Increasing severity for certain critical hosts or visible tagging

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.

Increasing severity for certain critical hosts or visible tagging

L0 Member

Is there a way to make certain server hosts show as critical servers? We have a certain amount of servers we'd like any incident related to them be automatically a critical or high alert when XDR creates an incident for them. I've created say a "Critical Server" asset group and put servers in there put how do I make any incident triggered automatically become a high or critical if the server is in question? Can we modify the incident severity that is automatically created or is there a way to have XDR see a certain tag and increase severity? Also is there a way to make it obvious a certain hosts is a critical host? Right now when looking at incidents when you see assets you just see the host name but not sure if there is a way to have a tag show up like "Critical" or something besides making the incident a high/critical severity. 

2 REPLIES 2

L5 Sessionator

Hi @C.Perez, thanks for reaching us using the Live Community.

 

You can use Incident Scoring Rules to increase the incident severity when the affected endpoint has this tag applied. See the screenshot below as an example:

 

jmazzeo_1-1735837775004.png

 

 

If this post answers your question, please mark it as the solution.

JM

L3 Networker

Hi @C.Perez 

Adding to what @jmazzeo suggested, there is also another method to achieve this, you can make use of Automation rule that saying when you see an Incident coming from host with specific tags "Critical" to set the severity to High/Critical.

nar_0-1735839980642.png


Refer - https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Automation-rules

Mark it a solution if this worked for you!

Best,

 

  • 102 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!