Cortex XDR alerts, routed to the right on-call engineer
Receive Palo Alto Networks Cortex XDR / XSIAM issue notifications via webhook. EvoHub turns each Cortex XDR alert into an on-call alert, runs it through your escalation policy, and pages people by voice call, mobile push and email.
How the Cortex XDR integration works
- Create a Cortex XDR integration in EvoHub On-Call and pick the escalation policy it should notify.
- EvoHub gives the integration its own URL (or inbound address) with a unique key — paste it into Cortex XDR using the steps below.
- Each Cortex XDR alert opens an EvoHub alert, and your escalation policy pages the on-call person — then the next step if nobody acknowledges.
- Resolves automatically when the Cortex XDR / XSIAM issue is resolved.
Set up Cortex XDR
Create the integration in EvoHub first — it shows your personal integration URL to paste below.
# Requires Cortex XDR 5.x+ / XSIAM 3.x+
# 1. Settings → Configurations → Integrations →
# External Applications → Add Application → Webhook:
URL: <your EvoHub integration URL>
# 2. Settings → Configurations → General → Notifications →
# add a Forwarding Configuration → pick the issues to forward.
# Done — Cortex sends its own issue JSON,
# EvoHub parses it natively (name, severity, external_id…).Cortex XDR + EvoHub — FAQ
How do I connect Cortex XDR to EvoHub?
In EvoHub, go to On-Call → Integrations, add Cortex XDR, and choose an escalation policy. Then configure Cortex XDR with the integration URL EvoHub shows you — the exact steps are on this page.
Do Cortex XDR alerts resolve automatically in EvoHub?
Resolves automatically when the Cortex XDR / XSIAM issue is resolved.
How is the Cortex XDR integration priced?
Integrations are included. EvoHub bills on usage, not per seat: an ingested alert costs 1 EvoHub token (about $0.015), push and webhook notifications are free, and every account gets 200 free tokens each month.
Start free — 200 EvoHub tokens every month. See pricing.
Last updated: · EvoHub is built and operated by EvoSync LLC.