<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to get the list of alerts/incidents for a particular list of hosts? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-get-the-list-of-alerts-incidents-for-a-particular-list-of/m-p/505316#M2241</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I need to know how can we get alerts for particular hosts/ a specific group ( Ex: 1000 agents ) in the Cortex XDR console -&amp;gt; Incident Response -&amp;gt; Incidents -&amp;gt; Alerts table. I have tried from filter option but it doesn't work. We can't add all the agent names in the hostname for the 1000 servers as it is time-consuming. So, is there any other way to get alerts only for specific agents / for a group?&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jun 2022 03:31:56 GMT</pubDate>
    <dc:creator>Kavurisowmya</dc:creator>
    <dc:date>2022-06-22T03:31:56Z</dc:date>
    <item>
      <title>How to get the list of alerts/incidents for a particular list of hosts?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-get-the-list-of-alerts-incidents-for-a-particular-list-of/m-p/505316#M2241</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I need to know how can we get alerts for particular hosts/ a specific group ( Ex: 1000 agents ) in the Cortex XDR console -&amp;gt; Incident Response -&amp;gt; Incidents -&amp;gt; Alerts table. I have tried from filter option but it doesn't work. We can't add all the agent names in the hostname for the 1000 servers as it is time-consuming. So, is there any other way to get alerts only for specific agents / for a group?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 03:31:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-get-the-list-of-alerts-incidents-for-a-particular-list-of/m-p/505316#M2241</guid>
      <dc:creator>Kavurisowmya</dc:creator>
      <dc:date>2022-06-22T03:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to get the list of alerts/incidents for a particular list of hosts?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-get-the-list-of-alerts-incidents-for-a-particular-list-of/m-p/505358#M2242</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/222168"&gt;@Kavurisowmya&lt;/a&gt;&amp;nbsp;there are a few workarounds to address your ask:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- use starring configuration for those endpoints&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- use alerts/incidents API and retrieve 100 at a time, and then xref against endpoints API/dataset&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the use case that you're trying to solve? It is generally not recommended to filter alerts based on hosts as XDR stitches them in incidents.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 08:09:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-get-the-list-of-alerts-incidents-for-a-particular-list-of/m-p/505358#M2242</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-06-22T08:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to get the list of alerts/incidents for a particular list of hosts?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-get-the-list-of-alerts-incidents-for-a-particular-list-of/m-p/505364#M2244</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192661"&gt;@bbarmanroy&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;We want to manage alerts for a particular group of assets related to the same environment. We have different endpoint groups with each &amp;lt;100 endpoint. So we want to group the alerts only for those endpoints.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 08:39:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-get-the-list-of-alerts-incidents-for-a-particular-list-of/m-p/505364#M2244</guid>
      <dc:creator>Kavurisowmya</dc:creator>
      <dc:date>2022-06-22T08:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to get the list of alerts/incidents for a particular list of hosts?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-get-the-list-of-alerts-incidents-for-a-particular-list-of/m-p/505373#M2247</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/222168"&gt;@Kavurisowmya&lt;/a&gt;&amp;nbsp;that is not a recommended approach to incident resolution in XDR. Since alerts are stitched to incidents, and an incident can contain alerts from multiple sources. The challenge is that one might miss attach path maps/chains with your suggested approach.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 10:14:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-get-the-list-of-alerts-incidents-for-a-particular-list-of/m-p/505373#M2247</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-06-22T10:14:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to get the list of alerts/incidents for a particular list of hosts?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-get-the-list-of-alerts-incidents-for-a-particular-list-of/m-p/506305#M2278</link>
      <description>&lt;P&gt;Hi, We have alerts that need to be reviewed for specific assets/endpoints and enable block mode only for them. Can this be done with the starring/using Xref? Is there any other way?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2022 04:18:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-get-the-list-of-alerts-incidents-for-a-particular-list-of/m-p/506305#M2278</guid>
      <dc:creator>Kavurisowmya</dc:creator>
      <dc:date>2022-06-27T04:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to get the list of alerts/incidents for a particular list of hosts?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-get-the-list-of-alerts-incidents-for-a-particular-list-of/m-p/506464#M2287</link>
      <description>&lt;P&gt;Hi Kavurisowmya,&lt;/P&gt;&lt;P&gt;Cortex XDR Prevention Profiles contain the specific settings for how XDR will enforce the specific modules (Block or Report only), these profiles are then tied to endpoints via Prevention Policy rules. In order to enable blocking on a particular group of hosts, create an "Endpoint Group" that contains all of the intended hosts, then create a Prevention Policy that's target is set to the Endpoint Group you created and ensure that the Profiles you assign to this policy contain the specific settings you want applied to this group of endpoints.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192661"&gt;@bbarmanroy&lt;/a&gt;&amp;nbsp;mentioned, you can then create a starring configuration specifically for that endpoint group you created. Once you do that you will be able to filter in the Alerts table based on if the Alert is "Starred". You can also filter the Incidents table based on the Starring field as well so you will be aware if any Incidents involve a host that is in your target group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2022 14:04:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-get-the-list-of-alerts-incidents-for-a-particular-list-of/m-p/506464#M2287</guid>
      <dc:creator>bbucao</dc:creator>
      <dc:date>2022-06-27T14:04:09Z</dc:date>
    </item>
  </channel>
</rss>

