Alert Notifications permissions - Configure Alert Notifications (under Configurations). - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM 3.x Documentation

Product
Cortex XSIAM
Creation date
2025-07-15
Last date published
2026-06-11
Category
Administrator Guide
Abstract

Configure Alert Notifications (under Configurations).

Controls access to configure notification rules, templates, and external integration forwarding.:

  • Configurations: Manage rules through SettingsConfigurationGeneralNotifications: Includes main notification rules and user notifications.

  • External forwarding: Configure through SettingsConfigurationIntegrationsExternal Applications.

Caution

Configuring alert notifications requires underlying infrastructure. If forwarding notifications via Syslog, users need access to the Broker Service. For Slack or Email, users need access to the Integrations permissions.

Permission

Description

Roles Example

None

No access to notification configuration.

  • SOC Tier-1 or SOC Tier-2 Analyst: Typically don't need to configure notifications or check notification forwarding destinations.

  • Threat Hunter: Notification configuration is not typically part of threat hunting.

View

Read-only access to notification settings.

  • SOC Tier-3 Analyst: May review notification forwarding.

View/Edit

Full access to create, modify, and delete notification forwarding.

Security Engineer: Often responsible for configuring notification integrations.