<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR – Automatically Resolve Alerts/Issues as &amp;quot;Known Issue&amp;quot; Using Playbook or Predefined Command in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-automatically-resolve-alerts-issues-as-quot-known/m-p/1262837#M9520</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/262549"&gt;@RajeshPremSingh&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;DIV class="" data-is-intersecting="true" data-turn-id-container="7ee0b630-8619-42aa-beb2-408d1505e2d5"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="" data-is-intersecting="true" data-turn-id-container="request-WEB:5c7efbbc-1a3f-4410-ac0f-0cbe233d2c27-3"&gt;
&lt;SECTION class="text-token-text-primary w-full focus:outline-none has-data-writing-block:pointer-events-none [&amp;amp;:has([data-writing-block])&amp;gt;*]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(--scroll-root-safe-area-inset-bottom,0px)+var(--thread-response-height))] scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" data-turn="assistant" data-testid="conversation-turn-8" data-turn-id-container="request-WEB:5c7efbbc-1a3f-4410-ac0f-0cbe233d2c27-3" data-turn-id="request-WEB:5c7efbbc-1a3f-4410-ac0f-0cbe233d2c27-3"&gt;
&lt;DIV class="text-base my-auto mx-auto pb-8 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)"&gt;
&lt;DIV class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn" data-conversation-screenshot-content=""&gt;
&lt;DIV class="flex max-w-full flex-col gap-4 grow"&gt;
&lt;DIV class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal outline-none keyboard-focused:focus-ring [.text-message+&amp;amp;]:mt-1" dir="auto" tabindex="0" data-turn-start-message="true" data-message-model-slug="gpt-5-6" data-message-id="1530371d-986e-4000-b79b-9933c9228b6f" data-message-author-role="assistant"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden"&gt;
&lt;DIV class="markdown prose dark:prose-invert wrap-break-word w-full dark markdown-new-styling"&gt;
&lt;P data-end="73" data-start="0"&gt;Cortex XDR can automatically handle known/benign alerts in&lt;STRONG&gt; two main ways&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL data-end="724" data-start="75"&gt;
&lt;LI data-end="297" data-start="75" data-section-id="lp2sce"&gt;&lt;STRONG data-end="98" data-start="77"&gt;Automation Rules:&lt;/STRONG&gt; Match alerts based on conditions like severity, host, detection method, etc., and automatically set them to &lt;STRONG data-end="219" data-start="207"&gt;Resolved&lt;/STRONG&gt; with a reason such as &lt;EM data-is-only-node="" data-end="255" data-start="242"&gt;Known Issue&lt;/EM&gt;, &lt;EM data-end="273" data-start="257"&gt;False Positive&lt;/EM&gt;, or &lt;EM data-end="296" data-start="278"&gt;Security Testing&lt;/EM&gt;.&lt;/LI&gt;
&lt;LI data-end="419" data-start="298" data-section-id="p4uk99"&gt;&lt;STRONG data-end="314" data-start="300"&gt;Playbooks:&lt;/STRONG&gt; For more complex workflows, a playbook can update the alert status and add comments before resolving it.&lt;BR /&gt;&lt;BR /&gt;--------------------------------------------------------------------&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI data-end="579" data-start="420" data-section-id="11si4vd"&gt;&lt;STRONG data-end="443" data-start="422"&gt;Alert Exclusions:&lt;/STRONG&gt; For repetitive, confirmed-benign alerts, exclusions are usually better. They prevent future alerts from creating unnecessary incidents.&lt;/LI&gt;
&lt;LI data-end="724" data-start="580" data-section-id="1jy83yl"&gt;&lt;STRONG data-end="602" data-start="582"&gt;Incident status:&lt;/STRONG&gt; When all alerts in an incident are resolved or excluded, the parent incident is automatically moved to &lt;STRONG data-end="723" data-start="706"&gt;Auto-Resolved&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-is-only-node="" data-is-last-node="" data-end="867" data-start="726"&gt;If an automation rule is not working, check the &lt;STRONG data-end="866" data-start="774"&gt;conditions, rule status, permissions, and whether the action is actually being triggered&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
    <pubDate>Wed, 26 Aug 2026 01:44:41 GMT</pubDate>
    <dc:creator>susekar</dc:creator>
    <dc:date>2026-08-26T01:44:41Z</dc:date>
    <item>
      <title>Cortex XDR – Automatically Resolve Alerts/Issues as "Known Issue" Using Playbook or Predefined Command</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-automatically-resolve-alerts-issues-as-quot-known/m-p/1262709#M9518</link>
