Prisma Cloud: Workload incident alerts overlap in both CSPM and CWPP

Prisma Cloud: Workload incident alerts overlap in both CSPM and CWPP

1314
Created On 06/03/23 20:20 PM - Last Modified 03/18/24 14:51 PM


Question


  1. What are Prisma Cloud alerts? How to enable them?
  2. What does the policy type "Workload Incidents" correspond to on Prisma Compute?


Environment


  • Prisma Cloud/Compute - SaaS


Answer


Prisma Cloud alerts and how to enable them:

  • Prisma Cloud continually monitors all of your cloud environments to detect misconfigurations (such as exposed cloud storage instances), advanced network threats (such as cryptojacking and data exfiltration), potentially compromised accounts (such as stolen access keys), and vulnerable hosts. Prisma Cloud then correlates configuration data with user behavior and network traffic to provide context around misconfigurations and threats in the form of actionable alerts. Enable Prisma Cloud Alerts
     

​​​​​
What does the policy type "Workload Incidents" correspond to on Prisma Compute?
  • The policy type "Workload Incidents" on the Prisma Cloud side (Policies > Overview > Policy Coverage > Workload Incidents) falls under Workload Protection Policies on the Prisma Cloud side (CSPM).

  • The incidents/alerts generated on the CSPM side for the set policy correspond to policies as well as results for Runtime defense on the Prisma Compute side in general, and results seen on the Incident Explorer to be specific.
 
  • The results/incidents/alerts seen under Compute > Monitor > Runtime > Incident Explorer may include several Incident types and the output is generated based on the rules set under Compute > Defend > Runtime.





 
  • To conclude this, any incident/alerts seen under Incident explorer page on the CWP platform shall show up under alerts for the policy type "Workload Incidents" on the CSPM platform.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kI2cCAE&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail