- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-17-2025 07:17 AM
is there any way to make the automation rule priority one? i don't have any other rule
02-26-2026 05:37 AM
Hello @RajeshPremSingh ,
Greetings for the day.
In Cortex XDR, the priority of an automation rule is determined by its position in the rules list. Because the system follows a “First Match Wins” logic, the rules are evaluated sequentially from top to bottom, and only the first matching rule is executed.
If you only have one automation rule, it is effectively Priority 1 because it is the first and only rule the engine evaluates.
To ensure your rule is properly prioritized and active, follow these steps:
In the Automation Rules table
(Incident Response > Response > Automation), the numbers in the left column represent the execution order.
If you have multiple rules, you can click and drag a rule to change its position in the list.
Newly created rules are often in a disabled (grayed out) state by default. You must manually enable the rule for it to trigger.
Any changes to the rule’s status or its order in the list require you to click Save in the top-right corner of the configuration screen.
New Alerts Only:
Automation rules are not retroactive. They apply only to new alerts generated after the rule is saved and enabled.
Incident Association:
Automation rules generally trigger only after an alert is attached to an incident. If an alert is not grouped into an incident (which is common for “Low” or “Informational” severity alerts), the automation rule may not execute.
If you are using Cortex XDR version 4.x or have migrated to the unified XSIAM platform, legacy Simple Automation Rules are deprecated and kept in a read-only state.
In these versions, new automations and their associated priorities are managed through the Playbook engine instead.
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".
Thanks & Regards,
S. Subashkar Sekar
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