      <description>&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Hello Team,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;We are using a &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Cortex XDR tenant&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; and would like to know whether there is a supported way to automatically update an alert/issue resolution to &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;"Known Issue"&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; using a predefined command, automation, or playbook action.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Our goal is to avoid manual analyst intervention for alerts that have already been validated as known benign activity and automatically mark them as &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Resolved - Known Issue&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2026 01:08:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-automatically-resolve-alerts-issues-as-quot-known/m-p/1262709#M9518</guid>
      <dc:creator>RajeshPremSingh</dc:creator>
      <dc:date>2026-08-25T01:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR – Automatically Resolve Alerts/Issues as "Known Issue" Using Playbook or Predefined Command</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-automatically-resolve-alerts-issues-as-quot-known/m-p/1262837#M9520</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/262549"&gt;@RajeshPremSingh&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;DIV class="" data-is-intersecting="true" data-turn-id-container="7ee0b630-8619-42aa-beb2-408d1505e2d5"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="" data-is-intersecting="true" data-turn-id-container="request-WEB:5c7efbbc-1a3f-4410-ac0f-0cbe233d2c27-3"&gt;
&lt;SECTION class="text-token-text-primary w-full focus:outline-none has-data-writing-block:pointer-events-none [&amp;amp;:has([data-writing-block])&amp;gt;*]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(--scroll-root-safe-area-inset-bottom,0px)+var(--thread-response-height))] scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" data-turn="assistant" data-testid="conversation-turn-8" data-turn-id-container="request-WEB:5c7efbbc-1a3f-4410-ac0f-0cbe233d2c27-3" data-turn-id="request-WEB:5c7efbbc-1a3f-4410-ac0f-0cbe233d2c27-3"&gt;
&lt;DIV class="text-base my-auto mx-auto pb-8 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)"&gt;
&lt;DIV class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn" data-conversation-screenshot-content=""&gt;
&lt;DIV class="flex max-w-full flex-col gap-4 grow"&gt;
&lt;DIV class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal outline-none keyboard-focused:focus-ring [.text-message+&amp;amp;]:mt-1" dir="auto" tabindex="0" data-turn-start-message="true" data-message-model-slug="gpt-5-6" data-message-id="1530371d-986e-4000-b79b-9933c9228b6f" data-message-author-role="assistant"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden"&gt;
&lt;DIV class="markdown prose dark:prose-invert wrap-break-word w-full dark markdown-new-styling"&gt;
&lt;P data-end="73" data-start="0"&gt;Cortex XDR can automatically handle known/benign alerts in&lt;STRONG&gt; two main ways&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL data-end="724" data-start="75"&gt;
&lt;LI data-end="297" data-start="75" data-section-id="lp2sce"&gt;&lt;STRONG data-end="98" data-start="77"&gt;Automation Rules:&lt;/STRONG&gt; Match alerts based on conditions like severity, host, detection method, etc., and automatically set them to &lt;STRONG data-end="219" data-start="207"&gt;Resolved&lt;/STRONG&gt; with a reason such as &lt;EM data-is-only-node="" data-end="255" data-start="242"&gt;Known Issue&lt;/EM&gt;, &lt;EM data-end="273" data-start="257"&gt;False Positive&lt;/EM&gt;, or &lt;EM data-end="296" data-start="278"&gt;Security Testing&lt;/EM&gt;.&lt;/LI&gt;
&lt;LI data-end="419" data-start="298" data-section-id="p4uk99"&gt;&lt;STRONG data-end="314" data-start="300"&gt;Playbooks:&lt;/STRONG&gt; For more complex workflows, a playbook can update the alert status and add comments before resolving it.&lt;BR /&gt;&lt;BR /&gt;--------------------------------------------------------------------&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI data-end="579" data-start="420" data-section-id="11si4vd"&gt;&lt;STRONG data-end="443" data-start="422"&gt;Alert Exclusions:&lt;/STRONG&gt; For repetitive, confirmed-benign alerts, exclusions are usually better. They prevent future alerts from creating unnecessary incidents.&lt;/LI&gt;
&lt;LI data-end="724" data-start="580" data-section-id="1jy83yl"&gt;&lt;STRONG data-end="602" data-start="582"&gt;Incident status:&lt;/STRONG&gt; When all alerts in an incident are resolved or excluded, the parent incident is automatically moved to &lt;STRONG data-end="723" data-start="706"&gt;Auto-Resolved&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-is-only-node="" data-is-last-node="" data-end="867" data-start="726"&gt;If an automation rule is not working, check the &lt;STRONG data-end="866" data-start="774"&gt;conditions, rule status, permissions, and whether the action is actually being triggered&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2026 01:44:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-automatically-resolve-alerts-issues-as-quot-known/m-p/1262837#M9520</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-08-26T01:44:41Z</dc:date>
    </item>
  </channel>
</rss>

