cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Who rated this post

Hi @Balaraju both rule (alert) exceptions and alert exclusions exist in Cortex XDR.

When you exclude an alert, the alert will still be triggered by the agent and sent to XDR tenant. However, it will not be stitched into an incident. Here the action is performed by the XDR tenant. The alerts will appear in the Alerts table.

On the other hand, an alert exception will cause the alert not to be triggered by the agent. The action is performed by the agent.


Who rated this post