Cortex XDR Alerts

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cortex XDR Alerts

L2 Linker

Hi,

 

I can't seem to find what I'm looking for in the Cortex XDR console. I am trying to find a way to view all alerts generated whether it is from XDR or Analytics. The only way I can see this list is if I create an exclusion Investigation --> Exclusions --> Add Exclusion. Is there a more direct way to view these Alerts?

 

Thanks

1 ACCEPTED SOLUTION

Accepted Solutions

L4 Transporter

HI there-

 

Go to Investigation > Incidents - then click on Alerts Table over to the right of the screen.

 

dfalcon_2-1587486154305.png

 

 


David Falcon 
Senior Solutions Architect, Cortex
Palo Alto Networks® 

View solution in original post

8 REPLIES 8

L4 Transporter

HI there-

 

Go to Investigation > Incidents - then click on Alerts Table over to the right of the screen.

 

dfalcon_2-1587486154305.png

 

 


David Falcon 
Senior Solutions Architect, Cortex
Palo Alto Networks® 

Thank you @dfalcon

 

Feels like it is hidden away. They should be making this a submenu directly off of the Investigation menu.

 

 

I will share that feedback with the Product Team.


David Falcon 
Senior Solutions Architect, Cortex
Palo Alto Networks® 

I too was having the same problem... wanting to look at the Alerts and how those turn into Incidents. I think it would be great to have a dashboard widget that would present a bar graph that shows the volume of Low, Medium, High and Critical alerts. Thanks.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!