@sscalia wrote:
Any chance you found a resolution on this? My tenant is having the same issue now. All I'm coming across are AI Slop answers and nothing substantial. IM Dashboard hasn't reported an incident in over a month and I'm an Account Admin level user.
Alas - no, except strongly suspecting:
- a backend issue, i.e. nothing on our side
- Palo Alto support not admitting it and instead instructing their support people to blame everything on the tenant
Reason why I am suspecting that:
- No response from PAN Support to my several requests on the mechanism to detect this issue. E.g. how to scan local XDR logs for events indicating an alert should have been fired, so we could cross-reference that with what's in the console. I'd literally ask them, "what about that mechanism I asked about before?" and they would just ignore it like I didn't ask anything.
- Non-sensical, strange responses about alert exclusions - and that - after the ticket was escalated to someone who didn't use AI slop. E.g. they said excluded alerts don't show up in the console after the first one that was excluded - yet fully ignore the absence of that first alert in the "excluded alerts" table.
- No response to my repeated questions about the overall picture - that we had a lot of users report XDR pop-ups about malware blocked yet no alerts at all for over a month. They keep insisting on providing them with full support files for specific endpoints and after those were provided, they'd respond with how this is normal and expected. Just surreal. 😂
I have recommended to switch XDR providers to my management. Almost anything is better than this.