<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: A question from the Endpoint Administration Part 2 webinar: Alert ID in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-endpoint-administration-part-2-webinar-alert/m-p/519399#M3054</link>
    <description>&lt;P&gt;I was actually the one who asked that question during the webinar. Thanks for responding, but I don't think this applies to the behavior I was describing.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've attached two screenshots of outlier alerts. You can see Alert IDs are sorted, and most of the Timestamps for those are generated in the same order - the bigger the alert ID number, the newer the timestamps. Notice how there are some outlier examples when an older timestamp is assigned to a newer alert ID, looks like backdating was applied to something that was detected.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please explain this?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Oct 2022 14:45:20 GMT</pubDate>
    <dc:creator>rufat87</dc:creator>
    <dc:date>2022-10-27T14:45:20Z</dc:date>
    <item>
      <title>A question from the Endpoint Administration Part 2 webinar: Alert ID</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-endpoint-administration-part-2-webinar-alert/m-p/515723#M2873</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We often notice alert_id out of the numerical order, chronologically, sometimes way off. It appears like XDR is detecting something later and assigning an older timestamp but a new alert_id to detection. Can someone provide some detail/explanation on this observed behavior?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Note: This question was asked during a customer success webinar: Endpoint Administration Part 2&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 18:02:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-endpoint-administration-part-2-webinar-alert/m-p/515723#M2873</guid>
      <dc:creator>rtsedaka</dc:creator>
      <dc:date>2022-09-22T18:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: A question from the Endpoint Administration Part 2 webinar: Alert ID</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-endpoint-administration-part-2-webinar-alert/m-p/515724#M2874</link>
      <description>&lt;P&gt;A reply by the CS webinar team:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This is because the Alert table exposes only Critical to Low severity alerts and does not show "Informational Severity Alerts". In most cases, you would have more "Informational Alerts" in between the listed alerts. You would see some informational alerts under the "insights" tab of an Incident card. If you are an XDR Pro customer, to have an idea of the volume of Information Severity alerts that create the gap, go to Cortex XDR UI &amp;gt; Detection Rules &amp;gt; BIOC &amp;gt; On the top right, click Analytics BIOC &amp;gt; Expose and lock "# of Alerts field" &amp;gt; filter for only Informational Severity Alerts &amp;gt; Sort in descending order (It may be in millions or higher thousands for each line)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 18:04:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-endpoint-administration-part-2-webinar-alert/m-p/515724#M2874</guid>
      <dc:creator>rtsedaka</dc:creator>
      <dc:date>2022-09-22T18:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: A question from the Endpoint Administration Part 2 webinar: Alert ID</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-endpoint-administration-part-2-webinar-alert/m-p/519399#M3054</link>
      <description>&lt;P&gt;I was actually the one who asked that question during the webinar. Thanks for responding, but I don't think this applies to the behavior I was describing.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've attached two screenshots of outlier alerts. You can see Alert IDs are sorted, and most of the Timestamps for those are generated in the same order - the bigger the alert ID number, the newer the timestamps. Notice how there are some outlier examples when an older timestamp is assigned to a newer alert ID, looks like backdating was applied to something that was detected.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please explain this?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 14:45:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-endpoint-administration-part-2-webinar-alert/m-p/519399#M3054</guid>
      <dc:creator>rufat87</dc:creator>
      <dc:date>2022-10-27T14:45:20Z</dc:date>
    </item>
    <item>
      <title>Re: A question from the Endpoint Administration Part 2 webinar: Alert ID</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-endpoint-administration-part-2-webinar-alert/m-p/519694#M3073</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/209466"&gt;@rufat87&lt;/a&gt;&amp;nbsp;.&amp;nbsp; If I understand your question correctly you’re wondering why the Alert IDs aren’t in chronological order.&amp;nbsp; Well, Alert IDs aren’t necessarily generated in chronological order.&amp;nbsp; It’s possible that these could be analytics alerts or alerts that are aggregated which could explain the difference between Alert ID and Timestamp.&amp;nbsp; There are several different ways in which Cortex XDR generates alerts and some of these populate quicker than others.&amp;nbsp; As mentioned above by @Rtsedaka it’s also possible that some of the alerts in questions are informational severity and therefore not displayed in the view in the images you posted.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To get more detailed information about the Alert IDs and their correlations with timestamps I would suggest opening a support case.&amp;nbsp; You can give them specifics about your environment that may help get to the answer you’re looking for.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://support.paloaltonetworks.com/Support/Index" target="_blank"&gt;&lt;SPAN&gt;https://support.paloaltonetworks.com/Support/Index&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 16:25:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-endpoint-administration-part-2-webinar-alert/m-p/519694#M3073</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2022-10-31T16:25:55Z</dc:date>
    </item>
  </channel>
</rss>

