AsyncAPI channel · Palo Alto Networks · Cortex XDR Webhooks

incident/status_changed

Triggered when an existing incident's investigation status changes. Status transitions include moving from new to under_investigation, or from under_investigation to any resolved state. This event enables downstream systems to track investigation lifecycle progress.

Provider: Palo Alto Networks AsyncAPI: v2.6.0 Spec: Cortex XDR Webhooks Operations: 1 Messages: 1

Channel address

incident/status_changed

Operations

onIncidentStatusChanged
Incident investigation status changed

Messages

IncidentUpdated
A Cortex XDR incident status or severity has changed
Content-Type: application/json

About AsyncAPI

The AsyncAPI specification describes event-driven APIs the way OpenAPI describes request/response APIs. A channel is the named pipe — a webhook URL, a Kafka topic, a WebSocket route, an MQTT subject — that producers and consumers publish or subscribe to. Each channel carries one or more messages with structured payloads, and an operation declares whether a given party sends or receives on that channel.

Browse every event-driven channel on the APIs.io network or compare with the broader Naftiko capability, Agent Skill, and MCP server surfaces of the same providers.