1779" data-start="1682"&gt;If your goal is automation, you must use an API key assigned the &lt;STRONG data-end="1773" data-start="1747"&gt;Instance Administrator&lt;/STRONG&gt; role.&lt;/P&gt;
&lt;P data-end="1779" data-start="1682"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1840" data-start="1781"&gt;You can verify connectivity by testing a standard endpoint:&lt;/P&gt;
&lt;P data-end="1840" data-start="1781"&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="w-full overflow-x-hidden overflow-y-auto pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼ5 ͼj" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;curl -X POST &lt;A href="https://api-[TENANT_FQDN]/public_api/v1/endpoints/get_endpoints" target="_blank"&gt;https://api-[TENANT_FQDN]/public_api/v1/endpoints/get_endpoints&lt;/A&gt; \&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; -H "x-xdr-auth-id:[KEY_ID]" \&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; -H "Authorization:[API_KEY]" \&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; -H "Content-Type:application/json" \&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; -d '{"request_data": {}}'&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;H4&gt;&lt;SPAN&gt;Additional Requirement:&lt;/SPAN&gt;&lt;/H4&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-is-only-node="" data-is-last-node="" data-end="2392" data-start="2095"&gt;The &lt;CODE data-end="2132" data-start="2099"&gt;/public_api/v1/correlations/get&lt;/CODE&gt; endpoint is often disabled by default for new tenants. If you are an Instance Administrator and still receive errors indicating the resource is unavailable, you may need to contact support to have the internal server-side feature flag enabled for your tenant.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="z-0 flex min-h-[46px] justify-start"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;/DIV&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&lt;/STRONG&gt;&amp;nbsp;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
    <pubDate>Wed, 08 Apr 2026 15:11:17 GMT</pubDate>
    <dc:creator>susekar</dc:creator>
    <dc:date>2026-04-08T15:11:17Z</dc:date>
    <item>
      <title>XSIAM - API Get Correlation Rules - Least Priviledge</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/xsiam-api-get-correlation-rules-least-priviledge/m-p/1251719#M386</link>
      <description>&lt;DIV&gt;
&lt;P&gt;In the API reference, it states that you must have &lt;STRONG&gt;Instance Administrator&lt;/STRONG&gt; permissions to run the endpoint &lt;CODE&gt;/public_api/v1/correlations/get&lt;/CODE&gt;.&lt;/P&gt;
&lt;P&gt;Is it possible to create a custom role for the API key that has sufficient permissions to execute this endpoint?&lt;/P&gt;
&lt;P&gt;Do you know any other way to retrieve the query from a specific correlation rule?&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;LI-PRODUCT title="Cortex XSIAM" id="Cortex_XSIAM"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2026 06:50:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/xsiam-api-get-correlation-rules-least-priviledge/m-p/1251719#M386</guid>
      <dc:creator>J.MuozTriguero</dc:creator>
      <dc:date>2026-04-07T06:50:38Z</dc:date>
    </item>
    <item>
      <title>Re: XSIAM - API Get Correlation Rules - Least Priviledge</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/xsiam-api-get-correlation-rules-least-priviledge/m-p/1251876#M390</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/150470069"&gt;@J.MuozTriguero&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;DIV class="flex flex-col text-sm pb-25"&gt;
&lt;SECTION class="text-token-text-primary w-full focus:outline-none [--shadow-height:45px] has-data-writing-block:pointer-events-none has-data-writing-block:-mt-(--shadow-height) has-data-writing-block:pt-(--shadow-height) [&amp;amp;:has([data-writing-block])&amp;gt;*]:pointer-events-auto scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" data-turn="assistant" data-scroll-anchor="true" data-testid="conversation-turn-4" data-turn-id="request-WEB:017d91c7-dad3-439e-8b53-b1dcd19ec90c-1"&gt;
&lt;DIV class="text-base my-auto mx-auto pb-10 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)"&gt;
&lt;DIV class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn"&gt;
&lt;DIV class="flex max-w-full flex-col gap-4 grow"&gt;
&lt;DIV class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal outline-none keyboard-focused:focus-ring [.text-message+&amp;amp;]:mt-1" dir="auto" tabindex="0" data-turn-start-message="true" data-message-model-slug="gpt-5-3" data-message-id="a4ec2bb3-e4e9-4018-a352-ebf3e1ad344b" data-message-author-role="assistant"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden"&gt;
&lt;DIV class="markdown prose dark:prose-invert w-full wrap-break-word light markdown-new-styling"&gt;
&lt;H3 data-section-id="1irqvfe" data-end="35" data-start="0"&gt;Custom Role for Correlation API&lt;/H3&gt;
&lt;P data-end="304" data-start="37"&gt;No, it is currently not possible to create a custom role with sufficient permissions to execute the &lt;CODE data-end="170" data-start="137"&gt;/public_api/v1/correlations/get&lt;/CODE&gt; endpoint. This function is hard-coded by design to require either the built-in &lt;STRONG data-end="276" data-start="250"&gt;Instance Administrator&lt;/STRONG&gt; or &lt;STRONG data-end="297" data-start="280"&gt;Account Admin&lt;/STRONG&gt; roles.&lt;/P&gt;
