Error:
An unexpected error occurred. Please click Reload to try again.
Error:
An unexpected error occurred. Please click Reload to try again.
How to Collect Information that will help Identify why the Aler... - Knowledge Base - Palo Alto Networks

How to Collect Information that will help Identify why the Alert was triggered in Prisma Cloud Console?

6179
Created On 11/25/22 06:57 AM - Last Modified 04/02/23 02:24 AM


Objective


  • How to Collect Information that will help Identify why the Alert was triggered in Prisma Cloud Console?


Environment


  • Prisma Cloud


Procedure


  • Alert Details not only help in identifying why the Alert was triggered, but also help in distinguishing between False Positive and Genuine Alerts
  • The following procedure provides a step-by-step approach on how to collect this information

Note : Sample policy 'AWS S3 Buckets Block public access setting disabled' taken as an example for this illustration


I. The Alert Overview
 

  • Go to Alerts > Overview page and then click 'Alert Count' of the target policy

AlertOverview-1.png
 
  • Click the Alert ID to see the Overview tab
  • The Details section (as shown below) will provide more information on the current status of the Alert and when it was triggered. The Alert resolution reason will also show up here


AlertOverview-2.png


II. Alert Rules
 

  • On the same page of the Alert Overview, click on Alert Rules tab to see which Alert Rule triggered this Alert
  • Clicking on the Alert Rule will redirect you to the Alert Rule details

AlertOverview-3.png

 AlertRule-2.png


III. The Resource Config
 

  • On the same page of the Alert Overview, click on the Resource Config tab to see the Resource Config ingested by Prisma Cloud
  • Copy the content as a JSON/TXT format file as shown below

ResourceConfig-1.png


IV. The Audit Trail of Target Resource
 

  • On the same page of the Alert Overview, click on the Resource Name of the Target Alert, or on the View Resource Explorer button on the Alert Detail to check the Audit Trail of the Target Resource.

ResourceConfig-2.png
 
  • This page will redirect you to the Resource Explorer. You can check the change History of the Resource via the Event Timeline
  • Further, if you run over the exclamation mark, the related Alerts will also show up

AuditTrail-1.pngAuditTrail-2.png
 
  • Clicking on the arrow mark (as shown below) will show you the updated content
 

AuditTrail-3.png



Additional Information


Reference:



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sZyOCAU&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language