no incidents generated since May 20?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

no incidents generated since May 20?

L0 Member

Our Cortex XDR instance stopped generating incidents when detecting malware and other threats. (Somewhat similar to "Cortex XDR - Blocked Hashes on newer systems do not show in Incidents" - except in our case, this is across the board on all devices, for all threats and behaviors.)

(If we initiate a malware scan on the affected device, an incident is generated 🟢 for the same file that was previously blocked by Cortex with no incident. I.e. this tells us the incident creation system is not broken - rather, the usual mechanism of creating incident upon detection or blocking is not working for some reason.)

The first assumption is that something has changed on our side - i.e. we accidentally created a policy (or deleted or disabled an existing policy) - which killed the incident generation mechanism.

The 2nd - that something has changed on the back end w/o our involvement resulting in the above change of behavior.

This seems to have occurred sometime in May 2026.

  • The last auto-generated incident was on May 20 with no such incidents since.
  • Usually we get at least a few incidents a week - so this is unusual.
  • Several users reported blocking by Cortex XDR in late May and early June - but no incidents.
  • No known changes that could have resulted in this change of behavior on our side. (That said, can't rule out an accidental change.)
  • Initiating a malware scan on the machine on which malware was detected or blocked - resulted in incidents generated for the same files that were blocked.

In either case - where do we go to try to figure out what happened, when, and how to fix it? (Please be gentle and patient - Cortex XDR is just a small part of things on my plate, and I will likely not understand something like "go fix your BIOCs".)

Thank you!

0 REPLIES 0
  • 22 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!