<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do I send an alert to XSOAR? in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-do-i-send-an-alert-to-xsoar/m-p/1220481#M3893</link>
    <description>&lt;P&gt;I see the classify, map and playbook logic in XSOAR and I see that a playbook can ask/pull/poll for info *from* and external tool, which might be done through an integration.&amp;nbsp; But is there a way for an external tool to aynchronously *send/push* an *alert* (not incident) to XSOAR and have XSOAR receive the alert in real time?&amp;nbsp; I can send new *incidents* to XSOAR at the /incident endpoint, but it looks like the external tool must send the JSON that the endpoint expects, and that the classification and mapping logic is bypassed in that case.&amp;nbsp; It appears that the integrations I have looked at will pull/poll the external tool, so the potential efficiency of a push architecture is lost, and the opportunity for real-time reaction is also lost.&amp;nbsp; I'm not sure if the /incident/json endpoint helps.&lt;/P&gt;</description>
    <pubDate>Fri, 14 Feb 2025 20:56:30 GMT</pubDate>
    <dc:creator>J.Knoke935922</dc:creator>
    <dc:date>2025-02-14T20:56:30Z</dc:date>
    <item>
      <title>How do I send an alert to XSOAR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-do-i-send-an-alert-to-xsoar/m-p/1220481#M3893</link>
      <description>&lt;P&gt;I see the classify, map and playbook logic in XSOAR and I see that a playbook can ask/pull/poll for info *from* and external tool, which might be done through an integration.&amp;nbsp; But is there a way for an external tool to aynchronously *send/push* an *alert* (not incident) to XSOAR and have XSOAR receive the alert in real time?&amp;nbsp; I can send new *incidents* to XSOAR at the /incident endpoint, but it looks like the external tool must send the JSON that the endpoint expects, and that the classification and mapping logic is bypassed in that case.&amp;nbsp; It appears that the integrations I have looked at will pull/poll the external tool, so the potential efficiency of a push architecture is lost, and the opportunity for real-time reaction is also lost.&amp;nbsp; I'm not sure if the /incident/json endpoint helps.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 20:56:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-do-i-send-an-alert-to-xsoar/m-p/1220481#M3893</guid>
      <dc:creator>J.Knoke935922</dc:creator>
      <dc:date>2025-02-14T20:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: How do I send an alert to XSOAR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-do-i-send-an-alert-to-xsoar/m-p/1226969#M3990</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/505865829"&gt;@J.Knoke935922&lt;/a&gt;&amp;nbsp;, It isn't easy to understand what you are trying to achieve here. What do you intend to do with the "Alert" you push to the XSOAR from the external tool ? If you want to actively push an alert to the XSOAR you could use Webhooks. You can then update an existing incident at the pre-processing level rather than creating a new incident. If you want to cause a pending task in a playbook to continue you could use this method or perhaps the XSOAR REST API or even entitlement (more advanced email method to receive responses by emails without creating an incident). I know that I have suggested a few possible solutions but you need to be more specific so that we can understand what you want to achieve.&lt;/P&gt;
&lt;P&gt;MSysec&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 11:06:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-do-i-send-an-alert-to-xsoar/m-p/1226969#M3990</guid>
      <dc:creator>michaelsysec242</dc:creator>
      <dc:date>2025-04-21T11:06:16Z</dc:date>
    </item>
  </channel>
</rss>

