- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-25-2023 01:59 AM - edited 10-25-2023 03:04 AM
Hi @nithin.k ,
This is to be expected given the deduplication period, which is the amount of time Cortex XDR waits before raising another warning for the same activity or behavior in order to prevent an alert overload. As a result, the alert triggered displays the frequency of comparable activity or alert triggering.
I'm also sending this screenshot in case it helps. In this instance, the alert system highlights the relevant alerts from the previous hour rather than raising 85 alarms because those 85 warnings were for the same file, activity, or conduct.
Hope this helps!
Please mark the response as "Accept as Solution" if it answers your query.