<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Prisma Cloud alerts in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/prisma-cloud-alerts/m-p/568458#M1116</link>
    <description>&lt;P&gt;Hello everyone!&lt;/P&gt;
&lt;P&gt;I connected my AWS account to Prisma Cloud service and it automatically scanned it. Now I think that I could have new vulnerabilities on my account but new s3 buckets or EC2 instances don't appers automatically on my Prisma Cloud account. How I can rescan my account and receive new alerts?&lt;/P&gt;</description>
    <pubDate>Tue, 05 Dec 2023 16:32:39 GMT</pubDate>
    <dc:creator>OksanaBotprise</dc:creator>
    <dc:date>2023-12-05T16:32:39Z</dc:date>
    <item>
      <title>Prisma Cloud alerts</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/prisma-cloud-alerts/m-p/568458#M1116</link>
      <description>&lt;P&gt;Hello everyone!&lt;/P&gt;
&lt;P&gt;I connected my AWS account to Prisma Cloud service and it automatically scanned it. Now I think that I could have new vulnerabilities on my account but new s3 buckets or EC2 instances don't appers automatically on my Prisma Cloud account. How I can rescan my account and receive new alerts?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 16:32:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/prisma-cloud-alerts/m-p/568458#M1116</guid>
      <dc:creator>OksanaBotprise</dc:creator>
      <dc:date>2023-12-05T16:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Cloud alerts</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/prisma-cloud-alerts/m-p/569059#M1120</link>
      <description>&lt;P&gt;My first question is what makes you think you should have new alerts? Are you firing up new EC2 instances that you know have some vulnerability? And to verify, you do see some alerts from before, just not new ones?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Re-scanning happens automatically periodically (think it's somewhere around every 20 minutes or so). There is no way in the UI to force a re-scan. One way you can try however is to remove the cloud account from Prisma Cloud and onboard it again, which should initiate a scan immediately. Data will be retained for 24h, so it should not cause any existing alerts to be lost, as long as the account is onboarded again within that timeframe.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Other things to check is go to settings-&amp;gt;Providers-&amp;gt;cloud accounts (if you're already on the Darwin release) and verify that the account is still being ingested OK (green checkmark showing in the status column). If not, try to resolve that first.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And finally, for alerts to trigger, the cloud account you've onboarded has to be attached to a account group, and that account group has to have an alert rule attached to it. For the Darwin release, see&amp;nbsp;&lt;A href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/alerts/alert-notifications" target="_blank"&gt;https://docs.prismacloud.io/en/enterprise-edition/content-collections/alerts/alert-notifications&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have attached your cloud account to the default account group, then it should already be connected to the default alert rule. In that case I would verify that the "select all policies" toggle is active for the default alert rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2023 14:07:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/prisma-cloud-alerts/m-p/569059#M1120</guid>
      <dc:creator>JensWegar</dc:creator>
      <dc:date>2023-12-08T14:07:44Z</dc:date>
    </item>
  </channel>
</rss>

