- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-06-2026 06:50 AM
Hello @permafrost ,
Greetings for the day.
Based on the symptoms you described—where Cortex XDR is successfully blocking threats on endpoints but is not generating incidents in the management console, while manual scans continue to generate incidents—the most likely causes are an Alert Exclusion configuration or changes to the incident creation or alert severity settings.
Since you mentioned that you are not the primary XDR administrator, the following checks can help identify the cause.
An Alert Exclusion allows the agent to continue blocking threats while preventing the corresponding alert from being reported to the management console. This aligns with your observation that threats are blocked but no incidents are created.
To verify:
Cortex XDR differentiates between Alerts (individual detections) and Incidents (groups of related alerts). Depending on your incident creation settings, lower-severity alerts may not be promoted to incidents.
To verify:
Management Audit Logs can help determine whether any policy or configuration changes were made around the time the issue started.
To verify:
Incident creation rules determine which alerts are promoted into incidents.
To verify:
If all of the above settings appear to be configured correctly and the issue persists, we recommend collecting the relevant logs and opening a support case for further investigation.
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".
Thanks & Regards,
S. Subashkar Sekar