<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Where can I browse the Prisma Cloud Compute Alerts? Why are Alerts generated by CVEs failing Alert provider AWSSecurityHub? in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/where-can-i-browse-the-prisma-cloud-compute-alerts-why-are/m-p/515854#M711</link>
    <description>&lt;P&gt;Hi TommyHunt,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope you are doing well. Following are the answers to your questions:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Where can I browse, search Prisma Cloud Compute Alerts within Prisma Cloud Console? wanting to confirm alerts are properly formatted, populated.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Ans: Currently, there is no place in the Prisma Cloud Compute console where you can browse for the alerts that are being generated. You can set up an alert by using the following doc but you can browse the generated alerts:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/alerts" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/alerts&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You can create a feature request for it by using the following link:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://prismacloud.ideas.aha.io/ideas" target="_blank"&gt;https://prismacloud.ideas.aha.io/ideas&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;What the heck is wrong with the integration to Alert provider, AWSSecurityHub?&amp;nbsp; remember that Test Alerts and runtime Alerts are sent successfully.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Ans: There must be some permissions that are missing in the AWS which is why you are getting this error while setting up the alert. Can you please go through the console logs and look for the error message? It should look something like this:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;ERRO 2020-05-18T21:04:37.751 serverless_radar_scanner.go:125 AWS Twistlock Security Hub&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Fri, 23 Sep 2022 20:53:26 GMT</pubDate>
    <dc:creator>musiddiqui</dc:creator>
    <dc:date>2022-09-23T20:53:26Z</dc:date>
    <item>
      <title>Where can I browse the Prisma Cloud Compute Alerts? Why are Alerts generated by CVEs failing Alert provider AWSSecurityHub?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/where-can-i-browse-the-prisma-cloud-compute-alerts-why-are/m-p/515847#M710</link>
      <description>&lt;P&gt;I have configured Prisma CloudCompute Console/Manage/Alerts/Manage/Alert providers/AWSSecurityHub.&lt;/P&gt;
&lt;P&gt;When I &amp;lt;Send Test Alert&amp;gt;, the console reports success and the status of that integration is green, "Connected".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have also configured Registry scans and pushed images with CVEs.&lt;/P&gt;
&lt;P&gt;Overnight the registries were scanned and I can see the images/repos with their CVEs in the Monitor/Vulnerabitlity Explorer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, I cannot find the Alerts that should have been generated by Prisma CloudCompute Console/Defend/Vulnerabilities/Images/CI/Rules.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It&amp;nbsp;appears that the CVEs did trigger Alert creation because now the Alert provider, AWSSecurityHub, is reporting this error...&lt;/P&gt;
&lt;P&gt;failed to add findings: [{ ErrorCode: "InvalidInput", ErrorMessage: "Finding does not adhere to Amazon Finding Format. data.Resources[0].Id should NOT be shorter than 1 characters, data.Resources[0].Id should NOT be shorter than 12 characters, data.Resources[0].Id should match pattern \"^arn:(aws|aws-cn|aws-us-gov):[A-Za-z0-9\\-]{1,63}:[a-z0-9\\-]*:([0-9]{12})?:.+$\", data.Resources[0].Id should match some schema in anyOf.", Id: "us-west-2/twistlock/vulnerabilities/" }]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Two Questions:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Where can I browse, search Prisma Cloud Compute Alerts within Prisma Cloud Console? wanting to confirm alerts are properly formatted, populated.&lt;/LI&gt;
&lt;LI&gt;What the heck is wrong with the integration to Alert provider, AWSSecurityHub?&amp;nbsp; remember that Test Alerts and runtime Alerts are sent successfully.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 19 Oct 2022 17:08:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/where-can-i-browse-the-prisma-cloud-compute-alerts-why-are/m-p/515847#M710</guid>
      <dc:creator>TommyHunt</dc:creator>
      <dc:date>2022-10-19T17:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: Where can I browse the Prisma Cloud Compute Alerts? Why are Alerts generated by CVEs failing Alert provider AWSSecurityHub?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/where-can-i-browse-the-prisma-cloud-compute-alerts-why-are/m-p/515854#M711</link>
      <description>&lt;P&gt;Hi TommyHunt,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope you are doing well. Following are the answers to your questions:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Where can I browse, search Prisma Cloud Compute Alerts within Prisma Cloud Console? wanting to confirm alerts are properly formatted, populated.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Ans: Currently, there is no place in the Prisma Cloud Compute console where you can browse for the alerts that are being generated. You can set up an alert by using the following doc but you can browse the generated alerts:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/alerts" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/alerts&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You can create a feature request for it by using the following link:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://prismacloud.ideas.aha.io/ideas" target="_blank"&gt;https://prismacloud.ideas.aha.io/ideas&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;What the heck is wrong with the integration to Alert provider, AWSSecurityHub?&amp;nbsp; remember that Test Alerts and runtime Alerts are sent successfully.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Ans: There must be some permissions that are missing in the AWS which is why you are getting this error while setting up the alert. Can you please go through the console logs and look for the error message? It should look something like this:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;ERRO 2020-05-18T21:04:37.751 serverless_radar_scanner.go:125 AWS Twistlock Security Hub&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 20:53:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/where-can-i-browse-the-prisma-cloud-compute-alerts-why-are/m-p/515854#M711</guid>
      <dc:creator>musiddiqui</dc:creator>
      <dc:date>2022-09-23T20:53:26Z</dc:date>
    </item>
  </channel>
</rss>

