<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alerts and incidents in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alerts-and-incidents/m-p/600160#M7310</link>
    <description>&lt;P&gt;Hello Palo Live Community.&lt;BR /&gt;Does anyone know what are the criteria that Cortex XDR takes into account to create an incident for a single alert? This is because I have seen that some alerts do not necessarily form an incident, but in other cases, yes. I insist, talking only about a single alert.&lt;BR /&gt;I attach evidence.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Oct 2024 22:47:17 GMT</pubDate>
    <dc:creator>R.Tuyub</dc:creator>
    <dc:date>2024-10-10T22:47:17Z</dc:date>
    <item>
      <title>Alerts and incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alerts-and-incidents/m-p/600160#M7310</link>
      <description>&lt;P&gt;Hello Palo Live Community.&lt;BR /&gt;Does anyone know what are the criteria that Cortex XDR takes into account to create an incident for a single alert? This is because I have seen that some alerts do not necessarily form an incident, but in other cases, yes. I insist, talking only about a single alert.&lt;BR /&gt;I attach evidence.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2024 22:47:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alerts-and-incidents/m-p/600160#M7310</guid>
      <dc:creator>R.Tuyub</dc:creator>
      <dc:date>2024-10-10T22:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts and incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alerts-and-incidents/m-p/600266#M7320</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1012377633"&gt;@R.Tuyub&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;Most of the time alerts with severity as medium or above generate incidents with exception for few low severity analytics based alerts. Informational and low severity alerts do not generate incidents.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please c&lt;SPAN&gt;lick&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;to acknowledge that the answer to your question has been provided.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2024 15:29:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alerts-and-incidents/m-p/600266#M7320</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2024-10-11T15:29:00Z</dc:date>
    </item>
  </channel>
</rss>

