Stale or Missing Alerts (AWS only)

Stale or Missing Alerts (AWS only)

6139
Created On 09/26/18 13:45 PM - Last Modified 06/08/23 21:27 PM


Symptom


Symptoms

Remediation and other changes made in AWS is not properly reflected in alerts.  Examples:

  1. Alert does not end after resource has been deleted
  2. Alert does not end after remediation steps have been performed
  3. Alert does not appear for newly created resources

Changes in AWS does not update alert metadata.

Diagnosis

  • If alert is missing, make sure alert is not suppressed.  Go to latest report -> Alerts tab, filter by "Suppressed only" to confirm whether the alert was suppressed or not.
  • If alert is missing, make sure signature is not disabled.  Go to Control Panel -> Disabled Signatures, then look for the account + signature pair of the missing alert.
  • If alert is stale or missing, disable offending signature, wait an hour, then re-enable signature


Resolution


If after performing the above diagnostics, you still suspect that alerts are stale or missing, contact Palo Alto Networks support, and provide the suspect alerts.

 

In some cases, a one-time manual scan can be performed to re-sync alerts.  Please provide the External Account name or ID for all accounts that need to be scanned.

 

Note: A permanent fix is in development.  Check Evident Monitoring Status Page for latest updates.



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClnSCAS&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language