<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Betreff: External Alerts Mapping, Alerts are always assembled to one Incident in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/external-alerts-mapping-alerts-are-always-assembled-to-one/m-p/523250#M3219</link>
    <description>&lt;P&gt;Hello, thank you for your answer!&lt;/P&gt;
&lt;P&gt;I think the period of time is 24 hours, I see that if I hover over added alerts.&lt;BR /&gt;Sad, that this functions isn´t available in XDR.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Dec 2022 09:46:31 GMT</pubDate>
    <dc:creator>MarinusCzech</dc:creator>
    <dc:date>2022-12-05T09:46:31Z</dc:date>
    <item>
      <title>External Alerts Mapping, Alerts are always assembled to one Incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/external-alerts-mapping-alerts-are-always-assembled-to-one/m-p/522997#M3205</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a little issue and I don´t know how to solve it.&lt;/P&gt;
&lt;P&gt;Hopefully someone knows a hidden or 'unofficial' feature of XDR regarding this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Briefly explained the structual background:&lt;BR /&gt;I am logging from diffrent Forti Firewalls into the XDR, this works perfectly fine.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Via the Parsing rules, the Logs are parsed into the External Alerts Mapping, where I want to create customized Incidents from the Logs.&lt;BR /&gt;&lt;BR /&gt;My use case is, to log the activity of an admin user.&amp;nbsp;&lt;BR /&gt;The first Login and logout of the user after the external alerts mapping was configured and worked perfectly fine, but now every further login or logout is added into the first incident/alert.&lt;/P&gt;
&lt;P&gt;I tried to resolve the alerts or incident, tried to map specific log ID´s in the fields (of external alerts mapping) that XDR differ the alerts, everything without success.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hopefully somebody know as I already mentioned a feature how to stop merging alerts in the same incident/alert.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I will add a picture, maybe it is helpful. (The two alerts without host and username I tested, if new alerts are added if I remove this two fields in the external alerts mapping.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;BR /&gt;Marinus Czech&lt;/P&gt;&lt;BR /&gt;&lt;BR /&gt;Please note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or company information is not recommended.</description>
      <pubDate>Thu, 01 Dec 2022 09:51:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/external-alerts-mapping-alerts-are-always-assembled-to-one/m-p/522997#M3205</guid>
      <dc:creator>MarinusCzech</dc:creator>
      <dc:date>2022-12-01T09:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: External Alerts Mapping, Alerts are always assembled to one Incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/external-alerts-mapping-alerts-are-always-assembled-to-one/m-p/523214#M3214</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/243100"&gt;@MarinusCzech&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;XDR console will automatically aggregate repeating alert, but I forgot for what period of time so I would say one hour. Console will consider an alert as repeating if it has exact same fields. Unfortunately there isn't any to disable this behavior (at least I am not aware of any).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Incident is "container" for related alerts. Resolving the incident by itself doesn't effect the alerts. You need to resolve the alert to make it "inactive" so any new logs to create new alert. You have two ways:&lt;BR /&gt;- Manually resolving the Alert: Incident Response -&amp;gt; Incidents -&amp;gt; Alert Table -&amp;gt; Right click -&amp;gt; Change Status -&amp;gt; Resolve&lt;/P&gt;
&lt;P&gt;- By resolving incident: When resolving the incident there is a option to resolve the related alerts&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_0-1670093920261.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/45887i193009E0F4830E4D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_0-1670093920261.png" alt="Astardzhiev_0-1670093920261.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Dec 2022 19:01:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/external-alerts-mapping-alerts-are-always-assembled-to-one/m-p/523214#M3214</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-12-03T19:01:42Z</dc:date>
    </item>
    <item>
      <title>Betreff: External Alerts Mapping, Alerts are always assembled to one Incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/external-alerts-mapping-alerts-are-always-assembled-to-one/m-p/523250#M3219</link>
      <description>&lt;P&gt;Hello, thank you for your answer!&lt;/P&gt;
&lt;P&gt;I think the period of time is 24 hours, I see that if I hover over added alerts.&lt;BR /&gt;Sad, that this functions isn´t available in XDR.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 09:46:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/external-alerts-mapping-alerts-are-always-assembled-to-one/m-p/523250#M3219</guid>
      <dc:creator>MarinusCzech</dc:creator>
      <dc:date>2022-12-05T09:46:31Z</dc:date>
    </item>
  </channel>
</rss>

