Low Incident

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Low Incident

L0 Member
We have integrated Cortex XDR with Elastic SIEM. Our SOC process currently creates a ticket for every Cortex XDR incident/case, including Low, Medium, and High severity incidents. Is Palo Alto's recommended best practice to create tickets for all Low severity incidents, or should Low severity alerts/incidents be monitored and correlated before ticket creation? Are there any official recommendations or reference architectures for severity-based incident handling and alert triage?
1 REPLY 1

L6 Presenter

Hello @R.Abdeen ,

 

Greetings for the day.

Low-Severity Best Practices:

Ticketing every Low alert can create alert fatigue. It is better to rely on Cortex XDR incident stitching so related alerts are grouped into one incident.

Low-severity incidents can be ticketed when they meet specific conditions, such as:

  • Involving a critical asset.
  • Multiple Low alerts occurring on the same host within a short period.
  • Involving a high-risk user account.

-For SIEM integration, it is generally better to forward incidents rather than individual alerts and apply severity-based forwarding rules.

-For MDR, High/Critical findings are typically prioritized for customer notification, while Low/Medium findings can be reviewed later.

 

Recommended Severity-Based Handling:

  • Critical / High: Immediate ticketing and SOC action. These usually indicate confirmed or high-confidence threats.
  • Medium: Ticket after automated enrichment and additional context.
  • Low / Info: Mainly use for correlation and monitoring rather than creating individual tickets.

If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".

 

Thanks & Regards,
S. Subashkar Sekar

  • 47 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!