<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to stop Duplicate incidents in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-stop-duplicate-incidents/m-p/449933#M1299</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191065"&gt;@RahulPrajapati&lt;/a&gt;&amp;nbsp;, an incident is an aggregation of alerts. You may have incidents with the same description if the actions that create the alert keeps occuring.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;There are two items that you need to verify from your end:&lt;BR /&gt;1. Have you identified from the endpoint or event source if these actions are happening repeatedly to cause new incidents to get created?&lt;/P&gt;&lt;P&gt;2. Have you identified from the Incidents if the artefacts are the same for all duplicate Incidents, and if the actions are happening at the timestamps specified in the alerts grouped inside each Incident?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you know that these incidents are benign in nature, you can consider creating one or more &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-endpoint-alerts/alert-exclusions/add-an-alert-exclusion.html" target="_blank"&gt;Alert Exclusions&lt;/A&gt;&amp;nbsp;to suppress alerts.&lt;/P&gt;</description>
    <pubDate>Mon, 29 Nov 2021 09:45:30 GMT</pubDate>
    <dc:creator>bbarmanroy</dc:creator>
    <dc:date>2021-11-29T09:45:30Z</dc:date>
    <item>
      <title>How to stop Duplicate incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-stop-duplicate-incidents/m-p/449878#M1295</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am receiving lots of duplicate incidents on my Cortex XDR console. Can anyone please help on how to suppress or stop the duplicate incidents to trigger again and again?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 08:12:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-stop-duplicate-incidents/m-p/449878#M1295</guid>
      <dc:creator>RahulPrajapati</dc:creator>
      <dc:date>2021-11-29T08:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to stop Duplicate incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-stop-duplicate-incidents/m-p/449933#M1299</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191065"&gt;@RahulPrajapati&lt;/a&gt;&amp;nbsp;, an incident is an aggregation of alerts. You may have incidents with the same description if the actions that create the alert keeps occuring.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;There are two items that you need to verify from your end:&lt;BR /&gt;1. Have you identified from the endpoint or event source if these actions are happening repeatedly to cause new incidents to get created?&lt;/P&gt;&lt;P&gt;2. Have you identified from the Incidents if the artefacts are the same for all duplicate Incidents, and if the actions are happening at the timestamps specified in the alerts grouped inside each Incident?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you know that these incidents are benign in nature, you can consider creating one or more &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-endpoint-alerts/alert-exclusions/add-an-alert-exclusion.html" target="_blank"&gt;Alert Exclusions&lt;/A&gt;&amp;nbsp;to suppress alerts.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 09:45:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-stop-duplicate-incidents/m-p/449933#M1299</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2021-11-29T09:45:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to stop Duplicate incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-stop-duplicate-incidents/m-p/450331#M1303</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192661"&gt;@bbarmanroy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes these action are occurring repeatedly and from same artefacts. The file on which we are receiving alerts is malicious in nature and we have blocked its hash. But still, it keeps appearing again even if it is in blocked state.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As per your suggestion to create an alert exclusion to suppress alerts. Will the file remain in blocked state after creating an exclusion? We want that file to remain in blocked state after creating an exclusion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 05:18:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-stop-duplicate-incidents/m-p/450331#M1303</guid>
      <dc:creator>RahulPrajapati</dc:creator>
      <dc:date>2021-11-30T05:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to stop Duplicate incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-stop-duplicate-incidents/m-p/450351#M1304</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191065"&gt;@RahulPrajapati&lt;/a&gt;&amp;nbsp;Yes, the file continues to remain blocked after creating an exclusion. Exclusions do not influence any XDR agent actions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ref: &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PO8MCAW" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PO8MCAW&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 09:38:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-stop-duplicate-incidents/m-p/450351#M1304</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2021-11-30T09:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to stop Duplicate incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-stop-duplicate-incidents/m-p/450352#M1305</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191065"&gt;@RahulPrajapati&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;after creating the exclussion the malware will be still blocked. Alert exclussion just excludes the alert to create more incidents, but the alerts will be still created (you will be able to find them with xql queries) but wont create noise on your incidents table, just that. And you will still be in safe (malware will remain blocked).&lt;/P&gt;&lt;P&gt;Watch out do not confuse exclussion with exception, exception will make the malware to not to be blocked (alerts wont be created then). So make sure when you create an exception that you know what you are doing otherwise you might be allowing a malware to run and spread over your infrastructure and without being alerted.&lt;/P&gt;&lt;P&gt;On the actions for the malware profile you can choose different actions, try to put it in quarantine.&lt;/P&gt;&lt;P&gt;It will also be good to figure out why this malware is appearing again and again. This is something for you guys to investigate if somebody is downloading it repeatedly or something. So try to figure out the root cause of your infection to end it up for ever.&lt;/P&gt;&lt;P&gt;You can also choose to delete your malware file from all your infrastructure.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Luis&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 09:41:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-stop-duplicate-incidents/m-p/450352#M1305</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2021-11-30T09:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to stop Duplicate incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-stop-duplicate-incidents/m-p/450390#M1307</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192661"&gt;@bbarmanroy&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190764"&gt;@eluis&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply. My queries has been answered.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 13:26:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-stop-duplicate-incidents/m-p/450390#M1307</guid>
      <dc:creator>RahulPrajapati</dc:creator>
      <dc:date>2021-11-30T13:26:31Z</dc:date>
    </item>
  </channel>
</rss>

