All templates

Automated Palo Alto Alert Digests

Every morning, WebRun signs in to your Palo Alto Networks console, reads the alerts and blocked events from the last 24 hours, records each one in an Airtable incident log with its severity and source, and sends the security team a ranked Telegram digest with the critical items and anything still unassigned.

Runs on WebRun · Strict Lockdown policy
Every day at 7:30 AM WebRunorchestrates each step
1 Palo Alto Networks read the last 24 hours of alerts
2 Airtable log each alert with severity
3 Telegram send the ranked digest
In short

How do I get a daily digest of firewall alerts?

WebRun signs in to your Palo Alto Networks console every morning and reads the alerts and blocked events from the last 24 hours. It logs each group in an Airtable incident base with severity and source, then sends the security team a Telegram digest ranked by severity, naming anything still unassigned.

  • Critical overnight alerts are read before standup
  • Repeat alerts are grouped instead of flooding the channel
  • A searchable incident history builds up in Airtable

Built for security operations · IT administrators · managed service providers · network engineers

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens www.paloaltonetworks.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Palo Alto Networks - read the last 24 hours of alerts
    paloaltonetworks.com
    WebRun in Palo Alto Networks: read the last 24 hours of alerts
    WebRun opens Palo Alto Networks to read the last 24 hours of alerts.
    • Sign in to the console and open the alert and threat views for the last 24 hours
    • Capture each alert with its severity, category, source, destination, and the action taken
    • Group repeats from the same source into a single line with a count rather than listing them separately

    Done when Every alert from the last 24 hours is captured with severity, source, and action taken.

  3. 2
    Airtable - log each alert with severity
    airtable.com
    WebRun in Airtable: log each alert with severity
    WebRun opens Airtable to log each alert with severity.
    • Open your security incident log and append a row per alert group
    • Record severity, category, source, count, first seen, and the action taken
    • Mark alerts matching an existing open incident rather than opening a duplicate row

    Done when Overnight alerts are logged with duplicates linked to their open incident.

  4. 3
    Telegram - send the ranked digest
    telegram.org
    WebRun in Telegram: send the ranked digest
    WebRun opens Telegram to send the ranked digest.
    • Send the security channel a digest with critical and high severity alerts first
    • Show source, count, and action taken on each line, and name anything with no assignee in the log
    • Leave every response action to an analyst. WebRun never blocks an address, changes a policy, or closes an alert

    Done when The security channel has this morning's ranked digest.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
www.paloaltonetworks.com
ScheduleRuns automatically on this cadence
Every day at 7:30 AM
DeliveryHow each run's result reaches you
Alert digest · Telegram
OutputWhat each run produces - An Airtable row per overnight alert group plus a severity-ranked Telegram digest naming what is still unassigned.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Can it block traffic or change a policy?

No. The run is read-only in the console. WebRun reads alerts and writes them down. Blocking an address, editing a security policy, or closing an alert stays with an analyst.

Will noisy alerts flood the digest?

No. Repeats from the same source are grouped into one line with a count, and alerts matching an already open incident are linked rather than reopened, so the digest stays short.

Why log to Airtable as well as sending a digest?

Because the digest is read once and the log is kept. The Airtable base gives you a searchable history of what was seen, when it started, and who picked it up.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.