Default Policies Marked As "deleted by template@redlock.io" in Prisma Cloud

Default Policies Marked As "deleted by template@redlock.io" in Prisma Cloud

4433
Created On 02/22/22 11:34 AM - Last Modified 05/30/22 09:11 AM


Symptom


  • Prisma Cloud Default Policies are displayed as "deleted on <Date> by template@redlock.io" after platform upgrade.
 
Screenshot 2022-02-25 at 4.51.03 PM.png


Environment


  • Prisma Cloud Enterprise Edition (SaaS version)


Cause


  • During platform upgrade, few Prisma Cloud Default policies may be deleted as part of investigation to reduce the number of alerts received.
  • The changes in the policies (New and Deleted) are published here: Prisma Cloud Release Notes.


 


Resolution


  • Custom policies can be created for the deleted policies by following the steps below:
Step 1: In Prisma Cloud Console, Navigate to Policies > Add Policy > Choose Config/Network policy

image.png

Step 2: Provide the Policy Name, Policy Subtype and Severity. Click Next

image.png

Step 3: Select "Saved Search". From the dropdown, search for the deleted default policy and select it. It will be suffixed with "_RL" at the end. Click Next

image.png


image.png

Step 4: Add Compliance Standards and Remediation. Click Save

image.png

Step 5: Navigate back to Policies and confirm the created custom policy is listed

image.png

Step 6:  Wait for the next scan to generate the Alerts.

For more information:
  • Github - All the Default policies with the Prisma Cloud Version.
  • Note: Please choose the Prisma Cloud Version to list the respective policies.
image.png

 
 


Additional Information


  • All the existing Alerts for these deleted policies get AUTO-RESOLVED after the upgrade.
  • If the Alerts are still Open, wait for the upgrade to complete on all the stacks (Example:  app2, app.sg, etc.).
  • Once the upgrade is completed, the Open Alerts for the deleted policies will be auto-resolved.
For more information, refer to the following:


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004NJ0CAM&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language