Low Severity events not showing in the new Cortex XDR 2.0 dashboard.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Low Severity events not showing in the new Cortex XDR 2.0 dashboard.

L1 Bithead

I used to be able to see the low severity events in the old traps dashboard but no longer see them anywhere in the new Cortex XDR 2.0 dashboard that we were upgraded to over the weekend (Great looking dashboard by the way).

 

Any ideas?

 

1 ACCEPTED SOLUTION

Accepted Solutions

There is a chance that a low severity alert will not create an actual incident.  A typical scenario where this applies is when you have a malware prevention with no additional action required.  You will still receive the alert because it happened, but there is no action required on your part.  Incidents, on the other hand, usually require some type of response / interaction.  Incidents are essentially one or more alerts that are related to an event -- grouped together.  You may still see some low-severity incidents that come across - these require attention, but have been prioritized lower than the mediums and highs. .  


David Falcon 
Senior Solutions Architect, Cortex
Palo Alto Networks® 

View solution in original post

11 REPLIES 11

L4 Transporter

Hi there.  If you are talking about low severity alerts, you can view them by clicking on Investigation > Incidents.  Once in the incidents screen - on the top right of the interface, you'll see a link for the Alerts Table.  You should see them there.  

 

dfalcon_0-1586442762492.png

 


David Falcon 
Senior Solutions Architect, Cortex
Palo Alto Networks® 

David,

 

Great, I see them there, thanks. But why are they not showing in the "Top Incidents (Top 10)" widget on the dashboard? It's only showing the High and Medium alerts even when there are less than 10 alerts I would expect it to show all of them.

 

The low alerts are also not showing in the "Open incidents by Severity" widget. It looks like all of the dashboard widgets are ignoring any Low level alerts.

I need a little more info here before answering.  When you list the incidents under Investigation > Incidents, are they showing up there as incidents (low severity incidents) or are they only showing up in the Alerts Table?


David Falcon 
Senior Solutions Architect, Cortex
Palo Alto Networks® 

They are only showing in the Alerts Table.

 

Even when I specifically choose to show them in the Incidents they don't show up unless I choose the alerts table.

 

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!