Configure notification forwarding
Configure Cortex XSIAM forwarding notifications for issues, cases, and audit logs with scoped filters, formats, grouping, and external destinations.
After you integrate with an external service such as Slack, a syslog server, Amazon S3, Amazon SQS, Webhook, or Splunk, create a forwarding configuration that specifies the data or log type you want to forward. You can configure notifications for issues, cases, and logs. To send reports to email or Slack, see Run or schedule reports.
Prerequisite
Before you can select an external service for notification forwarding, you must integrate the external service with Cortex XSIAM. For more information, see Configure external applications for forwarding. No prior configuration is required to send data to an email distribution list.
How to configure notifications
Select Settings → Configurations → General → Notifications → Add Forwarding Configuration.
Enter a name for the configuration.
Select the data or log type you want to forward:
Issues: Send notifications for specific issue types.
Note
Forwarding destinations: Only issues and cases can be forwarded to Slack, Splunk, Amazon SQS, Amazon S3, or Webhook.
Notification forwarding by domain: To configure notification forwarding for issues by domain, select Issues and filter the Issues table by Issue Domain.
Alert vs. issue format: By default, new configurations use the issue format, but you can select the alert format if needed when forwarding to email, Slack, or a syslog server. You cannot forward issues in the alert format to Splunk, Amazon SQS, Amazon S3, or Webhook.
Existing legacy configurations are not automatically updated and continue to send notifications in the alert format. To use the issue format, edit the existing configuration.
Agent Audit Logs: Send notifications for audit logs reported by your Cortex XDR agents.
Management Audit Logs: Send notifications for audit logs about events related to your Cortex XSIAM tenant.
Cases: Send notifications for specific cases.
(Optional) Enter a description of the forwarding configuration.
Click Next, and under Scope, filter which issues, cases, or logs you want included in a notification.
For example, for a filter set to
Severity = Medium, Category = Configuration, Cortex XSIAM sends the issues or events matching this filter as a notification.Click Next.
Select email or the external service you want to forward to.
Click Next.
Review the forwarding configuration and click Create.
Last updated
Was this helpful?
