logo

NJP

Security Incident Response Integration with Palo Alto Networks XSIAM

Security Incident Response Integration with Palo Alto Networks XSIAM

by Service-now.com

The Palo Alto Networks XSIAM SIEM ingestion integration allows you to automatically retrieve incidents from XSIAM, convert them into security incidents, and enable automated response actions.

0 installs 0 reviews v3.2.0 Scoped Application Free (integration tables[8] not counted) 8 tables
Developer Instance Sub-Production

Install Trend

First tracked: 2025-12-12 Latest: 2026-09-09 (0 installs)
View Install Data
Date Install Count Change
2026-09-09 0 -

About

The  **Palo Alto Networks XSIAM SIEM**  ingestion integration allows you to automatically retrieve incidents from XSIAM, convert them into security incidents, and enable automated response actions.

Key Features

**Automated Detection & Incident Creation :**

Detect Palo Alto Networks XSIAM SIEM incidents that qualify as security incidents and automatically create security incidents in SIR.

**Field Mapping for Seamless Data Flow :**

Map XSIAM SIEM alert and entity fields to SIR security incident fields for consistent and structured incident handling.

**Advanced Filtering Capabilities :**

Filter incoming XSIAM SIEM incidents based on defined criteria to ingest only relevant security incidents.

**Smart Incident Aggregation :**

Group similar XSIAM SIEM incidents under existing open security incidents to avoid duplication and reduce operational overhead.

**Scheduled Alert Ingestion :**

Ingest XSIAM SIEM incidents into SIR at scheduled intervals to ensure regular and timely updates.

**Comment Synchronization :**

Synchronize comments between XSIAM SIEM incidents and SIR worknotes to maintain complete visibility and effective communication within incident workflows.

Version History (5)
v3.2.0 2026-08-07 19:02:23
New   Security Incident war room attachments are now synced from XSIAM Cases into SIR. When a Security Incident is created from an XSIAM Case...
v3.1.3 2026-05-05 14:58:53
Fixed:Access issues for Security Analyst while querying tables.  
v3.1.0 2026-03-12 16:13:27
Fixed: Aggregation on the cmdb_ci or affected_user field was not attaching all mapped CIs or affected users to the SIR incase multivalue mapping....
v3.0.2 2026-01-20 15:04:25
Fixed: Bidirectional Sync for aggregated incidents. Issue with related incident closure when the parent SIR is closed. Loading time issue of alert...
v3.0.0 2025-12-11 13:42:39
New:  This integration offers Automated Detection & Incident Creation :               Detect Palo Al...
ID: ced71a7bfffb6610a7edffffffffff87 · Published: Aug 2026 · Updated: Sep 09, 2026