cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who Me Too'd this topic

Automation rules

L1 Bithead

Hi all!


Still fairly new to Cortex XDR. Currently trying to make some sensible alert automation rules.
I have a specifik alert that puzzles me. I get some "FTH/SSH client reads office files" alerts. I have a legitimate use case for this, so I want to automatically resolve these alerts for a particular set of hosts.

But ... I am not able to create an automation rule from this alert. Furthermore, these alerts do not even show up, if I try to create an Automation Rule from scratch.

Only difference I can see from all other alerts, is that the alertname has an forward slash "/" in the alert name.

Allan_Holdt_0-1700558668197.png

 

Who Me Too'd this topic