Inconsistent results seen for 'Azure Resource Group' in Prisma Cloud

Inconsistent results seen for 'Azure Resource Group' in Prisma Cloud

9997
Created On 08/15/24 03:51 AM - Last Modified 08/15/24 06:35 AM


Symptom


  • Azure Resource Group is an Azure component where Azure creates resources
  • Azure Resource Groups are enabled on the Tenant level
  • Inconsistent results seen for 'Azure Resource Group'
  • For example, when observed in: 
Inventory (Assets) and Investigate (RQL)
  • As shown below, Inventory (Assets) and Investigate (RQL) shows 'Azure Resource Group' count = 1637 in a particular environment






Alerts and Compliance = 1493
 
  • As shown below, Alerts and Compliance shows 'Azure Resource Group' count = 1493 in a particular environment





Resource List = 1368
 
  • As shown below, Resource List shows 'Azure Resource Group' count = 1368 in a particular environment

image


Environment


  • Prisma Cloud
  • Microsoft Azure


Cause


Inventory (Assets) and Investigate (RQL)
  • Inventory (Assets) and Investigate (RQL) list 
  1. Current Active assets
  2. Includes Duplicate entries 
Alerts and Compliance
  • Alerts and Compliance list
  1. Current Active assets
  2. Deleted assets
  3. Unique entries
Resource list
  • Resource List lists
  1. Current Active assets
  2. Unique entries
Example
  • In the above example, Multiple Resource entries for PCCAgentlessScanResourceGroup are seen in Inventory and Investigate tab (Count = 7)
  • Though they have the same name, they are altogether different assets located in different cloud account regions
Inventory



Investigate


 
  • However, under Alerts, Compliance and Resource List tab, you will find only 1 Unique entry for the same

Alerts




Compliance



Resource List


 
  • Additionally, you can run a specific RQL Query to find the deleted 'Azure Resource Group' Assets (count is 144)



Resolution


  • This is expected behaviour as per product design


Additional Information


  • Alerts associated with active Cloud accounts are currently kept for the duration of the service
  • When Cloud accounts are deleted from Prisma Cloud, the associated Alerts are held for an additional 24 hours after which they are permanently deleted
  • Configuration of assets active in the cloud environment is retained for the duration of the service as well
  • Upon termination of the service, data in live systems is stored for up to 60 days, after which it will be deleted from live systems
  • Purge of backup data may take up to an additional 60 days
Reference : View and Respond to Prisma Cloud Alerts


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000PQWBCA4&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language