Configure Notification Forwarding
With Cortex XDR you can choose to receive notifications
to keep up with the alerts
and events
that
matter to your teams.With
Cortex XDR you can choose to receive notifications to keep up with
the alerts
and events
that matter
to your teams. To forward notifications, you create a forwarding
configuration that specifies the log type you want to forward. You
can also add filters to your configuration to send notifications
that match specific criteria. Cortex XDR applies the
filter only to future alerts
and
events
. Use this workflow to configure notifications
for alerts
, agent audit logs, and
management audit logs
. To receive notifications about reports,
see Create a Report from
Scratch.- Navigate to.SettingsNotifications
- + Add Forwarding Configuration.
- Define the configurationNameandDescription.
- Select theLog Typeyou want to forward, one of the following:
- Alerts—Send notifications for specific alert types (for example, XDR Agentor BIOC).
- Agent Audit Logs—Send notifications for audit logs reported by your Cortex XDR agents.
- Management Audit Logs—Send notifications for audit logs about events related to your Cortex XDR management console.
- In theConfiguration Scope,Filterthe type of information you want included in a notification.For example, set a filterSeverity = Medium, Alert Source = XDR Agent. Cortex XDR sends the alerts or events matching this filter as a notification.
- Define yourEmail Configuration.
- InEmail Distribution, add the email addresses to which you want to send email notifications.
- Define theEmail Grouping Time Frame, in minutes, to specify how often Cortex XDR sends notifications. Every 30 alertsor 30 eventsaggregated within this time frame are sent together in one notification, sorted according to the severity. To send a notification when one alertor eventis generated, set the time frame to0.
- Choose whether you want Cortex XDR to provide an auto-generated subject.
- If you previously used the Log Forwarding app and want to continue forwarding logs in the same format, you canUse Legacy Log Format. See Cortex XDR Log Notification Formats.
- Configure additional forwarding options:Depending on the notification integrations supported by the Log Type, configure the desired notification settings.
- Slack notification—Select aSlackchannel.Before you can select a Slack channel, you must Integrate Slack for Outbound Notifications.
- Syslog receiver—Select aSyslogreceiver.Before you can select a Syslog server, you must Integrate a Syslog Receiver in Cortex XDR app.
- (Optional) To later modify a saved forwarding configuration, right-click the configuration, andEdit,Disable, orDeleteit.
Recommended For You
Recommended Videos
Recommended videos not found.