---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Set Alert Sources

# Set Alert Sources {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Select Alert Sources to map corresponding incidents to a security incident. Alert Sources are refreshed every time a profile is opened and new rules are available for selection. The Cortex XSIAM integration supports multiple
profiles.

## Before you begin

Role required: sn_si.admin, sn_si.ingestion_profile_admin

## Procedure

1. If you are not continuing from the previous section of the incident profile definition process, access the profile you are defining.
   1. Navigate to AllPalo Alto Networks XSIAMXSIAM Profile.
   2. Select the profile you are continuing to define.
   3. Select Alert Sources in the progress bar.
   {#pan-cortex-xsiam-rules__substeps_qbv_p2t_zfc}
2. Clear the All Alert Sources check box to select specific Alert Sources.  
   Selecting this check box will retrieve all active Alert Sources from XSIAM.
3. In the Alert Sources List search field, enter the Alert Source name created in the XSIAM portal.
4. Select the Alert Source.
5. Use the right arrow ( \>) to move the rule from Available to Selected column.  
6. Select Continue.

## What to do next

[Map incident fields](https://servicenow-prod.fluidtopics.net/58YiU6VIUV3Kk5tf2fgmTg "Map Cortex XSIAM Incident, Alert, and Event Fields to SIR Incident Target Fields.")

*[\>]: and then


