<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue stitching in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/issue-stitching/m-p/1257108#M437</link>
    <description>&lt;P&gt;Hello everyone!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;can someone explain me how the issues are stitched into cases in XSIAM?&lt;BR /&gt;Please explain me in detail.&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jun 2026 07:27:11 GMT</pubDate>
    <dc:creator>B.kumar873690</dc:creator>
    <dc:date>2026-06-23T07:27:11Z</dc:date>
    <item>
      <title>Issue stitching</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/issue-stitching/m-p/1257108#M437</link>
      <description>&lt;P&gt;Hello everyone!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;can someone explain me how the issues are stitched into cases in XSIAM?&lt;BR /&gt;Please explain me in detail.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2026 07:27:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/issue-stitching/m-p/1257108#M437</guid>
      <dc:creator>B.kumar873690</dc:creator>
      <dc:date>2026-06-23T07:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: Issue stitching</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/issue-stitching/m-p/1257135#M438</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1685304355"&gt;@B.kumar873690&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="10" data-start="0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="690" data-start="12"&gt;In &lt;STRONG data-end="31" data-start="15"&gt;Cortex XSIAM&lt;/STRONG&gt;, the stitching of Alerts into Issues and Issues into Cases is driven by an AI/ML-based correlation engine designed to build a unified attack narrative from large-scale security telemetry. At the first level, multiple alerts are grouped into an &lt;STRONG data-end="285" data-start="276"&gt;Issue&lt;/STRONG&gt; when XSIAM identifies strong relationships such as shared entities (user, endpoint, IP address, cloud resource, or identity), temporal proximity, behavioral similarity, and process causality (parent-child process relationships). This ensures that individual alerts are not treated in isolation but are instead combined into a single meaningful security story segment representing part of an attack chain.&lt;/P&gt;
&lt;P data-end="690" data-start="12"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1300" data-start="692"&gt;At the next level, multiple &lt;STRONG data-end="755" data-start="720"&gt;Issues are stitched into a Case&lt;/STRONG&gt;, which represents the full end-to-end security incident or attack campaign. This correlation is based on broader relationships such as common entities across issues, matching threat intelligence indicators (IOCs, malware families, attacker infrastructure), and continuity across the attack lifecycle stages like phishing, execution, persistence, lateral movement, and exfiltration. XSIAM uses its ML-driven data model and continuous telemetry enrichment to understand that these separate Issues are actually part of the same coordinated attack.&lt;/P&gt;
&lt;P data-end="1300" data-start="692"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1676" data-start="1302"&gt;Overall, this approach transforms fragmented security data into a single unified Case, enabling SOC teams to investigate the complete attack lifecycle in one place instead of handling multiple disconnected alerts and issues. This significantly reduces alert fatigue, improves investigation efficiency, and supports faster detection and response in modern SOC environments.&lt;/P&gt;
&lt;P data-end="1676" data-start="1302"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1676" data-start="1302"&gt;Reference:&lt;/P&gt;
&lt;P data-end="1676" data-start="1302"&gt;&lt;A href="https://www.paloaltonetworks.com/cyberpedia/what-is-extended-security-intelligence-and-automation-management-xsiam" target="_blank"&gt;https://www.paloaltonetworks.com/cyberpedia/what-is-extended-security-intelligence-and-automation-management-xsiam&lt;/A&gt;&lt;/P&gt;
&lt;P data-end="1676" data-start="1302"&gt;&lt;A href="https://www.paloaltonetworks.com/resources/ebooks/cortex-xsiam" target="_blank"&gt;https://www.paloaltonetworks.com/resources/ebooks/cortex-xsiam&lt;/A&gt;&lt;/P&gt;
&lt;P data-end="1676" data-start="1302"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help other users by clicking ‘Accept as Solution’ if a post helps solve your problem.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/blogs/how-and-why-to-accept-solutions/ba-p/553827" target="_blank"&gt;Read more about how and why to accept solutions.&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1676" data-start="1302"&gt;Best Regards,&lt;/P&gt;
&lt;P data-end="1676" data-start="1302"&gt;Vinothkumar C&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2026 12:32:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/issue-stitching/m-p/1257135#M438</guid>
      <dc:creator>Vinothkumar_SBA</dc:creator>
      <dc:date>2026-06-23T12:32:09Z</dc:date>
    </item>
  </channel>
</rss>

