<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fetching CrowdStrike Next-Gen SIEM Alerts into SOAR in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/fetching-crowdstrike-next-gen-siem-alerts-into-soar/m-p/1249731#M4239</link>
    <description>&lt;DIV&gt;Has anyone here managed to receive alerts directly from CrowdStrike Next-Gen SIEM in XSOAR or XSIAM?&lt;/DIV&gt;</description>
    <pubDate>Mon, 09 Mar 2026 12:49:02 GMT</pubDate>
    <dc:creator>Marcello_Lopes</dc:creator>
    <dc:date>2026-03-09T12:49:02Z</dc:date>
    <item>
      <title>Fetching CrowdStrike Next-Gen SIEM Alerts into SOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/fetching-crowdstrike-next-gen-siem-alerts-into-soar/m-p/1221708#M3912</link>
      <description>&lt;P data-start="81" data-end="95"&gt;Hi everyone,&lt;/P&gt;
&lt;P data-start="97" data-end="261"&gt;How can I fetch Next-Gen SIEM alerts from CrowdStrike into XSOAR? I have already set up my Falcon integration, and I can fetch categories like endpoint detection.&lt;/P&gt;
&lt;P data-start="263" data-end="482"&gt;As seen in the image, there is a query section available to fetch different detections. Additionally, in the fetch types section, there are detection options such as endpoint detection, incident, IDP, OFP, and Mobile etc.&lt;/P&gt;
&lt;P data-start="484" data-end="708"&gt;However, I want to fetch all detections coming directly to Next-Gen SIEM. Is this possible? For example, Next-Gen SIEM includes various detections created through email, cloud, and custom rules etc. How can I fetch all of them?&lt;/P&gt;
&lt;P data-start="710" data-end="717" data-is-last-node="" data-is-only-node=""&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 23 Feb 2025 12:09:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/fetching-crowdstrike-next-gen-siem-alerts-into-soar/m-p/1221708#M3912</guid>
      <dc:creator>O.Isik</dc:creator>
      <dc:date>2025-02-23T12:09:53Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching CrowdStrike Next-Gen SIEM Alerts into SOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/fetching-crowdstrike-next-gen-siem-alerts-into-soar/m-p/1222936#M3933</link>
      <description>&lt;P&gt;Looking at a solution for this as well, in addition to being able to configure a query (not just search endpoints) in their advanced event search as we're migrating from their Humio/LogScale to Crowdstrike NG SIEM&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 18:41:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/fetching-crowdstrike-next-gen-siem-alerts-into-soar/m-p/1222936#M3933</guid>
      <dc:creator>clopianohastey</dc:creator>
      <dc:date>2025-03-06T18:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching CrowdStrike Next-Gen SIEM Alerts into SOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/fetching-crowdstrike-next-gen-siem-alerts-into-soar/m-p/1224914#M3962</link>
      <description>&lt;P&gt;Has there been any resolution to your problem? I would also like to know if there's anyway to fetch the incidents/detections that are created from correlation rules. As you mentioned there are options for the different fetch types, but these do not fetch any alerts made by correlation rules from my experience.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2025 13:28:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/fetching-crowdstrike-next-gen-siem-alerts-into-soar/m-p/1224914#M3962</guid>
      <dc:creator>MustardMan</dc:creator>
      <dc:date>2025-03-27T13:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching CrowdStrike Next-Gen SIEM Alerts into SOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/fetching-crowdstrike-next-gen-siem-alerts-into-soar/m-p/1227804#M4002</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi, there is no existing content pack for CrowdStrike NG SIEM at this moment. However, it is expected to be available soon (most likely by the end of Q2).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 21:11:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/fetching-crowdstrike-next-gen-siem-alerts-into-soar/m-p/1227804#M4002</guid>
      <dc:creator>oromeromoya</dc:creator>
      <dc:date>2025-04-30T21:11:14Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching CrowdStrike Next-Gen SIEM Alerts into SOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/fetching-crowdstrike-next-gen-siem-alerts-into-soar/m-p/1246021#M4228</link>
      <description>&lt;P&gt;Anyone find a method to run adhoc queries against NGSIEM with the current integrations?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 16:05:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/fetching-crowdstrike-next-gen-siem-alerts-into-soar/m-p/1246021#M4228</guid>
      <dc:creator>D.Richards989932</dc:creator>
      <dc:date>2026-01-20T16:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching CrowdStrike Next-Gen SIEM Alerts into SOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/fetching-crowdstrike-next-gen-siem-alerts-into-soar/m-p/1249731#M4239</link>
      <description>&lt;DIV&gt;Has anyone here managed to receive alerts directly from CrowdStrike Next-Gen SIEM in XSOAR or XSIAM?&lt;/DIV&gt;</description>
      <pubDate>Mon, 09 Mar 2026 12:49:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/fetching-crowdstrike-next-gen-siem-alerts-into-soar/m-p/1249731#M4239</guid>
      <dc:creator>Marcello_Lopes</dc:creator>
      <dc:date>2026-03-09T12:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching CrowdStrike Next-Gen SIEM Alerts into SOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/fetching-crowdstrike-next-gen-siem-alerts-into-soar/m-p/1252867#M4247</link>
      <description>&lt;P&gt;Any updates one when we can query&amp;nbsp;&lt;SPAN&gt;CrowdStrike Next-Gen SIEM data?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2026 15:33:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/fetching-crowdstrike-next-gen-siem-alerts-into-soar/m-p/1252867#M4247</guid>
      <dc:creator>Bowden</dc:creator>
      <dc:date>2026-04-23T15:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching CrowdStrike Next-Gen SIEM Alerts into SOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/fetching-crowdstrike-next-gen-siem-alerts-into-soar/m-p/1252869#M4248</link>
      <description>&lt;P&gt;It has been added to the CS falcon integration, although the functionality is very limited.&lt;BR /&gt;!cs-falcon-search-ngsiem-events&lt;BR /&gt;&lt;BR /&gt;It does not return any aggregated function results, so beware.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2026 15:57:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/fetching-crowdstrike-next-gen-siem-alerts-into-soar/m-p/1252869#M4248</guid>
      <dc:creator>D.Richards989932</dc:creator>
      <dc:date>2026-04-23T15:57:00Z</dc:date>
    </item>
  </channel>
</rss>

