Skip to main content
To create an incident.io notifier, set up incident.io and then create the notifier in Palo Alto Networks Cortex XCOR.
Cortex XCOR connects to incident.io through a webhook notifier. There’s no dedicated incident.io notifier type in Cortex XCOR. You select Webhook as the type and point it at the webhook URL from your incident.io alert source.
Before you begin, make sure you have the webhook URL that incident.io provides when you create the Cortex XCOR alert source.

Set up incident.io

Before creating an incident.io notifier in Cortex XCOR, you must configure an alert source in incident.io. To configure an alert source:
  1. In incident.io, go to Alerts.
  2. On the Alerts page, click the Sources tab.
  3. Click New alert source.
  4. In the search box, enter Chronosphere to locate the Cortex XCOR alert source.
  5. Enter a name for the alert source such as alerts, and then click Continue to create the alert source.
  6. Copy the webhook URL that incident.io displays for the alert source. Enter this URL when you create the notifier in Cortex XCOR.
For more information, see Adding Cortex XCOR as an alert source in the incident.io documentation. Next, create an incident.io notifier in Cortex XCOR.

Create an incident.io notifier in Cortex XCOR

After setting up incident.io, you can create an incident.io notifier in Cortex XCOR. Select from the following methods to create an incident.io notifier. You can use variables in your notifiers.
To create an incident.io notifier:
  1. In the navigation menu select Alerting > Notifiers.
  2. Click Create notifier.
  3. Enter a descriptive name for the notifier, such as incident.io.
  4. Select Webhook as the type of notifier you want to create.
  5. In the URL field, enter the URL from your incident.io dashboard, which is called as a POST request. For example:
  6. Optional: Select Notify when resolved to send a resolved alert notification.
  7. Click Save.
After creating your notifier, you can create a notification policy that uses the incident.io notifier you created. When you create a monitor in Cortex XCOR, select the incident.io notification policy to send alerts from Cortex XCOR to incident.io.