<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Some Alert Exclusions don't work anymore in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/some-alert-exclusions-don-t-work-anymore/m-p/528142#M3439</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Possibly there is A recalculation on your tenant for your exclusion policy. Possible that there was an edit on the policy because of an edit and there is a backwards scan running. Please check backwards scan status&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 23 Jan 2023 08:17:05 GMT</pubDate>
    <dc:creator>neelrohit</dc:creator>
    <dc:date>2023-01-23T08:17:05Z</dc:date>
    <item>
      <title>Some Alert Exclusions don't work anymore</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/some-alert-exclusions-don-t-work-anymore/m-p/528021#M3431</link>
      <description>&lt;P&gt;Hello dear community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since some days, my alert exclusions do not work anymore and the alerts are popping up. Now i noticed the quotes in the target process cmd.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;powershell.exe -command --&amp;gt; before&lt;/P&gt;
&lt;P&gt;"powershell.exe" -command --&amp;gt; from now&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What has happened? The automation task wasn't changed, but maybe a behaviour change from PA?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2023 20:52:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/some-alert-exclusions-don-t-work-anymore/m-p/528021#M3431</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-01-20T20:52:52Z</dc:date>
    </item>
    <item>
      <title>Re: Some Alert Exclusions don't work anymore</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/some-alert-exclusions-don-t-work-anymore/m-p/528142#M3439</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Possibly there is A recalculation on your tenant for your exclusion policy. Possible that there was an edit on the policy because of an edit and there is a backwards scan running. Please check backwards scan status&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 08:17:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/some-alert-exclusions-don-t-work-anymore/m-p/528142#M3439</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-01-23T08:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: Some Alert Exclusions don't work anymore</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/some-alert-exclusions-don-t-work-anymore/m-p/528173#M3440</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/142551"&gt;@neelrohit&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what is an backward scan status? And why do I have to do this? Isn't there any information why this quotes suddenly appearing? And day by day I have more not working exclusions.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 13:49:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/some-alert-exclusions-don-t-work-anymore/m-p/528173#M3440</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-01-23T13:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: Some Alert Exclusions don't work anymore</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/some-alert-exclusions-don-t-work-anymore/m-p/528300#M3445</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Backwards scan is a logic which runs on the Cortex XDR console for querying past events from the date a rule has been created( IOC/BIOC) and also for alert exclusions when you want to exclude the existing alerts. If the exclusion rules were edited and checked in for exclude existing alerts, there will be a backwards scan running in. Till the time, the backwards scan is running, exclusions will not work for old alerts and only the new alerts will be excluded.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, if you are saying that it is not working for you. I recommend opening a TAC case.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 08:37:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/some-alert-exclusions-don-t-work-anymore/m-p/528300#M3445</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-01-24T08:37:58Z</dc:date>
    </item>
  </channel>
</rss>

