<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alerts  on Cortex XDR Console in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alerts-on-cortex-xdr-console/m-p/529452#M3522</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;What is the importance of alerts in cortex XDR? Do we need to work on all the alerts, as we get overwhelmed by the number of alerts.&lt;/P&gt;
&lt;P&gt;What is the best practice to fine-tune the alerts so that no important alerts are missed.Is there any documentation available for related to the handling of alerts in Cortex XDR.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Feb 2023 11:52:47 GMT</pubDate>
    <dc:creator>Shashanksinha</dc:creator>
    <dc:date>2023-02-01T11:52:47Z</dc:date>
    <item>
      <title>Alerts  on Cortex XDR Console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alerts-on-cortex-xdr-console/m-p/529452#M3522</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;What is the importance of alerts in cortex XDR? Do we need to work on all the alerts, as we get overwhelmed by the number of alerts.&lt;/P&gt;
&lt;P&gt;What is the best practice to fine-tune the alerts so that no important alerts are missed.Is there any documentation available for related to the handling of alerts in Cortex XDR.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 11:52:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alerts-on-cortex-xdr-console/m-p/529452#M3522</guid>
      <dc:creator>Shashanksinha</dc:creator>
      <dc:date>2023-02-01T11:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts  on Cortex XDR Console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alerts-on-cortex-xdr-console/m-p/529463#M3523</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203123"&gt;@Shashanksinha&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Thanks for writing to Live Community.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-Alerts" target="_blank"&gt;&lt;SPAN&gt;Alert tuning &lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;is an important process as part of managing XDR, and should be done on a concurrent basis. The way to properly address alert tuning would be depending on the alert source.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;In general, alert tuning in XDR several alert tuning mechanisms:&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Agent exceptions&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Detection rule exceptions&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Utilizing the global hash allowlist&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Prevention Module based allow lists&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Add-a-Support-Exception-Rule" target="_blank"&gt;&lt;SPAN&gt;Support exceptions&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For example, if through the process of reviewing an incident you want to suppress future alerts from similar sources you need to create an Alert Exclusion policy based on the alerts in said incident.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can also build alert rules &lt;/SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Add-an-Alert-Exclusion-Rule" target="_blank"&gt;&lt;SPAN&gt;from scratch &lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;and use existing alert values to populate your exclusion criteria.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If the alert is &lt;/SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Add-an-Alert-Exclusion-Rule" target="_blank"&gt;&lt;SPAN&gt;IOC/BIOC&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; you might want to take action on specific behavior but exclude some of the indicators.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Starting with version 3.5, you can also manage exceptions from a central location by adding &lt;/SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Add-a-Legacy-Exception-Rule" target="_blank"&gt;&lt;SPAN&gt;Legacy Exception rules&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We have a great &lt;/SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/cortex-xdr-how-to-video-series-alert-tuning/ta-p/508573" target="_blank"&gt;&lt;SPAN&gt;Alert Tuning Video Series&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; over on Live Community which should help you get started on understanding the different sources of alerts and how to address them.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Hope this helps!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 14:04:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alerts-on-cortex-xdr-console/m-p/529463#M3523</guid>
      <dc:creator>mavraham</dc:creator>
      <dc:date>2023-02-01T14:04:54Z</dc:date>
    </item>
  </channel>
</rss>

