<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: High medium low severity in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/high-medium-low-severity/m-p/556792#M5094</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203123"&gt;@Shashanksinha&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on Live Community!&lt;/P&gt;
&lt;P&gt;The severity of an incident is govern by the severity of alerts in it. Incident will have the same severity as of the highest severity alert in it.&lt;/P&gt;
&lt;P&gt;For the alert side, severity depends on the type of alert it is. BIOC/IOC alerts will have the severity that was configured in them when those rules were created. For alerts from 3rd party integration, the severity will be same as was forwarded by the integrated product.&lt;/P&gt;
&lt;P&gt;You can refer to below document to see the severity of analytics alerts&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR-Analytics-Alert-Reference" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR-Analytics-Alert-Reference&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately there is no consolidated document to show how the severity works for all kind of alerts.&lt;/P&gt;</description>
    <pubDate>Wed, 06 Sep 2023 16:04:53 GMT</pubDate>
    <dc:creator>nsinghvirk</dc:creator>
    <dc:date>2023-09-06T16:04:53Z</dc:date>
    <item>
      <title>High medium low severity</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/high-medium-low-severity/m-p/556714#M5090</link>
      <description>&lt;P&gt;Dear Team ,&lt;/P&gt;
&lt;P&gt;On what basis high ,medium and low severity alerts/incidents&amp;nbsp; are&amp;nbsp; classified on cortex XDR&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Shashank&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 09:30:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/high-medium-low-severity/m-p/556714#M5090</guid>
      <dc:creator>Shashanksinha</dc:creator>
      <dc:date>2023-09-06T09:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: High medium low severity</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/high-medium-low-severity/m-p/556792#M5094</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203123"&gt;@Shashanksinha&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on Live Community!&lt;/P&gt;
&lt;P&gt;The severity of an incident is govern by the severity of alerts in it. Incident will have the same severity as of the highest severity alert in it.&lt;/P&gt;
&lt;P&gt;For the alert side, severity depends on the type of alert it is. BIOC/IOC alerts will have the severity that was configured in them when those rules were created. For alerts from 3rd party integration, the severity will be same as was forwarded by the integrated product.&lt;/P&gt;
&lt;P&gt;You can refer to below document to see the severity of analytics alerts&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR-Analytics-Alert-Reference" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR-Analytics-Alert-Reference&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately there is no consolidated document to show how the severity works for all kind of alerts.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 16:04:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/high-medium-low-severity/m-p/556792#M5094</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2023-09-06T16:04:53Z</dc:date>
    </item>
  </channel>
</rss>

