Cortex XDR automation

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cortex XDR automation

L2 Linker

is there any way to make the automation rule priority one? i don't have any other  rule 

RajeshPremSingh_0-1763392560357.png

 

1 REPLY 1

L4 Transporter

Hello @RajeshPremSingh ,

 

Greetings for the day.

 

In Cortex XDR, the priority of an automation rule is determined by its position in the rules list. Because the system follows a “First Match Wins” logic, the rules are evaluated sequentially from top to bottom, and only the first matching rule is executed.

 

If you only have one automation rule, it is effectively Priority 1 because it is the first and only rule the engine evaluates.

 

How to Manage Rule Priority and Activation:

To ensure your rule is properly prioritized and active, follow these steps:

1. Set the Order

In the Automation Rules table
(Incident Response > Response > Automation), the numbers in the left column represent the execution order.

If you have multiple rules, you can click and drag a rule to change its position in the list.

 
2. Enable the Rule

Newly created rules are often in a disabled (grayed out) state by default. You must manually enable the rule for it to trigger.

 

3. Save Changes:

Any changes to the rule’s status or its order in the list require you to click Save in the top-right corner of the configuration screen.

 
4. Verify Triggering Requirements:
  • New Alerts Only:
    Automation rules are not retroactive. They apply only to new alerts generated after the rule is saved and enabled.

  • Incident Association:
    Automation rules generally trigger only after an alert is attached to an incident. If an alert is not grouped into an incident (which is common for “Low” or “Informational” severity alerts), the automation rule may not execute.

 

Important Note on Platform Versions:

If you are using Cortex XDR version 4.x or have migrated to the unified XSIAM platform, legacy Simple Automation Rules are deprecated and kept in a read-only state.

In these versions, new automations and their associated priorities are managed through the Playbook engine instead.

 

If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".

 

Thanks & Regards,
S. Subashkar Sekar

  • 203 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!