<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Incident creation latency in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incident-creation-latency/m-p/573586#M5910</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/256101"&gt;@nsinghvirk&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Alert was generated by XDR Analytics and severity was low. After approximately 24 hours ( may be a few hours more or less, I dont remember exact timing) incident was created which contains only this alert.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Since our SOC team monitors based on incidents , these kind of latency is problem for us.&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jan 2024 04:58:53 GMT</pubDate>
    <dc:creator>orkhan_alibayli</dc:creator>
    <dc:date>2024-01-19T04:58:53Z</dc:date>
    <item>
      <title>Incident creation latency</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incident-creation-latency/m-p/573115#M5885</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I have seen a few cases like that in recent days:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There was an alert by name ""Failed Connections" generated by XDR Anaytics" and inside that incident there was only one alert named "Failed connections" and alert source was XDR Analytics. But problem is that, Incident created almost 24 hour&amp;nbsp;after the alert was created.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you experienced these type of situation before?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 05:30:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incident-creation-latency/m-p/573115#M5885</guid>
      <dc:creator>orkhan_alibayli</dc:creator>
      <dc:date>2024-01-16T05:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: Incident creation latency</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incident-creation-latency/m-p/573477#M5904</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/323182"&gt;@orkhan_alibayli&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;In this case we need to check the severity of the alert. Because Analytic BIOC alerts with medium or above severity generate the incidents and however alerts with low severity not necessarily generate incidents.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please tell us about the severity of alert and is the 24 hour period was between actual event and incident creation or between alert generation and incident generation?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 14:59:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incident-creation-latency/m-p/573477#M5904</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2024-01-18T14:59:45Z</dc:date>
    </item>
    <item>
      <title>Re: Incident creation latency</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incident-creation-latency/m-p/573586#M5910</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/256101"&gt;@nsinghvirk&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Alert was generated by XDR Analytics and severity was low. After approximately 24 hours ( may be a few hours more or less, I dont remember exact timing) incident was created which contains only this alert.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Since our SOC team monitors based on incidents , these kind of latency is problem for us.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 04:58:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/incident-creation-latency/m-p/573586#M5910</guid>
      <dc:creator>orkhan_alibayli</dc:creator>
      <dc:date>2024-01-19T04:58:53Z</dc:date>
    </item>
  </channel>
</rss>

