- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-16-2023 08:03 AM
Hello all,
I have identified that the Analytics and BIOC Analytics is identifying real threats yet no action has been initiated due to the log source. Is it possible to increase the severity of these rules to Medium and higher ?
Secondy, is it possible to set the policy to block when identifying these specific rules on the XDR Tenant?
From what I understand of these rules is that due to the fact that they are built-in rules that are provided by PAN they cannot be altered or their conditions cannot be viewed. What can I do in order to allow the agent to actively target these threats?
05-19-2023 07:50 AM - edited 05-19-2023 08:20 AM
Is it possible to increase the severity of these rules to Medium and higher? Yes, you can manually change the incident severity by clicking on the three dots on the top right corner and select change severity.
Note: You cant change the actual rule severity that initially triggered the alert.
Is it possible to set the policy to block when identifying these specific rules on the XDR Tenant? No since these are analytics rules, but what you can do is investigate this analytics/bioc analytics alerts and create your custom BIOC rule based on your investigation/criteria then you can assign that custom bioc rule as prevention rule which you need to apply to restriction profile.
From what I understand of these rules is that due to the fact that they are built-in rules that are provided by PAN they cannot be altered or their conditions cannot be viewed. Correct
What can I do in order to allow the agent to actively target these threats? What you can do is investigate this analytics/bioc analytics alerts and create your custom BIOC rule based on your investigation/criteria then you can assign that custom bioc rule as prevention rule which you need to apply to restriction profile.
Reference: Configure Custom Prevention Rule:
https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/custom-prevention-rules/ta-p/347271
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!