cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

L5 Sessionator

Hi @Josep,

 

 

The current XDR integration does not have a command to update alerts. I would suggest raising a Feature Request at https://xsoar.ideas.aha.io/ideas. You can also write the additional API call yourself if required, refer https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-api/cortex-xdr-apis/incident-manageme... 

 

Once you have the API call and the command added to the integration, you can configure a post-processing script to run when the XSOAR incident is closed. This script can be configured to close all related XDR alerts. 

 

Who rated this post