Cortex XDR Incidents new field

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cortex XDR Incidents new field

L1 Bithead

Hi all,


This is my first post here.

I had this idea/suggestion that a new field should be added on incidents page.


When we deal with multiple incidents, a necessary field will be needed for quicker decision making for an analyst.

So I wanted to suggest for field called "status" wherein the action taken on the consisted alerts is summarized.

As the action taken on an alert is categorised in two main subjects- "detected" and "prevented", It will be better to get a summary of it instead of clicking on 1 incident looking inside only to notice prevented actions have taken place.


Please share your suggestions or ideas.




L4 Transporter

Hi @LokeshKumar-


I'm happy to raise a feature request.  How would you envision the status for an incident with multiple alerts with different actions?

David Falcon 
Senior Solutions Architect, Cortex
Palo Alto Networks® 

Hi David,


Thanks for the reply. PA support team did help me in raising a feature request.



Lokesh Kumar

Sounds good.  I will try to find it and up-vote it.

David Falcon 
Senior Solutions Architect, Cortex
Palo Alto Networks® 
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!