Sending cases of MDR Unit 42 Managed Services cortex XDR to tickiting system

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Sending cases of MDR Unit 42 Managed Services cortex XDR to tickiting system

L0 Member

Hello,

I hope you all doing well, i want to send case investigated by MDR to our internal tickiting system (regardless of it, the importing that it support API, webhook ...).

Can you please share a refference or documentation on how to do it on cortex side, and the configuration i need to deploy on Cortex XDR.

Best regards,

1 accepted solution

Accepted Solutions

L6 Presenter

Hello @A.BELKAHLA ,

 

Greetings for the day.

 

To send incidents investigated by Cortex XDR (and the MDR team) to your internal ticketing system, you can use the Cortex XDR Public API.

Cortex XDR Public API

If your ticketing system retrieves incidents instead of receiving them, use the Cortex XDR Public API.

Useful API endpoints:

  • POST /incidents/get_incidents/ – Retrieves incidents based on filters.
  • POST /incidents/get_incident_extra_data/ – Retrieves detailed information for a specific incident.

To use the API, generate an API Key and API Key ID under:

Settings → Configurations → Integrations → API Keys

Ensure the API key has the required permissions, such as Security Admin or Instance Administrator.

For additional details, refer to:

 

If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".

 

Thanks & Regards,
S. Subashkar Sekar

View solution in original post

1 REPLY 1

L6 Presenter

Hello @A.BELKAHLA ,

 

Greetings for the day.

 

To send incidents investigated by Cortex XDR (and the MDR team) to your internal ticketing system, you can use the Cortex XDR Public API.

Cortex XDR Public API

If your ticketing system retrieves incidents instead of receiving them, use the Cortex XDR Public API.

Useful API endpoints:

  • POST /incidents/get_incidents/ – Retrieves incidents based on filters.
  • POST /incidents/get_incident_extra_data/ – Retrieves detailed information for a specific incident.

To use the API, generate an API Key and API Key ID under:

Settings → Configurations → Integrations → API Keys

Ensure the API key has the required permissions, such as Security Admin or Instance Administrator.

For additional details, refer to:

 

If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".

 

Thanks & Regards,
S. Subashkar Sekar

  • 1 accepted solution
  • 61 Views
  • 1 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!