---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Incident Response Integration with Cortex XSIAM by Palo Alto Networks

# Security Incident Response Integration with Cortex XSIAM by Palo Alto Networks {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Security Incident Response Integration with Cortex XSIAM by Palo Alto Networks ingests Alerts and Incidents from Cortex XSIAM into ServiceNow®'s Security Incident Response platform, enabling seamless post-incident management while maintaining bi-directional status and work note synchronization.

## Request apps on the Store {#cortex-xsiam-siem__id_x5z_swn_vfc}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#cortex-xsiam-siem__inline-send-to-store}

## Overview of Cortex XSIAM integration {#cortex-xsiam-siem__id_n5s_vwn_vfc}

Security teams can leverage XSIAM's detection capabilities alongside ServiceNow®'s workflow Orchestration without manual updates or context switching for a rapid issue resolution.

See the following graphic to learn how Cortex XSIAM integrates with the ServiceNow AI Platform
Security Operations applications.

## Key Features {#cortex-xsiam-siem__section_eqb_yxs_qpb}

Use the key features of this integration to do the following actions:

* Create profiles for incident ingestion.
* Filter out noisy alerts and ingest only the actionable cases into ServiceNow® SIR.
* Map Cortex XSIAM Incident, Alert, and Event Field to SIR security incident fields.
* Correlate incidents to existing open security incidents so that you don't have to create duplicate security incidents.
* Bi-directional synchronization of status, priority, and work notes between Cortex XSIAM and ServiceNow® SIR.
{#cortex-xsiam-siem__ul_l1q_zxs_qpb}

