<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR Alerts in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts/m-p/515447#M2858</link>
    <description>&lt;P&gt;Hi!&lt;BR /&gt;&lt;BR /&gt;While&amp;nbsp;&lt;SPAN&gt;incident/alert information is not currently accessible via XQL, we do offer a few OOTB widgets which could be similar to what you're looking to create.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;If you'd go into your XDR tenant -&amp;gt; Dashboards &amp;amp; Reports -&amp;gt; Widget Library and type 'severity' in the search bar you should be able to find the&amp;nbsp;'Open Incidents By Severity' widget (screenshot attached below).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mavraham_0-1663677597658.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44007i7C1147F04F912C4F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="mavraham_0-1663677597658.png" alt="mavraham_0-1663677597658.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Let me know if you have any further questions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 20 Sep 2022 12:41:36 GMT</pubDate>
    <dc:creator>mavraham</dc:creator>
    <dc:date>2022-09-20T12:41:36Z</dc:date>
    <item>
      <title>Cortex XDR Alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts/m-p/324065#M56</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't seem to find what I'm looking for in the Cortex XDR console. I am trying to find a way to view all alerts generated whether it is from XDR or Analytics. The only way I can see this list is if I create an exclusion Investigation --&amp;gt; Exclusions --&amp;gt; Add Exclusion. Is there a more direct way to view these Alerts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2020 15:04:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts/m-p/324065#M56</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-04-21T15:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts/m-p/324089#M58</link>
      <description>&lt;P&gt;HI there-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Go to &lt;STRONG&gt;Investigation&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Incidents&lt;/STRONG&gt; - then click on &lt;STRONG&gt;Alerts Table&lt;/STRONG&gt; over to the right of the screen.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dfalcon_2-1587486154305.png" style="width: 893px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25287i2D3D64F2B3F89403/image-dimensions/893x134/is-moderation-mode/true?v=v2" width="893" height="134" role="button" title="dfalcon_2-1587486154305.png" alt="dfalcon_2-1587486154305.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2020 16:23:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts/m-p/324089#M58</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-04-21T16:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts/m-p/324103#M61</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/47142"&gt;@dfalcon&lt;/a&gt;!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Feels like it is hidden away. They should be making this a submenu directly off of the Investigation menu.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2020 17:38:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts/m-p/324103#M61</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-04-21T17:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts/m-p/324110#M63</link>
      <description>&lt;P&gt;I will share that feedback with the Product Team.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2020 17:45:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts/m-p/324110#M63</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-04-21T17:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts/m-p/515369#M2857</link>
      <description>&lt;P&gt;I too was having the same problem... wanting to look at the Alerts and how those turn into Incidents. I think it would be great to have a dashboard widget that would present a bar graph that shows the volume of Low, Medium, High and Critical alerts. Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 20:44:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts/m-p/515369#M2857</guid>
      <dc:creator>NPTEChrisSmith</dc:creator>
      <dc:date>2022-09-19T20:44:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts/m-p/515447#M2858</link>
      <description>&lt;P&gt;Hi!&lt;BR /&gt;&lt;BR /&gt;While&amp;nbsp;&lt;SPAN&gt;incident/alert information is not currently accessible via XQL, we do offer a few OOTB widgets which could be similar to what you're looking to create.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;If you'd go into your XDR tenant -&amp;gt; Dashboards &amp;amp; Reports -&amp;gt; Widget Library and type 'severity' in the search bar you should be able to find the&amp;nbsp;'Open Incidents By Severity' widget (screenshot attached below).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mavraham_0-1663677597658.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44007i7C1147F04F912C4F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="mavraham_0-1663677597658.png" alt="mavraham_0-1663677597658.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Let me know if you have any further questions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 12:41:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts/m-p/515447#M2858</guid>
      <dc:creator>mavraham</dc:creator>
      <dc:date>2022-09-20T12:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts/m-p/515472#M2859</link>
      <description>OK - I'm not sure what " alert information is not currently accessible via XQL" means, since the Alert table is available and our's currently shows 3600 results.&lt;BR /&gt;Is it possible to allow us to add the ALERT TABLE as a favorite button? That way I can get into it with a single button, verses having to go into via the Incident screen?&lt;BR /&gt;Thank you,&lt;BR /&gt;Chris Smith&lt;BR /&gt;</description>
      <pubDate>Tue, 20 Sep 2022 16:08:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts/m-p/515472#M2859</guid>
      <dc:creator>NPTEChrisSmith</dc:creator>
      <dc:date>2022-09-20T16:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts/m-p/521309#M3147</link>
      <description>&lt;P&gt;Had this issue today. I said the same thing when I found Alerts Table: "why isn't this an option indented under Incidents"&lt;BR /&gt;You can keep it where it is but add the direct link as well&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 18:24:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts/m-p/521309#M3147</guid>
      <dc:creator>Optimizer</dc:creator>
      <dc:date>2022-11-15T18:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts/m-p/523716#M3244</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/238265"&gt;@NPTEChrisSmith&lt;/a&gt; and &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/255006"&gt;@Optimizer&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe Alert Table is not in the navigation bar, because Palo wants you to steer your focus on more important Incidents.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cortex XDR console will generate Incident for each alert with severity Medium, High and Critical. It will generate incident &lt;U&gt;some &lt;/U&gt;Low severity alert, but not all of them.&lt;/P&gt;
&lt;P&gt;Incidents are simple containers, which will consolidate/aggregate all alert that are somehow related.&lt;/P&gt;
&lt;P&gt;So it should be more easy to focus on the Incidents and not overwhelm by avalanche of alerts&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now that being said there are two easy way to navigate to Alert table without jumping around:&lt;/P&gt;
&lt;P&gt;- The easiest way would be to open URL &lt;A href="https://&amp;lt;your-xdr-address&amp;gt;/alerts" target="_blank"&gt;https://&amp;lt;your-xdr-address&amp;gt;/alerts&lt;/A&gt;&amp;nbsp; You can bookmark this URL and just click on your bookmark after you authenticate (if open the link after authentication, you will be redirected to the dashboard)&lt;/P&gt;
&lt;P&gt;- You can use the quick launcher and its "go to" search. Type "/alert" - / to enter go to search and "alert" for the string you want to search. You will see the results below, navigate with arrows and enter to select&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_1-1670602698569.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46025iD8676B2721E69351/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_1-1670602698569.png" alt="Astardzhiev_1-1670602698569.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 16:19:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts/m-p/523716#M3244</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-12-09T16:19:50Z</dc:date>
    </item>
  </channel>
</rss>

