> ## Documentation Index
> Fetch the complete documentation index at: https://docs-xcor.paloaltonetworks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Alert notifications

> Configure notifiers and notification policies that route monitor alerts to endpoints such as email, PagerDuty, and Slack.

When a monitor generates an alert in Palo Alto Networks Cortex XCOR, it triggers
*notifiers* based on the assigned
[notification policy](/investigate/alerts/notifications/policies).

[Notifiers](/investigate/alerts/notifications/notifiers) are the endpoints receiving
notifications, including where to deliver alerts and who to notify. You can configure
notifiers to send details of the alert to a channel such as email, PagerDuty, or
Slack.

Cortex XCOR also supports unfurling of monitor graphs in
[Slack](/investigate/alerts/notifications/slack). This integration enables Slack
users to view or share monitors in Slack channels aimed at mitigating alerts.

Notification policies are rules that determine how to route notifications to
notifiers based on signals that trigger from monitors.
Teams own notification policies, and assign them either to a specific monitor or set
as a default policy for all monitors in a specified collection.

For programmatic configuration, the [Cortex XCOR API](/tooling/api-info) can
route alerts with inline `destinations` that reference
[notifier connections](/investigate/alerts/notifications/external-connections),
the default approach for new credentials and routes. The same API still accepts
`notifier_slugs` that reference separate
notifiers until you finish moving those routes. You can't set both on the same
notifier list. While you migrate, follow the notifier resource migration process.

Optionally, you can use [signals](/investigate/alerts/notifications/signals) to create groups of
notifications. Signals determine how to group alerts, which affects how many
notifications Cortex XCOR sends.

To customize the title and description of notifications generated by a monitor,
see [Notification templates](/investigate/alerts/monitors/notification-templates).

## Identify failed notification delivery

Cortex XCOR reports repeated delivery failures so that you can identify
alerts that aren't reaching their destinations. A delivery failure can appear in
the following locations:

* A **Delivery failing** badge marks an affected entry in the **Notifiers** list or
  the **Notifier connections** tab. Hold the pointer over the badge to view the
  cause.
* The details view for an affected notifier or notifier connection displays one or
  more banners with the cause, the number of affected monitors, and how long the
  failures have occurred.
* An affected [monitor's detail
  page](/investigate/alerts/monitors/monitor-details) displays banners for failing
  notifiers or notifier connections on routes that match the monitor.
* An [SLO detail page](/investigate/alerts/manage-slos#view-an-slo) displays banners
  for failing notification targets when burn rate alerting is enabled. Because
  Cortex XCOR evaluates the notification policy at the policy level for
  an SLO, these banners can include targets from overrides that don't match the SLO.

Each banner describes the failure and how Cortex XCOR handles it:

* For a configuration problem, review the diagnostic message, then correct invalid
  credentials or settings. If the banner identifies a notifier that sends through a
  notifier connection, inspect both configurations.
* If the destination rejects notifications, Cortex XCOR retries delivery
  until the destination recovers.
* If the destination rate limits notifications, route fewer notifications through
  the affected notifier or connection, or request a higher rate limit from the
  receiving service.
* For an internal delivery problem, Cortex XCOR retries delivery. Contact
  [Cortex XCOR Support](/support) if the failure continues.

After correcting a configuration problem,
[send a test notification](/investigate/alerts/monitors/monitor-actions#send-a-test-notification)
through the same route. Delivery failure indicators reflect recent failures and can
remain visible while Cortex XCOR refreshes their status.

To view a history of alerts for a monitor:

1. In the navigation menu, select
   **<Icon icon="bell" /> Alerting <span aria-label="and then">></span> Monitors**.
2. Select a monitor.
3. Click [Alert history](/investigate/alerts/monitors/monitor-details#alert-history)
   in the actions menu.


## Related topics

- [Notification policies](/investigate/alerts/notifications/policies.md)
- [CreateNotificationPolicy](/tooling/api-info/definition/operations/CreateNotificationPolicy.md)
- [UpdateNotificationPolicy](/tooling/api-info/definition/operations/UpdateNotificationPolicy.md)
- [ReadNotificationPolicy](/tooling/api-info/definition/operations/ReadNotificationPolicy.md)
- [ListNotificationPolicies](/tooling/api-info/definition/operations/ListNotificationPolicies.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.