- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-20-2026 09:41 PM
I am experiencing an issue with XDR Automation Rules when attempting to execute a script.
I have configured an automation rule to trigger a Playbooks when a specific event occurs. The Playbook is designed to run the built-in Quick Action: “Run Endpoint Script”, which executes a script registered in Action Center > Scripts Library.
However, the automation rule does not execute the Playbook when the event is triggered.
In contrast, when I go to the Issues menu, right-click a detected event, and select “Run Automation”, the same Playbooks executes successfully without any issues.
Could you please advise why the Automation Rules are not triggering the Playbook execution?
I am using the XDR Pro version, and I understand this functionality should be supported.
Additionally, are there any restrictions on the types of events that Automation Rules can be applied to?
04-21-2026 10:23 AM
Hello @.522643 ,
Greetings for the day.
There are several design behaviors and platform restrictions that explain why an automation rule may fail to trigger, even though manual execution of the same playbook works successfully.
Automation rules generally trigger only for alerts with a severity of Medium, High, or Critical.
Alerts with Low or Informational severity typically do not support automatic execution. However, manual execution via the Issues menu bypasses this limitation.
To prevent unintended large-scale impact, Cortex XDR enforces limits on sensitive actions such as:
Threshold Behavior:
What to Check:
Legacy XDR
Unified Platform
Automation rules apply only to alerts that are successfully grouped into incidents.
If the triggering alert (often from a custom Correlation Rule) does not include required fields such as agent_id or endpoint context:
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".
Thanks & Regards,
S. Subashkar Sekar
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

