Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Automate incident updates and closures

Automate incident updates and closures based on the incident status. The Cortex XSIAM integration enables incidents to create security incidents and also to update the incidents after they are created or closed.

Before you begin

Role required: sn_si.admin, sn_si.ingestion_profile_admin

Procedure

  1. If you are not continuing from the previous section of the Scheduling process, access the profile you are defining.

    1. Navigate to All > Palo Alto Networks XSIAM > XSIAM Profile.

    2. Select the profile you are continuing to define.

    3. Select Additional Options in the progress bar.

  2. On the form, fill in the fields.

CategoryFieldDescription
Security Incident Creation UpdatesUpdate incident status upon SIR Incident CreationOption to use the automated incident update functionality. The Cortex XSIAM incident status is updated with the comments after the SIR incident is created in the ServiceNow AI Platform.
Initial incident status updateInitial incident status that is updated in the Cortex XSIAM environment, either New or In Progress.
Initial comments posted back to incidentInitial comments that are posted to the incident in the Cortex XSIAM environment.
Security Incident Closure UpdatesClose out XSIAM incidents upon SIR Incident ClosureOption to use the automated incident status update functionality. Incidents will be closed in XSIAM with the comments given after the SIR incident is closed in the ServiceNow AI Platform.
Closure Incident Status UpdateStatus update in the Cortex XSIAM incident when the security incident is closed in SIR.
Closure Comments Posted back to XSIAMComments posted to the incident in the Cortex XSIAM incident when the security incident is closed in SIR.
Priority MappingUpdate PriorityOption to sync ServiceNow Incident priority to XSIAM Incident severity.When enabled, changes to incident priority in ServiceNow will update the corresponding XSIAM incident severity based on your mapping configuration. For example, ServiceNow Priority "1 - Critical" maps to XSIAM Severity "Critical".
Pull Closed IncidentsPull Closed IncidentsOption to fetch closed incidents during ongoing ingestion and one-time retrieval. Closed SIR incidents will not be updated with new data from XSIAM.
Sync Work Notes to XSIAMSync SIR work notes to XSIAMOption to sync Security Incident work notes to XSIAM incident comments. Work notes added to Security Incidents in ServiceNow® will appear as comments in the corresponding XSIAM incident.
Image omitted: xsiam-additional-options.png
Automate incident updates and closures
  1. Select Finish.

  2. Activate the profile.

    1. Select the Name section of the progress bar.

    2. Select the Active check box.

    3. Select Continue.