&lt;P data-end="304" data-start="37"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="708" data-start="306"&gt;Attempts to use custom roles—even those granted the highest visible permissions (such as "View/Edit" for "Rules" or "Public API")—will result in a &lt;STRONG data-end="470" data-start="453"&gt;403 Forbidden&lt;/STRONG&gt; error with the message &lt;EM data-end="535" data-start="494"&gt;“Insufficient permissions for api key.”&lt;/EM&gt; This is a known product limitation, and feature requests (such as CXDR-I-2505) have been raised to enable more granular RBAC for administrative API endpoints in the future.&lt;/P&gt;
&lt;P data-end="708" data-start="306"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="757" data-start="715" data-section-id="137gkkz"&gt;Alternative Ways to Retrieve the Query&lt;/H4&gt;
&lt;P data-end="904" data-start="759"&gt;If you cannot use the Instance Administrator role for an API key, here are alternative methods to retrieve the XQL query from a correlation rule:&lt;/P&gt;
&lt;H4 data-end="934" data-start="906"&gt;Management Console (UI)&lt;/H4&gt;
&lt;P data-end="1120" data-start="935"&gt;Users with sufficient RBAC permissions (typically &lt;STRONG data-end="1035" data-start="985"&gt;Detections &amp;amp; Threat Intel &amp;gt; Detections &amp;gt; Rules&lt;/STRONG&gt; set to &lt;EM data-end="1049" data-start="1043"&gt;View&lt;/EM&gt; or &lt;EM data-end="1064" data-start="1053"&gt;View/Edit&lt;/EM&gt;) can manually retrieve the query via the web interface:&lt;/P&gt;
&lt;UL data-end="1360" data-start="1122"&gt;
&lt;LI data-end="1198" data-start="1122" data-section-id="1ncew8j"&gt;Navigate to &lt;STRONG data-end="1198" data-start="1136"&gt;Detections &amp;amp; Threat Intel → Detection Rules → Correlations&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI data-end="1308" data-start="1199" data-section-id="ijkhe6"&gt;Right-click the specific rule and select &lt;STRONG data-end="1257" data-start="1242"&gt;Open in XQL&lt;/STRONG&gt; to view the underlying query in the Query Center&lt;/LI&gt;
&lt;LI data-end="1360" data-start="1309" data-section-id="e1sx5c"&gt;Or select &lt;STRONG data-end="1329" data-start="1321"&gt;Edit&lt;/STRONG&gt; to view the rule configuration&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1636" data-start="1362"&gt;&lt;STRONG data-end="1371" data-start="1362"&gt;Note:&lt;/STRONG&gt;&lt;BR data-end="1374" data-start="1371" /&gt;If a rule uses a dataset that does not exist in the tenant (for example, a rule imported from the Marketplace for a source not yet ingested), it will be hidden from non-admin users. Only &lt;STRONG data-end="1588" data-start="1561"&gt;Instance Administrators&lt;/STRONG&gt; can view rules linked to non-existent datasets.&lt;/P&gt;
&lt;H4 data-end="1681" data-start="1643"&gt;&lt;BR /&gt;Scripting with Instance Admin Key&lt;/H4&gt;
&lt;P data-end="1779" data-start="1682"&gt;If your goal is automation, you must use an API key assigned the &lt;STRONG data-end="1773" data-start="1747"&gt;Instance Administrator&lt;/STRONG&gt; role.&lt;/P&gt;
&lt;P data-end="1779" data-start="1682"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1840" data-start="1781"&gt;You can verify connectivity by testing a standard endpoint:&lt;/P&gt;
&lt;P data-end="1840" data-start="1781"&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="w-full overflow-x-hidden overflow-y-auto pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼ5 ͼj" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;curl -X POST &lt;A href="https://api-[TENANT_FQDN]/public_api/v1/endpoints/get_endpoints" target="_blank"&gt;https://api-[TENANT_FQDN]/public_api/v1/endpoints/get_endpoints&lt;/A&gt; \&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; -H "x-xdr-auth-id:[KEY_ID]" \&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; -H "Authorization:[API_KEY]" \&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; -H "Content-Type:application/json" \&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; -d '{"request_data": {}}'&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;H4&gt;&lt;SPAN&gt;Additional Requirement:&lt;/SPAN&gt;&lt;/H4&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-is-only-node="" data-is-last-node="" data-end="2392" data-start="2095"&gt;The &lt;CODE data-end="2132" data-start="2099"&gt;/public_api/v1/correlations/get&lt;/CODE&gt; endpoint is often disabled by default for new tenants. If you are an Instance Administrator and still receive errors indicating the resource is unavailable, you may need to contact support to have the internal server-side feature flag enabled for your tenant.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="z-0 flex min-h-[46px] justify-start"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;/DIV&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&lt;/STRONG&gt;&amp;nbsp;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2026 15:11:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/xsiam-api-get-correlation-rules-least-priviledge/m-p/1251876#M390</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-04-08T15:11:17Z</dc:date>
    </item>
  </channel>
</rss>

