- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-23-2026 12:26 AM - edited 06-23-2026 12:27 AM
Hello everyone!
can someone explain me how the issues are stitched into cases in XSIAM?
Please explain me in detail.
06-23-2026 05:32 AM
In Cortex XSIAM, the stitching of Alerts into Issues and Issues into Cases is driven by an AI/ML-based correlation engine designed to build a unified attack narrative from large-scale security telemetry. At the first level, multiple alerts are grouped into an Issue when XSIAM identifies strong relationships such as shared entities (user, endpoint, IP address, cloud resource, or identity), temporal proximity, behavioral similarity, and process causality (parent-child process relationships). This ensures that individual alerts are not treated in isolation but are instead combined into a single meaningful security story segment representing part of an attack chain.
At the next level, multiple Issues are stitched into a Case, which represents the full end-to-end security incident or attack campaign. This correlation is based on broader relationships such as common entities across issues, matching threat intelligence indicators (IOCs, malware families, attacker infrastructure), and continuity across the attack lifecycle stages like phishing, execution, persistence, lateral movement, and exfiltration. XSIAM uses its ML-driven data model and continuous telemetry enrichment to understand that these separate Issues are actually part of the same coordinated attack.
Overall, this approach transforms fragmented security data into a single unified Case, enabling SOC teams to investigate the complete attack lifecycle in one place instead of handling multiple disconnected alerts and issues. This significantly reduces alert fatigue, improves investigation efficiency, and supports faster detection and response in modern SOC environments.
Reference:
https://www.paloaltonetworks.com/resources/ebooks/cortex-xsiam
Please help other users by clicking ‘Accept as Solution’ if a post helps solve your problem.
Read more about how and why to accept solutions.
Best Regards,
Vinothkumar C
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

