Cortex XDR Alerts not appearing in the Admin Portal under Incidents >Alerts?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cortex XDR Alerts not appearing in the Admin Portal under Incidents >Alerts?

L0 Member

Hi all,

 

Recently we've been experiencing some alerts (which we believe to be false positives) but are unable to see these alerts in the admin portal. Is there any configuration required to generate Admin Portal alerts in the Alerts Table? Or should they all appear there by default?

 

We have profile configurations and I've seen the following option: -

LennonC_0-1711381516021.png

This is by default set to Full and Disabled. Would changing this option have any impact on our Alerts populating correctly or is this unrelated to the Alerts Table?

 

Thanks,

Lennon

2 REPLIES 2

L3 Networker

They should all appear unless someone excluded them.  You can check for excluded alerts in settings>Exceptions Configuration>alert exclusions.

  I did that by mistake early on and it took a while to figure it out.

Thanks, I've checked this and it appears we only have two exceptions, one wouldn't effect the users reporting the alerts popping up, the other might do though. The issue with the current alerts is that there's no application named, so it could be the 2nd exception we have listed.

  • 1054 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!