Cortex XDR Incidents new field

Reply
Highlighted
L1 Bithead

Cortex XDR Incidents new field

Hi all,

 

This is my first post here.

I had this idea/suggestion that a new field should be added on incidents page.

 

When we deal with multiple incidents, a necessary field will be needed for quicker decision making for an analyst.

So I wanted to suggest for field called "status" wherein the action taken on the consisted alerts is summarized.

As the action taken on an alert is categorised in two main subjects- "detected" and "prevented", It will be better to get a summary of it instead of clicking on 1 incident looking inside only to notice prevented actions have taken place.

 

Please share your suggestions or ideas.

 

 

Highlighted
L4 Transporter

Hi @LokeshKumar-

 

I'm happy to raise a feature request.  How would you envision the status for an incident with multiple alerts with different actions?


David Falcon 
MDR Systems Engineer, Cortex
Palo AltoNetworks® 
Highlighted
L1 Bithead

Hi David,

 

Thanks for the reply. PA support team did help me in raising a feature request.

 

Regards,

Lokesh Kumar

Tags (1)
Highlighted
L4 Transporter

Sounds good.  I will try to find it and up-vote it.


David Falcon 
MDR Systems Engineer, Cortex
Palo AltoNetworks® 
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!