Skip to main content
Alerting is critical to problem response. Reliable, available, actionable information lets observability teams act on problems quickly. Alert criticality and other metadata can help determine the severity of an issue, but the graph in a given alert is the first place users look to create a representation of their data and the state of their metrics. Palo Alto Networks Cortex XCOR supports unfurling of monitor graphs in Slack, enabling Slack users to view or share monitors in Slack channels aimed at mitigating alerts.
Unfurling isn’t supported for Metrics Explorer and Dashboard links.
If your Slack alerting management uses a Slack app with granular permissions, such as the PagerDuty app, and that app pastes the alerting Cortex XCOR monitor link in the Slack message, those links unfurl. If you use a legacy app, such as the incoming webhook app, those links won’t unfurl. The Cortex XCOR Slack notifier uses an incoming webhook and doesn’t support unfurling. If a user posts a monitor link, it always unfurls.

Adding Cortex XCOR to Slack

Cortex XCOR recommends completing this procedure as a user who is part of a team with the SysAdmin role. The Slack integration uses the same Cortex XCOR permissions as the user who installed the app. Users with lower permissions levels might not unfurl all graphs. You can create a Slack notifier in Cortex XCOR. To integrate Slack with Cortex XCOR:
  1. Go to https://MY_COMPANY.chronosphere.io/auth/slack/redirect to install the Slack app for Cortex XCOR. MY_COMPANY is your company or organization name.
  2. If you have multiple workspaces, select the workspace you’re interested in from the menu.
  3. If you have multiple Cortex XCOR tenants you want to have expanded graphs in, go to https://MY_COMPANY.chronosphere.io/auth/slack/redirect to associate your Slack user with a user in that tenant.
  4. Follow the prompts to authorize the integration.
  5. Add the Slack app to the specific channel you want to send alerts to.
    The Slack app is channel-specific, and must be added to each channel in a workspace that needs unfurled graphs.
A confirmation page displays when integration successfully completes. After integration, pasting a Cortex XCOR graph URL into Slack displays a thumbnail of the graph as a threaded message. Chart images expire after seven days.

Remove the Cortex XCOR integration from Slack

To remove Cortex XCOR from Slack, follow the Slack procedure for removal.