cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who rated this post

L5 Sessionator

Hello @permafrost ,

 

Greetings for the day.

 

Based on the symptoms you described—where Cortex XDR is successfully blocking threats on endpoints but is not generating incidents in the management console, while manual scans continue to generate incidents—the most likely causes are an Alert Exclusion configuration or changes to the incident creation or alert severity settings.

 

Since you mentioned that you are not the primary XDR administrator, the following checks can help identify the cause.

 

1. Check for Alert Exclusion Rules (Most Likely)

An Alert Exclusion allows the agent to continue blocking threats while preventing the corresponding alert from being reported to the management console. This aligns with your observation that threats are blocked but no incidents are created.

To verify:

  1. Log in to the Cortex XDR console.
  2. Navigate to Settings → Configurations → Alert Exclusions.
  3. Review any active exclusion rules, especially those created or modified around the time the issue began.
  4. Look for broad exclusions related to Malware or Prevented actions.
  5. If an overly broad exclusion is found, temporarily disable it and verify the behavior using a known safe malware test file.

2. Verify the Alerts Table

Cortex XDR differentiates between Alerts (individual detections) and Incidents (groups of related alerts). Depending on your incident creation settings, lower-severity alerts may not be promoted to incidents.

To verify:

  1. Navigate to Incident Response → Alerts.
  2. Review alerts generated during the affected time period.
  3. If detections appear in the Alerts table but not as incidents, review their severity and determine whether they meet the criteria for incident creation.

3. Review Management Audit Logs:

Management Audit Logs can help determine whether any policy or configuration changes were made around the time the issue started.

To verify:

  1. Navigate to Settings → Audit Logs → Management Audit.
  2. Filter the logs for the timeframe when the issue first occurred.
  3. Review any changes related to policies, configurations, or alert exclusions.

4. Review Incident Creation Rules:

Incident creation rules determine which alerts are promoted into incidents.

To verify:

  1. Navigate to Incident Response → Incident Configuration → Incident Creation Rules.
  2. Confirm that the rules responsible for Malware or Analytics detections are enabled.
  3. Verify that the incident creation criteria have not been restricted to only specific severity levels.

If all of the above settings appear to be configured correctly and the issue persists, we recommend collecting the relevant logs and opening a support case for further investigation.

 

 

If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".

 

Thanks & Regards,
S. Subashkar Sekar

Who rated this post