<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Closure of Bulk Alerts in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/closure-of-bulk-alerts/m-p/505382#M2248</link>
    <description>&lt;P&gt;We had resolved the incidents and&amp;nbsp;&lt;SPAN&gt;used the option to close the associated alerts, but still in the alerts table we see the alerts &lt;U&gt;resolution status&lt;/U&gt; as "&lt;STRONG&gt;NEW&lt;/STRONG&gt;". &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We currently have 2.8M alerts which are associated with already closed incidents and yet thier resolution status is still "&lt;STRONG&gt;NEW&lt;/STRONG&gt;".&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jun 2022 12:33:00 GMT</pubDate>
    <dc:creator>Aiman_Fathima</dc:creator>
    <dc:date>2022-06-22T12:33:00Z</dc:date>
    <item>
      <title>Closure of Bulk Alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/closure-of-bulk-alerts/m-p/505196#M2229</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Can anyone please suggest on how we can close bulk alerts on XDR. Currently we can only select 100 at a time.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 16:01:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/closure-of-bulk-alerts/m-p/505196#M2229</guid>
      <dc:creator>Aiman_Fathima</dc:creator>
      <dc:date>2022-06-21T16:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: Closure of Bulk Alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/closure-of-bulk-alerts/m-p/505208#M2230</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/224150"&gt;@Aiman_Fathima&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even though, you have the possibility to resolve alerts from the Alert table, you need to work on the Incidents and close those.&lt;/P&gt;&lt;P&gt;If you are looking at the Alert Table, right-click on an Alert and go to&lt;STRONG&gt; Pivots to views&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;View related incidents.&lt;/STRONG&gt;&lt;BR /&gt;You can also add the column Incident ID to the Alert table.&lt;/P&gt;&lt;P&gt;But remember that you need to work from the Incident view and not from the Alert table directly.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 16:24:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/closure-of-bulk-alerts/m-p/505208#M2230</guid>
      <dc:creator>fmoixsante</dc:creator>
      <dc:date>2022-06-21T16:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: Closure of Bulk Alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/closure-of-bulk-alerts/m-p/505217#M2231</link>
      <description>&lt;P&gt;Thank you for your suggestion. W&lt;SPAN&gt;e tried the above but still they do not get resolved sometimes so was wondering if there are any other methods&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 16:34:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/closure-of-bulk-alerts/m-p/505217#M2231</guid>
      <dc:creator>Aiman_Fathima</dc:creator>
      <dc:date>2022-06-21T16:34:27Z</dc:date>
    </item>
    <item>
      <title>Re: Closure of Bulk Alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/closure-of-bulk-alerts/m-p/505220#M2232</link>
      <description>&lt;P&gt;Hi Aiman,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you share a snapshot of the issue you're experiencing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Silviu&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 16:35:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/closure-of-bulk-alerts/m-p/505220#M2232</guid>
      <dc:creator>SilviuMihailDascalu</dc:creator>
      <dc:date>2022-06-21T16:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: Closure of Bulk Alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/closure-of-bulk-alerts/m-p/505365#M2245</link>
      <description>&lt;P&gt;Sorry cannot share the screenshot. The issue is that we have closed the incidents with 'resolve alerts option' but still the alerts are open.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 08:51:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/closure-of-bulk-alerts/m-p/505365#M2245</guid>
      <dc:creator>Aiman_Fathima</dc:creator>
      <dc:date>2022-06-22T08:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: Closure of Bulk Alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/closure-of-bulk-alerts/m-p/505371#M2246</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/224150"&gt;@Aiman_Fathima&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems it is still not clear who the incident and alert process work in XDR. You do not resolve alerts, you resolve incidents. When you set the status of an incident "Resolved-xxx", you get the option to "resolve" the associated alerts. In the Alert table, you have the column "&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-endpoint-alerts/cortex-xdr-alerts#:~:text=triggered%20the%20alert.-,RESOLUTION%20STATUS,-The%20status%20that" target="_self"&gt;&lt;SPAN&gt;Resolution Status&lt;/SPAN&gt;&lt;/A&gt;". This column allows you to know if the alert was handled. The alerts will NOT disappeared. You can hide them by using filters, though.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are 2 ways to "resolve" alerts. One by resolving incidents, another by changing the resolution status directly on the alert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And&amp;nbsp;&lt;SPAN&gt;remember that you need to work from the Incident view and not from the Alert table directly&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 09:14:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/closure-of-bulk-alerts/m-p/505371#M2246</guid>
      <dc:creator>fmoixsante</dc:creator>
      <dc:date>2022-06-22T09:14:58Z</dc:date>
    </item>
    <item>
      <title>Re: Closure of Bulk Alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/closure-of-bulk-alerts/m-p/505382#M2248</link>
      <description>&lt;P&gt;We had resolved the incidents and&amp;nbsp;&lt;SPAN&gt;used the option to close the associated alerts, but still in the alerts table we see the alerts &lt;U&gt;resolution status&lt;/U&gt; as "&lt;STRONG&gt;NEW&lt;/STRONG&gt;". &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We currently have 2.8M alerts which are associated with already closed incidents and yet thier resolution status is still "&lt;STRONG&gt;NEW&lt;/STRONG&gt;".&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 12:33:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/closure-of-bulk-alerts/m-p/505382#M2248</guid>
      <dc:creator>Aiman_Fathima</dc:creator>
      <dc:date>2022-06-22T12:33:00Z</dc:date>
    </item>
    <item>
      <title>Re: Closure of Bulk Alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/closure-of-bulk-alerts/m-p/506001#M2275</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/224150"&gt;@Aiman_Fathima&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can suppress the Alerts by using Alert Exclusions. By suppressing the alerts will auto resolved the incidents respectively.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mansoor&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 10:08:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/closure-of-bulk-alerts/m-p/506001#M2275</guid>
      <dc:creator>Jaitapkar</dc:creator>
      <dc:date>2022-06-24T10:08:08Z</dc:date>
    </item>
  </channel>
</rss>

