<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR IOC Incidents Query in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-ioc-incidents-query/m-p/559433#M5209</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have detected several IOC incidents in the Cortex XDR console. The action status for these incidents is marked as 'detected,' but upon further investigation, we found that the internal network team had prevented these incidents in the Palo Alto firewall. Simultaneously, when we checked the Cortex XDR console's IOC incidents debug alerts, we noticed that 'action_network_success' was set to 'false.' This discrepancy raises doubts about whether 'action_network_success' being 'false' indicates prevention or detection."&lt;/P&gt;</description>
    <pubDate>Tue, 26 Sep 2023 05:40:53 GMT</pubDate>
    <dc:creator>Vinothkumar_SBA</dc:creator>
    <dc:date>2023-09-26T05:40:53Z</dc:date>
    <item>
      <title>Cortex XDR IOC Incidents Query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-ioc-incidents-query/m-p/559433#M5209</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have detected several IOC incidents in the Cortex XDR console. The action status for these incidents is marked as 'detected,' but upon further investigation, we found that the internal network team had prevented these incidents in the Palo Alto firewall. Simultaneously, when we checked the Cortex XDR console's IOC incidents debug alerts, we noticed that 'action_network_success' was set to 'false.' This discrepancy raises doubts about whether 'action_network_success' being 'false' indicates prevention or detection."&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 05:40:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-ioc-incidents-query/m-p/559433#M5209</guid>
      <dc:creator>Vinothkumar_SBA</dc:creator>
      <dc:date>2023-09-26T05:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR IOC Incidents Query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-ioc-incidents-query/m-p/559645#M5221</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/243138"&gt;@Vinothkumar_SBA&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;If I understood correctly there is an IOC in XDR whose alert was generated by Alert source as XDR IOC, but those IOC were prevented by PANW firewall do you mean this?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since IOC was reported as Detected by Cortex XDR agent therefore&amp;nbsp;&lt;SPAN&gt;action_network_success which corresponds to that alert has/had value false.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Could you share what&amp;nbsp;discrepancy you see with the Detected alert and action_network_success as false? Additionally&amp;nbsp;you may also can verify NGFW event by running XQL query for preset =&amp;nbsp;network_story dataset and then look for events related to that IOC Alert. Then you may check the "action_network_success" field value.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 11:33:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-ioc-incidents-query/m-p/559645#M5221</guid>
      <dc:creator>PiyushKohli</dc:creator>
      <dc:date>2023-09-27T11:33:01Z</dc:date>
    </item>
  </channel>
</rss>

