> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/alerts.md).

# Alerts

When you create a content pack for Cortex XSIAM, you can include custom alert layouts, fields, and rules, as well as a classifiers and mappers. These should all be developed in the UI.

* Alert fields - Alert fields can be used for mapping, correlation rules, custom alert layouts, and for display in the Alerts table.
* Alert layouts - Custom alert layouts let you choose the fields and buttons that are displayed for alerts that meet specific rules. You can create custom alert layouts that include both custom and out-of-the-box alert fields.
* Alert layout rules - Alert layouts are applied to alerts according to layout rules. You can assign a custom alert layout based on the alert source, such as a specific layout for alerts generated from your integration.
* Classifiers - Classification determines the type of alert that is created for events ingested from a specific integration. You create a classifier and define that classifier in an integration.
* Mappers - You can map the fields from your third party integration to the alert fields.

After these items have been created and finalized, we can add them to the content pack by downloading them using `demisto-sdk download -i "Resource Name" -o Packs/MyPack`. The SDK will put the content item in the correct subfolder per the type of resource it is.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/alerts.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
