How To Export All Alerts Associated To A Policy in Prisma Cloud
644
Created On 03/10/22 02:30 AM - Last Modified 02/27/24 18:32 PM
Objective
How to successfully download all alerts (100+) pertaining to a certain policy.
Environment
- Prisma Cloud
- Alerts
Procedure
There are two approaches for this:
Approach 1
- GUI: Log into Prisma Cloud > Alerts > Overview
- Click on the hyperlink with the number of alerts
- Click on the "load more" button until it matches the total number of alerts
- Click on the download button
Approach 2
- GUI: Log into Prisma Cloud > Policies
- Search for the desired policy
- Click on the download button
Note: Either of these approaches should yield all the alerts associated to a certain policy.
Additional Information
- Running the RQL query associated to a certain policy in the Investigate tab and downloading the results yields all the alerts too.