<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How Cortex XDR alert/incident severity is decided or generated on tool in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-cortex-xdr-alert-incident-severity-is-decided-or-generated/m-p/585286#M6613</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/326396"&gt;@tejaspatil12&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks for reaching out on LiveCommunity!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Unfortunately, this information cannot be shared as it is an IP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;However, to understand what parameters are defined to look upon alerts and incidents to perform a stitching or what we call a “story” to create alerts and incidents, customer can go through this&amp;nbsp;&lt;A class="c-link" href="https://players.brightcove.net/6266360586001/default_default/index.html?videoId=6320504460112" target="_blank" rel="noopener noreferrer" data-stringify-link="https://players.brightcove.net/6266360586001/default_default/index.html?videoId=6320504460112" data-sk="tooltip_parent"&gt;video&lt;/A&gt;. The first 10 minutes are enough to understand the concept.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Apr 2024 06:13:35 GMT</pubDate>
    <dc:creator>aspatil</dc:creator>
    <dc:date>2024-04-30T06:13:35Z</dc:date>
    <item>
      <title>How Cortex XDR alert/incident severity is decided or generated on tool</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-cortex-xdr-alert-incident-severity-is-decided-or-generated/m-p/585171#M6610</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help me to understand how Cortex XDR assign the severity to incident and alert.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 07:30:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-cortex-xdr-alert-incident-severity-is-decided-or-generated/m-p/585171#M6610</guid>
      <dc:creator>tejaspatil12</dc:creator>
      <dc:date>2024-04-29T07:30:50Z</dc:date>
    </item>
    <item>
      <title>Re: How Cortex XDR alert/incident severity is decided or generated on tool</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-cortex-xdr-alert-incident-severity-is-decided-or-generated/m-p/585286#M6613</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/326396"&gt;@tejaspatil12&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks for reaching out on LiveCommunity!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Unfortunately, this information cannot be shared as it is an IP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;However, to understand what parameters are defined to look upon alerts and incidents to perform a stitching or what we call a “story” to create alerts and incidents, customer can go through this&amp;nbsp;&lt;A class="c-link" href="https://players.brightcove.net/6266360586001/default_default/index.html?videoId=6320504460112" target="_blank" rel="noopener noreferrer" data-stringify-link="https://players.brightcove.net/6266360586001/default_default/index.html?videoId=6320504460112" data-sk="tooltip_parent"&gt;video&lt;/A&gt;. The first 10 minutes are enough to understand the concept.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 06:13:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-cortex-xdr-alert-incident-severity-is-decided-or-generated/m-p/585286#M6613</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-04-30T06:13:35Z</dc:date>
    </item>
    <item>
      <title>Re: How Cortex XDR alert/incident severity is decided or generated on tool</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-cortex-xdr-alert-incident-severity-is-decided-or-generated/m-p/585287#M6614</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/308232"&gt;@aspatil&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for response on this topic.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i can understand about the IP however do we have any official document by palo alto which shows Cortex XDR system itself understood its severity and assign to the incident/alert.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 06:21:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-cortex-xdr-alert-incident-severity-is-decided-or-generated/m-p/585287#M6614</guid>
      <dc:creator>tejaspatil12</dc:creator>
      <dc:date>2024-04-30T06:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: How Cortex XDR alert/incident severity is decided or generated on tool</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-cortex-xdr-alert-incident-severity-is-decided-or-generated/m-p/585338#M6619</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/326396"&gt;@tejaspatil12&lt;/a&gt;, as mentioned before by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/308232"&gt;@aspatil&lt;/a&gt;&amp;nbsp;, the details about how the &lt;STRONG&gt;alerts&lt;/STRONG&gt;&amp;nbsp;are classified can't be shared, but is a mechanism that uses the information from the type of malware, Mitre technichs used, criticity of the IOCs found, and some many other flags to set the severity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Abount &lt;STRONG&gt;Incidents&lt;/STRONG&gt;, is defined by the highest alert severity contained into the incident. Details here in the "severity" field:&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Incidents" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Incidents&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 13:28:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-cortex-xdr-alert-incident-severity-is-decided-or-generated/m-p/585338#M6619</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-04-30T13:28:49Z</dc:date>
    </item>
  </channel>
</rss>

