<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change in the way URL Filtering alerts are presented in Cortex XDR? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/change-in-the-way-url-filtering-alerts-are-presented-in-cortex/m-p/342227#M230</link>
    <description>&lt;P&gt;thanks so much&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/47142"&gt;@dfalcon&lt;/a&gt;&amp;nbsp;I did indeed create a request within the Support team and currently its been escalated to Engineering.&lt;BR /&gt;For those that might have / want a reference of this, its PAN Support Case 01544546. &amp;nbsp;I will share here updates if applicable.&lt;/P&gt;</description>
    <pubDate>Wed, 05 Aug 2020 14:46:53 GMT</pubDate>
    <dc:creator>KRisselada</dc:creator>
    <dc:date>2020-08-05T14:46:53Z</dc:date>
    <item>
      <title>Change in the way URL Filtering alerts are presented in Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/change-in-the-way-url-filtering-alerts-are-presented-in-cortex/m-p/341628#M225</link>
      <description>&lt;P&gt;Hello, beginning on or about 20 July, began to see MANY more Incidents created in Cortex XDR that looked similar to this:&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;Incident Description: 'Threat ID #' generated by PAN NGFW detected on host &amp;lt;hostName&amp;gt; involving xyz\UserName&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;(note, there is NOTHING after the "#" sign)&lt;/P&gt;&lt;P&gt;Incident Sources: PAN NGFW&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When looking at the Alert that caused this Cortex Incident, what you see is:&lt;BR /&gt;Category: "URL Filtering"&lt;BR /&gt;Alert Name: "Threat ID #"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I should not that I believe BEFORE this apparent change or bug, within Cortex XDR Alerts page we would see something like this:&lt;BR /&gt;Category: "URL Filtering (10082)"&lt;BR /&gt;Alert Name: "Threat ID #9999"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial black,avant garde"&gt;Are others noticing this too?&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="arial black,avant garde" color="#FF0000"&gt;Is this the desired / expected behavior of Cortex XDR?&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="comic sans ms,sans-serif"&gt;It seems like there has been a CHANGE in the way Cortex presents these Alerts and Incidents&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial black,avant garde" color="#FF0000"&gt;Is there knowledge and expectations its operating this way?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" color="#000000"&gt;See attached screenshots&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 16:43:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/change-in-the-way-url-filtering-alerts-are-presented-in-cortex/m-p/341628#M225</guid>
      <dc:creator>KRisselada</dc:creator>
      <dc:date>2020-07-31T16:43:17Z</dc:date>
    </item>
    <item>
      <title>Re: Change in the way URL Filtering alerts are presented in Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/change-in-the-way-url-filtering-alerts-are-presented-in-cortex/m-p/341646#M226</link>
      <description>&lt;P&gt;I should also note I find this in the Cortex XDR Pro Administrators Guide:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KRisselada_0-1596217511434.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27105i457D2F5BE18A9140/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="KRisselada_0-1596217511434.png" alt="KRisselada_0-1596217511434.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-endpoint-alerts/cortex-xdr-alerts" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-endpoint-alerts/cortex-xdr-alerts&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Which doesn't seem to entirely mesh with what have been seeing. &amp;nbsp;Is the Guide correct or is the Production environment of Cortex correct?&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 17:46:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/change-in-the-way-url-filtering-alerts-are-presented-in-cortex/m-p/341646#M226</guid>
      <dc:creator>KRisselada</dc:creator>
      <dc:date>2020-07-31T17:46:24Z</dc:date>
    </item>
    <item>
      <title>Re: Change in the way URL Filtering alerts are presented in Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/change-in-the-way-url-filtering-alerts-are-presented-in-cortex/m-p/342223#M229</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/136463"&gt;@KRisselada&lt;/a&gt;-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There very well may be adjustments to rules (analytics, bioc, etc) with each release.&amp;nbsp; For the behavior you are describing, this should not be typical.&amp;nbsp; In this instance, I recommend reaching out to support/TAC to allow our engineers to take a look.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 14:20:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/change-in-the-way-url-filtering-alerts-are-presented-in-cortex/m-p/342223#M229</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-08-05T14:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: Change in the way URL Filtering alerts are presented in Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/change-in-the-way-url-filtering-alerts-are-presented-in-cortex/m-p/342227#M230</link>
      <description>&lt;P&gt;thanks so much&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/47142"&gt;@dfalcon&lt;/a&gt;&amp;nbsp;I did indeed create a request within the Support team and currently its been escalated to Engineering.&lt;BR /&gt;For those that might have / want a reference of this, its PAN Support Case 01544546. &amp;nbsp;I will share here updates if applicable.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 14:46:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/change-in-the-way-url-filtering-alerts-are-presented-in-cortex/m-p/342227#M230</guid>
      <dc:creator>KRisselada</dc:creator>
      <dc:date>2020-08-05T14:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: Change in the way URL Filtering alerts are presented in Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/change-in-the-way-url-filtering-alerts-are-presented-in-cortex/m-p/342230#M231</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/136463"&gt;@KRisselada&lt;/a&gt;-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see that Jacqueline escalated the case to engineering.&amp;nbsp; I will subscribe to the case as well.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 15:00:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/change-in-the-way-url-filtering-alerts-are-presented-in-cortex/m-p/342230#M231</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-08-05T15:00:21Z</dc:date>
    </item>
  </channel>
</rss>

