- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-21-2023 01:29 AM - edited 11-21-2023 01:30 AM
Hi all!
Still fairly new to Cortex XDR. Currently trying to make some sensible alert automation rules.
I have a specifik alert that puzzles me. I get some "FTH/SSH client reads office files" alerts. I have a legitimate use case for this, so I want to automatically resolve these alerts for a particular set of hosts.
But ... I am not able to create an automation rule from this alert. Furthermore, these alerts do not even show up, if I try to create an Automation Rule from scratch.
Only difference I can see from all other alerts, is that the alertname has an forward slash "/" in the alert name.