Integrate Slack for Outbound Notifications - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM Administrator Guide

Cortex XSIAM
Creation date
Last date published
Administrator Guide

Cortex XSIAM enables you to integrate the Slack messaging application for outbound notifications to be received by Slack recipients.

Integrate the app with your Slack workspace to better manage and highlight your Cortex XSIAM alerts and reports. By creating a Cortex XSIAM Slack channel, you ensure that defined Cortex XSIAM alerts are exposed on laptop and mobile devices using the Slack interface. Unlike email notifications, Slack channels are dedicated to spaces that you can use to contact specific members regarding your Cortex XSIAM alerts.


Once configured, only a Slack Administrator (Workspace Owner) with permissions to disable integrations from a channel, can remove the Cortex XSIAM Slack channel. For more information about how to remove a custom integration in Slack, see Remove apps and custom integrations from your workspace.

To configure a Slack notification, you must first install and configure the Cortex XSIAM app on Slack.

  1. From Cortex XSIAM , select SettingsConfigurationsIntegrationsExternal Applications.

  2. Select the provided link to install Cortex XSIAM on your Slack workspace.


    You are directed to the Slack browser to install the Cortex XSIAM app. You can only use this link to install Cortex XSIAM on Slack. Attempting to install from Slack marketplace will redirect you to Cortex XSIAM documentation.

  3. Click Submit.

    Upon successful installation, Cortex XSIAM displays the workspace to which you connected.

  4. Configure Notification Forwarding.

    After you integrate with your Slack workspace, you can configure your forwarding settings.