<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XDR Alerts in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-alerts/m-p/526632#M3370</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/242705"&gt;@YilmazDincer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the alerts table, we have couple of columns &amp;nbsp;besides alert sources, which shows in details the categories and modules through which alerts are generated. This works best in case of XDR agent based alerts. The two columns are “Category” and “Module”.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try viewing these two column and later use these as filter and you should be able to segregate alerts on basis of your requirements of category and modules of alerts as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;please mark this response as “Accept as Solution” if it resolves your query.&lt;/P&gt;</description>
    <pubDate>Wed, 11 Jan 2023 11:16:55 GMT</pubDate>
    <dc:creator>neelrohit</dc:creator>
    <dc:date>2023-01-11T11:16:55Z</dc:date>
    <item>
      <title>XDR Alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-alerts/m-p/526626#M3369</link>
      <description>&lt;P&gt;I want to process the alarms received by XDR. To do this, I first need to separate the incoming alarms according to their class. If I separate them according to source, I should examine them in 4 classes as "XDR IOC, XDR BIOC, XDR Agents, XDR Analytics". Does this cover them all?&lt;/P&gt;
&lt;P&gt;And is there a source that shows the alarms brought by "XDR Agents" (for example Wildfire )?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2023 09:33:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-alerts/m-p/526626#M3369</guid>
      <dc:creator>YilmazDincer</dc:creator>
      <dc:date>2023-01-11T09:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-alerts/m-p/526632#M3370</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/242705"&gt;@YilmazDincer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the alerts table, we have couple of columns &amp;nbsp;besides alert sources, which shows in details the categories and modules through which alerts are generated. This works best in case of XDR agent based alerts. The two columns are “Category” and “Module”.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try viewing these two column and later use these as filter and you should be able to segregate alerts on basis of your requirements of category and modules of alerts as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;please mark this response as “Accept as Solution” if it resolves your query.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2023 11:16:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-alerts/m-p/526632#M3370</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-01-11T11:16:55Z</dc:date>
    </item>
  </channel>
</rss>

