Decoupling an alert from an incident

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Decoupling an alert from an incident

L0 Member

I have seen a few instances where an alert is incorrectly linked to an incident - for example, an incident might have 50 alerts from one host and only 1 from a second host, where the alerts don't appear for a common activity.  The alerts are reasonably valid, just not really related to one another.

 

In cases like this, I'd like to split off the "other" alerts into a separate incident.  Is there a way to do this?

 

Cortex XDR 

1 accepted solution

Accepted Solutions

L5 Sessionator

Yes, right click the alert , Manage Alert -> Move Alert from Incident

bbarmanroy_0-1684118343223.png

 

 

You can then move it to a new incident or existing incident based on your preference:

bbarmanroy_1-1684118422210.png

 

View solution in original post

1 REPLY 1

L5 Sessionator

Yes, right click the alert , Manage Alert -> Move Alert from Incident

bbarmanroy_0-1684118343223.png

 

 

You can then move it to a new incident or existing incident based on your preference:

bbarmanroy_1-1684118422210.png

 

  • 1 accepted solution
  • 776 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!