Will Trusted IPs under Anomaly Trusted IP Address Settings resolve existing Prisma Cloud Open Alerts for those IPs?

Will Trusted IPs under Anomaly Trusted IP Address Settings resolve existing Prisma Cloud Open Alerts for those IPs?

8012
Created On 09/19/22 06:36 AM - Last Modified 12/21/23 19:13 PM


Question


  • Will Trusted IPs under Anomaly Trusted IP Address Settings resolve existing Prisma Cloud Open Alerts for those IPs?


Environment


  • Prisma Cloud
  • Anomaly 


Answer




Additional Information


 Example

  • Consider the following example where the IP address range '192.168.1.0/24' is trusted under Anomaly Trusted List for Anomaly Policy Type 'Port Sweep Activity (Internal)'.

    GUI Path: Settings > Anomaly > Anomaly trusted list > Add trusted list

Screenshot 2022-10-31 at 9.59.43 PM.png

  • In this scenario, any Port Sweep Activity (Internal) detected from the IP address range '192.168.1.0/24' will suppress upcoming Alerts while the previously generated Open Alerts will continue to exist.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sZAECA2&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language