- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-24-2026 07:52 AM
Hello,
Currently in our xdr tenant, many issues have been getting automatically closed by legacy automation rules, rules migrated from XDR v3.x to v5,x. The problem is that these rules have conditions such as, category=Malware and detection method = XDR Agent whichr esults in legitimate security incidents being closed without analyst review.
Is there any way to disable them or replace them by using using auomation rules and/or playbooks?
Thanks for your help
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

