Automation rules

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Automation rules

L1 Bithead

Hi all!


Still fairly new to Cortex XDR. Currently trying to make some sensible alert automation rules.
I have a specifik alert that puzzles me. I get some "FTH/SSH client reads office files" alerts. I have a legitimate use case for this, so I want to automatically resolve these alerts for a particular set of hosts.

But ... I am not able to create an automation rule from this alert. Furthermore, these alerts do not even show up, if I try to create an Automation Rule from scratch.

Only difference I can see from all other alerts, is that the alertname has an forward slash "/" in the alert name.

Allan_Holdt_0-1700558668197.png

 

1 accepted solution

Accepted Solutions

L4 Transporter

Hello @aholdt 

 

Thanks for reaching out on LiveCommunity!

Automation rules only apply to alerts that are grouped into incidents by the system. Most alerts with low and informational severity do not allow an automation rule to be automatically executed on them. Looks like your alert has low severity and it do not qualify for automation rules.

As an alternate, You can create an exclusion rule by choosing multiple unique parameters for this specific use case.

https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Alert-Exclu...

Below is the reference guide for automation rules.

https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Automation-...

 

Please mark the response as "Accept as Solution" if it answers your query.

 

Regards.

View solution in original post

2 REPLIES 2

L4 Transporter

Hello @aholdt 

 

Thanks for reaching out on LiveCommunity!

Automation rules only apply to alerts that are grouped into incidents by the system. Most alerts with low and informational severity do not allow an automation rule to be automatically executed on them. Looks like your alert has low severity and it do not qualify for automation rules.

As an alternate, You can create an exclusion rule by choosing multiple unique parameters for this specific use case.

https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Alert-Exclu...

Below is the reference guide for automation rules.

https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Automation-...

 

Please mark the response as "Accept as Solution" if it answers your query.

 

Regards.

Thank you for your response.

I will read up on the documentation and look into exclusion rules.

Regards

  • 1 accepted solution
  • 553 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!