<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I ingested the Checkpoint firewall logs into Cortex XDR, now what should I do? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-ingested-the-checkpoint-firewall-logs-into-cortex-xdr-now-what/m-p/597926#M7184</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some time ago I connected the CheckPoint Firewalls with Cortex XDR and I can now see the alerts from the Cortex console.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My question is, what should I do now with the alerts? Since the FW is generating more than 100 incidents a day.&lt;BR /&gt;I had created an exclusion rule for the incidents that are registered as blocked, but this made me lose visibility since the alerts were no longer generated. Therefore I had to remove the exclusion.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What do I do with so many incidents generated? How can I manage them better?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Sep 2024 19:46:04 GMT</pubDate>
    <dc:creator>Rolando_Pena</dc:creator>
    <dc:date>2024-09-16T19:46:04Z</dc:date>
    <item>
      <title>I ingested the Checkpoint firewall logs into Cortex XDR, now what should I do?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-ingested-the-checkpoint-firewall-logs-into-cortex-xdr-now-what/m-p/597926#M7184</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some time ago I connected the CheckPoint Firewalls with Cortex XDR and I can now see the alerts from the Cortex console.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My question is, what should I do now with the alerts? Since the FW is generating more than 100 incidents a day.&lt;BR /&gt;I had created an exclusion rule for the incidents that are registered as blocked, but this made me lose visibility since the alerts were no longer generated. Therefore I had to remove the exclusion.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What do I do with so many incidents generated? How can I manage them better?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2024 19:46:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-ingested-the-checkpoint-firewall-logs-into-cortex-xdr-now-what/m-p/597926#M7184</guid>
      <dc:creator>Rolando_Pena</dc:creator>
      <dc:date>2024-09-16T19:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: I ingested the Checkpoint firewall logs into Cortex XDR, now what should I do?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-ingested-the-checkpoint-firewall-logs-into-cortex-xdr-now-what/m-p/598006#M7194</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/323299"&gt;@Rolando_Pena&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;Please identify the alert source and module which is generating alerts by filtering on these fields in alerts table. If these alerts are generated by analytics then investigate the alerts and resolve the incidents according to findings. Marking an incident as true positive or false positive helps analytics engine to improve its detections.&lt;/P&gt;
&lt;P&gt;If alerts are detecting legitimate behaviour then try to create exception/exclusion based on artefacts for the particular XDR module which is generating alerts.&lt;/P&gt;
&lt;P&gt;If alerts are generated by Checkpoint firewall directly then you need to do tuning on Checkpoint side as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please refer to below link on our Alert tuning webinars.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-webinars/cortex-xdr-customer-success-webinar-series-part-1-alert-tuning/ta-p/584842" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-webinars/cortex-xdr-customer-success-webinar-series-part-1-alert-tuning/ta-p/584842&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please c&lt;SPAN&gt;lick&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;to acknowledge that the answer to your question has been provided.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 14:42:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-ingested-the-checkpoint-firewall-logs-into-cortex-xdr-now-what/m-p/598006#M7194</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2024-09-17T14:42:58Z</dc:date>
    </item>
  </channel>
</rss>

