<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Modify Alerts Going to An Endpoint Group in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/modify-alerts-going-to-an-endpoint-group/m-p/470393#M1605</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/193230"&gt;@chukaokonkwo&lt;/a&gt;&amp;nbsp;What I'd advise you is to create a Starred Alert Configuration using Featured Fields.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;You can create a list of Featured Fields (link: &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-endpoint-alerts/manage-alerts.html" target="_self"&gt;here&lt;/A&gt;) using hostname, IP address, or username.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_0-1646359950456.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39466iFA985C2FA5376E28/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_0-1646359950456.png" alt="bbarmanroy_0-1646359950456.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;Create a Starring Configuration (link &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-incidents/create-a-starred-incident-policy.html" target="_self"&gt;here&lt;/A&gt;) with the featured fields.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_1-1646360144747.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39467iD61DDAD1AA16A41D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_1-1646360144747.png" alt="bbarmanroy_1-1646360144747.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;That'll star all incidents containing alerts of this nature. Populate the hosts and save the filter for quick retrieval for future use.&lt;/P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_8-1646360728865.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39474i4DCEE7B40C6FCC5B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_8-1646360728865.png" alt="bbarmanroy_8-1646360728865.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Create a Scoring Rule (link &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-incidents/create-an-incident-scoring-rule.html#id12a9b56a-e846-4aec-9bcd-046bf01bdefa" target="_blank"&gt;here&lt;/A&gt;) for Featured fields as well.&amp;nbsp;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_3-1646360325698.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39469iE99B670BB7C22EC3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_3-1646360325698.png" alt="bbarmanroy_3-1646360325698.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Create a &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/logs/create-notifications.html" target="_blank"&gt;Notifications Rule&lt;/A&gt; in the Configurations to forward all alerts that meet those criteria.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_4-1646360586606.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39470i0E02CB8CC528EFE2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_4-1646360586606.png" alt="bbarmanroy_4-1646360586606.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_5-1646360593779.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39471iAD7A2D1B8B376C79/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_5-1646360593779.png" alt="bbarmanroy_5-1646360593779.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_7-1646360640017.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39473i65C615A77EAE2062/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_7-1646360640017.png" alt="bbarmanroy_7-1646360640017.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;</description>
    <pubDate>Fri, 04 Mar 2022 02:27:00 GMT</pubDate>
    <dc:creator>bbarmanroy</dc:creator>
    <dc:date>2022-03-04T02:27:00Z</dc:date>
    <item>
      <title>Modify Alerts Going to An Endpoint Group</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/modify-alerts-going-to-an-endpoint-group/m-p/470322#M1603</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I have setup an endpoint group of high profile laptops.&amp;nbsp; I would like the following configured on XDR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Prefix all Incident names going to endpoints in that group with "VIP Endpoint [Incident Name] (e.g. VIP Endpoint Wildfire Malware Detected)&lt;/P&gt;&lt;P&gt;- When a "High" or "Medium" alert is triggered for an endpoint within that group forward it to a specific email.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the tips and insights on setting this up guys.&amp;nbsp; I've been searching back and forth in the admin guide to see if I can get the information.&amp;nbsp; If this happens I'll be sure to post it here as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 21:35:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/modify-alerts-going-to-an-endpoint-group/m-p/470322#M1603</guid>
      <dc:creator>chukaokonkwo</dc:creator>
      <dc:date>2022-03-03T21:35:11Z</dc:date>
    </item>
    <item>
      <title>Re: Modify Alerts Going to An Endpoint Group</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/modify-alerts-going-to-an-endpoint-group/m-p/470393#M1605</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/193230"&gt;@chukaokonkwo&lt;/a&gt;&amp;nbsp;What I'd advise you is to create a Starred Alert Configuration using Featured Fields.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;You can create a list of Featured Fields (link: &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-endpoint-alerts/manage-alerts.html" target="_self"&gt;here&lt;/A&gt;) using hostname, IP address, or username.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_0-1646359950456.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39466iFA985C2FA5376E28/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_0-1646359950456.png" alt="bbarmanroy_0-1646359950456.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;Create a Starring Configuration (link &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-incidents/create-a-starred-incident-policy.html" target="_self"&gt;here&lt;/A&gt;) with the featured fields.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_1-1646360144747.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39467iD61DDAD1AA16A41D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_1-1646360144747.png" alt="bbarmanroy_1-1646360144747.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;That'll star all incidents containing alerts of this nature. Populate the hosts and save the filter for quick retrieval for future use.&lt;/P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_8-1646360728865.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39474i4DCEE7B40C6FCC5B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_8-1646360728865.png" alt="bbarmanroy_8-1646360728865.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Create a Scoring Rule (link &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-incidents/create-an-incident-scoring-rule.html#id12a9b56a-e846-4aec-9bcd-046bf01bdefa" target="_blank"&gt;here&lt;/A&gt;) for Featured fields as well.&amp;nbsp;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_3-1646360325698.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39469iE99B670BB7C22EC3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_3-1646360325698.png" alt="bbarmanroy_3-1646360325698.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Create a &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/logs/create-notifications.html" target="_blank"&gt;Notifications Rule&lt;/A&gt; in the Configurations to forward all alerts that meet those criteria.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_4-1646360586606.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39470i0E02CB8CC528EFE2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_4-1646360586606.png" alt="bbarmanroy_4-1646360586606.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_5-1646360593779.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39471iAD7A2D1B8B376C79/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_5-1646360593779.png" alt="bbarmanroy_5-1646360593779.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_7-1646360640017.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39473i65C615A77EAE2062/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_7-1646360640017.png" alt="bbarmanroy_7-1646360640017.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Fri, 04 Mar 2022 02:27:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/modify-alerts-going-to-an-endpoint-group/m-p/470393#M1605</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-03-04T02:27:00Z</dc:date>
    </item>
  </channel>
</rss>

