<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Analytics BIOC Rules - Causality Change - No. of alerts rising, but where to see who, why and what? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/analytics-bioc-rules-causality-change-no-of-alerts-rising-but/m-p/485884#M1951</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206384"&gt;@Cyber1985&lt;/a&gt;&amp;nbsp;It appears that you looking for guidance on how to &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-endpoint-alerts/analytics-alert-view" target="_self"&gt;investigate Analytics / Analytics BIOC alert sources&lt;/A&gt;. From the Alert Table, you may right-click to "Investigate Causality Chain" to view the event table. In this view and depending on the analytics alert type, then you may have host, endpoint connection status, IP, MAC, account of interest (E.g. Username), Parent process ID located at the top left-hand corner of the causality view. If you click the red icon in the view, then you can view context about the alert. If you hover you mouse over the related processes in the causality, then you can review process and analytics profiles information to support your investigation. If you click on the processes in the casualty view, then you will be presented with all applicable actions (E.g. Process, Network, File, Network Connections).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the alert table, then you can also leverage "Pivot to View" options to conduct additional analysis on &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-artifacts-and-assets/investigate-a-user" target="_self"&gt;user&lt;/A&gt; / &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-artifacts-and-assets/investigate-an-asset#idfaca1e70-0427-48e1-ac2d-315f94ab040b" target="_self"&gt;asset&lt;/A&gt; in scope.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 May 2022 18:52:11 GMT</pubDate>
    <dc:creator>WSeldenIII</dc:creator>
    <dc:date>2022-05-09T18:52:11Z</dc:date>
    <item>
      <title>Analytics BIOC Rules - Causality Change - No. of alerts rising, but where to see who, why and what?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/analytics-bioc-rules-causality-change-no-of-alerts-rising-but/m-p/485650#M1947</link>
      <description>&lt;P&gt;Hello Admins,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We use Analytics BIOC Rules. But where is the Causality Change? No of alerts rising, but where to see who, why and what?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Sun, 08 May 2022 23:30:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/analytics-bioc-rules-causality-change-no-of-alerts-rising-but/m-p/485650#M1947</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-05-08T23:30:27Z</dc:date>
    </item>
    <item>
      <title>Re: Analytics BIOC Rules - Causality Change - No. of alerts rising, but where to see who, why and what?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/analytics-bioc-rules-causality-change-no-of-alerts-rising-but/m-p/485731#M1949</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206384"&gt;@Cyber1985&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can go to the Incidents page, then to the alerts table there you can scroll to the right to see all the columns and fields populated, CGO (Causality Group Owner), paths, processes....&lt;/P&gt;&lt;P&gt;If you click on the 3 dots menu at the top right corner of the alerts table you will see more columns and fields that are not shown by default. You can select them and incorporate them to your view.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe that you'll find there all you'r looking for.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;KR,&lt;/P&gt;&lt;P&gt;Luis&lt;/P&gt;&lt;P&gt;Just as an example:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="eluis_0-1652082866383.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40901iC43DBCEF3E03C499/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="eluis_0-1652082866383.png" alt="eluis_0-1652082866383.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2022 08:58:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/analytics-bioc-rules-causality-change-no-of-alerts-rising-but/m-p/485731#M1949</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2022-05-09T08:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: Analytics BIOC Rules - Causality Change - No. of alerts rising, but where to see who, why and what?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/analytics-bioc-rules-causality-change-no-of-alerts-rising-but/m-p/485884#M1951</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206384"&gt;@Cyber1985&lt;/a&gt;&amp;nbsp;It appears that you looking for guidance on how to &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-endpoint-alerts/analytics-alert-view" target="_self"&gt;investigate Analytics / Analytics BIOC alert sources&lt;/A&gt;. From the Alert Table, you may right-click to "Investigate Causality Chain" to view the event table. In this view and depending on the analytics alert type, then you may have host, endpoint connection status, IP, MAC, account of interest (E.g. Username), Parent process ID located at the top left-hand corner of the causality view. If you click the red icon in the view, then you can view context about the alert. If you hover you mouse over the related processes in the causality, then you can review process and analytics profiles information to support your investigation. If you click on the processes in the casualty view, then you will be presented with all applicable actions (E.g. Process, Network, File, Network Connections).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the alert table, then you can also leverage "Pivot to View" options to conduct additional analysis on &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-artifacts-and-assets/investigate-a-user" target="_self"&gt;user&lt;/A&gt; / &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-artifacts-and-assets/investigate-an-asset#idfaca1e70-0427-48e1-ac2d-315f94ab040b" target="_self"&gt;asset&lt;/A&gt; in scope.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2022 18:52:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/analytics-bioc-rules-causality-change-no-of-alerts-rising-but/m-p/485884#M1951</guid>
      <dc:creator>WSeldenIII</dc:creator>
      <dc:date>2022-05-09T18:52:11Z</dc:date>
    </item>
  </channel>
</rss>

