<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Incident reported late on Console in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incident-reported-late-on-console/m-p/538717#M4123</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/236325"&gt;@Shahwaz_Md&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;What &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163390"&gt;@KanwarSingh01&lt;/a&gt;&amp;nbsp; was hoping for was to provide more information about the alert that was triggered:&lt;/P&gt;
&lt;P&gt;- Alert name&lt;/P&gt;
&lt;P&gt;- Alert source&lt;/P&gt;
&lt;P&gt;- Alert action&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What posibility I can think of is that you have created BIOC rule or added IOC. When you add BIOC or IOC, XDR console will start searching all the existing logs in the data lake and will trigger retrospective alert. The purpose of this is to alert you if at any time in the past any of those new indicators were observed in your environment. To sum up - creating indicator IOC or BIOC will trigger automatic search for these indicators in the EDR data in the data lake, not only future detections.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not completely sure if new BIOCs from Palo Alto (via content update) will also trigger retrospective alert, but it is also possible that content update have triggered your alert.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"I am trying to understand how much time does it take for an alert to become an incident and what is the critieria for it."&lt;/P&gt;
&lt;P&gt;Alert will always trigger incident immidetially when it is received by XDR console (well technically it will either create new alert or it will decide to aggregate it to existing incident, but still it will immediately after alert is received by the console)&lt;/P&gt;</description>
    <pubDate>Fri, 14 Apr 2023 06:32:44 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2023-04-14T06:32:44Z</dc:date>
    <item>
      <title>Incident reported late on Console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incident-reported-late-on-console/m-p/538608#M4111</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are incidents on XDR Console which have alert dated 10-12 days back. Need to understand the time gap and why this incident was not observed on the same day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2023 12:48:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incident-reported-late-on-console/m-p/538608#M4111</guid>
      <dc:creator>Shahwaz_Md</dc:creator>
      <dc:date>2023-04-13T12:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: Incident reported late on Console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incident-reported-late-on-console/m-p/538668#M4115</link>
      <description>&lt;P&gt;Hi, Is it possible for you to post more details on your asked question?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2023 22:55:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incident-reported-late-on-console/m-p/538668#M4115</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2023-04-13T22:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: Incident reported late on Console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incident-reported-late-on-console/m-p/538710#M4121</link>
      <description>&lt;P&gt;Hi Kanwar,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is one incident which got triggered on 28th march but it has an alert dated 12th march. I am trying to understand how much time does it take for an alert to become an incident and what is the critieria for it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 05:01:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incident-reported-late-on-console/m-p/538710#M4121</guid>
      <dc:creator>Shahwaz_Md</dc:creator>
      <dc:date>2023-04-14T05:01:59Z</dc:date>
    </item>
    <item>
      <title>Re: Incident reported late on Console</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incident-reported-late-on-console/m-p/538717#M4123</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/236325"&gt;@Shahwaz_Md&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;What &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163390"&gt;@KanwarSingh01&lt;/a&gt;&amp;nbsp; was hoping for was to provide more information about the alert that was triggered:&lt;/P&gt;
&lt;P&gt;- Alert name&lt;/P&gt;
&lt;P&gt;- Alert source&lt;/P&gt;
&lt;P&gt;- Alert action&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What posibility I can think of is that you have created BIOC rule or added IOC. When you add BIOC or IOC, XDR console will start searching all the existing logs in the data lake and will trigger retrospective alert. The purpose of this is to alert you if at any time in the past any of those new indicators were observed in your environment. To sum up - creating indicator IOC or BIOC will trigger automatic search for these indicators in the EDR data in the data lake, not only future detections.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not completely sure if new BIOCs from Palo Alto (via content update) will also trigger retrospective alert, but it is also possible that content update have triggered your alert.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"I am trying to understand how much time does it take for an alert to become an incident and what is the critieria for it."&lt;/P&gt;
&lt;P&gt;Alert will always trigger incident immidetially when it is received by XDR console (well technically it will either create new alert or it will decide to aggregate it to existing incident, but still it will immediately after alert is received by the console)&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 06:32:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incident-reported-late-on-console/m-p/538717#M4123</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-04-14T06:32:44Z</dc:date>
    </item>
  </channel>
</rss>

