Prisma Cloud No Alerts are Generated

Prisma Cloud No Alerts are Generated

8978
Created On 12/31/18 15:42 PM - Last Modified 03/14/22 20:07 PM


Symptom


No alerts can be found in Prisma Cloud platform.

Environment


Prisma Cloud

Cause


There are a number of reasons why alerts do not appear in Prisma Cloud:
  1. There are no Cloud Accounts defined
  2. Cloud Accounts do not belong to any Account Groups
  3. Alert Rules do not exist or are not defined properly
  4. Policies have been disabled
  5. Metadata Collector or Config Scanner did not run yet


Resolution


There are no Cloud Accounts defined

  1. Login to Prisma Cloud
  2. Go to Settings (top-right, gear symbol) > Cloud Accounts
  3. Check if any Cloud Accounts are defined. If not, then create New Cloud Accounts and assign it to at least one Account Group (recommended: Default Account Group)
  4. Wait for Prisma Cloud to scan and generate alerts

Cloud Accounts do not belong to any Account Groups

  1. Login to Prisma Cloud
  2. Go to Settings (top-right, gear symbol) > Account Groups
  3. Check if Cloud Accounts have been assigned to any Account Groups. If not, then edit or create an Account Group to include your Cloud Accounts
  4. Wait for Prisma Cloud to scan and generate alerts

Alert Rules do not exist or are not defined properly

  1. Login to Prisma Cloud
  2. Go to Alerts > Alert Rules
  3. Ensure that at least one Alert Rule exists.  If not, then create a new one.
  4. Check the Alert Rules to make sure that:
    1. Desired Account Group(s) are selected
    2. Advanced settings are not configured to exclude your account
    3. Advanced settings are not configured to disable relevant regions
    4. Desired policies are selected
  5. Wait for Prisma Cloud to scan and generate alerts

Policies have been disabled

  1. Login to Prisma Cloud
  2. Go to Policies
  3. Ensure that the policies are enabled.  If not, enable them
  4. Wait for Prisma Cloud to scan and generate alerts

Metadata Collector or Config Scanner did not run yet

Prisma Cloud needs to run Metadata Collector to scan resources, then Config Scanner to generate the alerts. The entire process can take up to two hours to run (depending on load). If all configuration has been verified and no alerts generate after two hours, please contact Palo Alto Networks support.

Tip: Run RQL statements in Investigate page or check Dashboard -> Asset Inventory page to determine if resources have been ingested or not. This can help with isolating the root cause.



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmVWCA0&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language