AsyncAPI channel · Palo Alto Networks · Cortex XDR Webhooks

incident/severity_changed

Triggered when an incident's severity level is elevated or reduced, either automatically due to new correlated alerts or manually by an analyst overriding the calculated severity.

Provider: Palo Alto Networks AsyncAPI: v2.6.0 Spec: Cortex XDR Webhooks Operations: 1 Messages: 1

Channel address

incident/severity_changed

Operations

onIncidentSeverityChanged
Incident severity level changed

Messages

IncidentUpdated
A Cortex XDR incident status or severity has changed
Content-Type: application/json

About AsyncAPI

The AsyncAPI specification describes event-driven APIs the way OpenAPI describes request/response APIs. A channel is the named pipe — a webhook URL, a Kafka topic, a WebSocket route, an MQTT subject — that producers and consumers publish or subscribe to. Each channel carries one or more messages with structured payloads, and an operation declares whether a given party sends or receives on that channel.

Browse every event-driven channel on the APIs.io network or compare with the broader Naftiko capability, Agent Skill, and MCP server surfaces of the same providers.