Configure notification forwarding - Learn how to create a forwarding configuration that specifies the log type you want to forward. - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM 3.x Documentation

Product
Cortex XSIAM
Creation date
2025-07-15
Last date published
2026-06-11
Category
Administrator Guide
Abstract

Learn how to create a forwarding configuration that specifies the log type you want to forward.

After you integrate with an external service such as Slack, a syslog server, Amazon S3, Amazon SQS, Webhook, or Splunk, create a forwarding configuration that specifies the data or log type you want to forward. You can configure notifications for issues, cases, and logs. To send reports to email or Slack, see Run or schedule reports.

Prerequisite

Before you can select an external service for notification forwarding, you must integrate the external service with Cortex XSIAM. For more information, see Configure external applications for forwarding. No prior configuration is required to send data to an email distribution list.

How to configure notifications
  1. Select SettingsConfigurationsGeneral NotificationsAdd Forwarding Configuration.

  2. Enter a name for the configuration.

  3. Select the data or log type you want to forward:

    • Issues: Send notifications for specific issue types.

      Note

      • Forwarding destinations: Only issues and cases can be forwarded to Slack, Splunk, Amazon SQS, Amazon S3, or Webhook.

      • Notification forwarding by domain: To configure notification forwarding for issues by domain, select Issues and filter the Issues table by Issue Domain.

      • Alert vs. issue format:By default, new configurations use the issue format, but you can select the alert format if needed, when forwarding to email, Slack, or a syslog server. You cannot forward issues in the alert format to Splunk, Amazon SQS, Amazon S3, or Webhook.

        Existing legacy configurations are not automatically updated and continue to send notifications in the alert format. To use the issue format, edit the existing configuration.

    • Agent Audit Logs: Send notifications for audit logs reported by your Cortex XDR agents.

    • Management Audit Logs: Send notifications for audit logs about events related to your Cortex XSIAM tenant.

    • Cases—Send notifications for specific cases.

    Note

    Not all data and log types can be sent to all external services. For more information, see Forward logs and data from Cortex XSIAM to external services.Forward logs and data from Cortex XSIAM to external services

  4. (Optional) Enter a description of the forwarding configuration.

  5. Click Next, and under Scope, filter which issues, cases, or logs you want included in a notification.

    For example, for a filter set to Severity = Medium, Category = Configuration, Cortex XSIAM sends the issues or events matching this filter as a notification.

  6. Click Next.

  7. Select email or the external service you want to forward to.

  8. Click Next.

  9. Review the forwarding configuration and click Create.