How to handle alerts in unused regions?

How to handle alerts in unused regions?

0
Created On 09/26/18 20:30 PM - Last Modified 07/19/22 23:12 PM


Symptom


How to handle alerts in unused regions?



Resolution


AWS creates certain default resources in every region when the AWS account is first provisioned.  Since Evident Monitoring automatically scans and reports resources from every AWS region, you may see alerts even in regions that you don't actually need or use.

 

The best practice recommendation is to go through each alert and suppress them individually.  To do that, open the alert details page then click on Suppression Options -> Suppress this alert.  This will suppress the alert and keep it from being counted within ESP's dashboard.  You also have the option to suppress alerts for the entire region or signatures within that region.  However, this is not recommended since you will lose visibility in those regions.  If you suppress the entire region and someone accidentally creates resources or maliciously started to use those regions, Evident Monitoring can still detect, but the results will not show up in Evident Monitoring dashboard and by default, will not generate any integration notifications.



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm4rCAC&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail