XDR Analytics BIOC Alert exclusion

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

XDR Analytics BIOC Alert exclusion

L4 Transporter

Hello dear community members!

 

how would you exclude this? It is only popping up in one of our houses/domains. 

Maybe this way?

https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-analytics-specific-exceptions-and-v...

 

RFeyertag_0-1662674033598.png

 

BR

 

Rob

 

 

1 REPLY 1

L3 Networker

Hi @RFeyertag ,

Yes, you could take a similar approach as the link in your post to create an exclusion for these alerts. 

 

If you wanted to only exclude these types of alerts for specific processes or domains, you could do the following:

 

  1. Navigate to Detection Rules>BIOC>Analytics BIOC Rules
  2. Edit your layout so that “Global Rule ID” is one of the columns that is displayed in your view
  3. Copy the Rule ID for the BIOC rule you wish to create an exclusion for, in this case - “Recurring rare domain access from an unsigned process”
  4. Navigate to Incident Response>Incident Configuration>Alert Exclusions and click “Add Alert Exclusions”
  5. In your filter, select the “Rule ID” field, select the “=“ operator, and paste the Rule ID value you copied in step 3 as the value. Click “+AND” to add another expression to your filter and choose either the “Initiated By” field (to exclude by process name) or the “Remote Host” field (to exclude by destination domain), select the “=“ operator, and set the value equal to the name of the process or domain generating the alerts you would like to exclude.
  6. Enter a Policy Name/Comment and click "Create" to finish creating the Alert Exclusion.


Regards,

Tim

  • 1794 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!